Install and activate
Assign permissions
Assign the two Universal Search permission sets: BAA SEARCH ADM for the people who set the app up, and BAA SEARCH for every user who searches.
updated: applies-to: 1.0.0.1
This page applies to version 1.0.0.1; the current product version is 1.0.0.0.
Universal Search ships two assignable permission sets, one for the people who administer the app and one for everyone who searches. Assigning them now means your administrators can start indexing without a SUPER account, and your users can open the search page as soon as the index is built.
The two permission sets
| Permission set | Caption | Assign to |
|---|---|---|
BAA SEARCH |
Universal Search - Use | Every user who searches |
BAA SEARCH ADM |
Universal Search - Admin | Administrators, IT and partner consultants who set up and maintain the app |
- Universal Search - Use lets a user open the Universal Search page, read the index and setup, and run searches.
- Universal Search - Admin includes everything in Universal Search - Use. It adds full access to the app's own tables, the setup, index configuration and activation pages, and the access that Start Indexing needs: read, insert, modify and delete on Job Queue Entry, plus read, insert and modify on Job Queue Category.
NOTE
Without BAA SEARCH ADM, an administrator who is not a SUPER user cannot schedule the background indexing job, so Start Indexing cannot complete. Assign it before anyone runs the setup.
Assign a permission set to a user
- In Tell Me, search for Users and open the user you want to give access to.
- In the user's permission sets, add
BAA SEARCH ADMfor an administrator, orBAA SEARCHfor someone who only searches.
- Repeat for every user who needs Universal Search. A user who has
BAA SEARCH ADMdoes not also needBAA SEARCH.
Permissions and search results
The permission sets control who can use Universal Search. They do not grant access to Business Central's business tables, although both include read access to the app's own index table, which stores the text of every indexed field. Results only include tables the searching user can read, and opening a result checks the read permission again.
WARNING
The read check is made per table, not per record, and Universal Search does not apply security filters to individual results. If you limit some users to part of a table with security filters, leave that table out of Search Index Configuration.
People who post documents but do not use Universal Search do not need either permission set. Universal Search records changes to indexed tables with its own built-in permissions, so their postings do not fail for lack of a Universal Search permission set.
For every grant in both sets, see the permission sets reference.
What's next
Register your environment for the free license: Activate the license.