Security & Permissions: API User Permissions Tab

Prev Next
In Beta

This feature is in beta for select customers. Contact your CSM for more information. 

The API User Permissions tab is part of the Security and Permissions page and contains the setting that controls how API managed users (users that were created via API) are managed in R365. This tab is only displayed if at least 1 user has been created via API. By default, the API Users toggle is enabled, allowing users created via API to be edited and managed in R365.

From this page, users can:

  • Enable API managed users to be edited in R365

  • Disable API managed users from being edited in R365


Security

Users must have the following permission to enable or disable API users from being managed in R365:

  • Administration → Users → User Roles → Create/Edit/Delete User Roles & Permissions


These permissions can be added to custom user roles or individual users. The Permission Access report can be used to determine which user roles or users already have these permissions assigned. For more information, see User Setup and Security.


Navigation

Navigation Menu

  1. Click the Admin app.

  2. Click users & security.

  3. Click security & permissions.

  4. Click the API User Permissions tab.

Search

Navigate to pages with the R365 global search bar:

  1. Enter all or part of the page name in the R365 global search bar.

  2. Select the page from the results list.

Only enabled pages can be searched for. If the desired page is not enabled, contact your CSM for assistance.



API User Permissions Tab

Button/Field

Description

1

API Users


Editing Restrictions for API Managed Users

When the API Users toggle is off, edits to API-managed users are restricted. All fields and checkboxes on the User Role and Report Roles tabs become read-only.

User Records

When the 'API Users' setting is disabled, API-managed user records display a message indicating that edits are restricted within R365 and all fields are read-only.  The message is only displayed for users that contain the following permission:

  • Administration → Users → Edit Users

This restriction also applies to users attempting to update their own user record.

Users Page

When the 'API Users' setting is disabled, API managed users are not editable in the table of the Users page, all fields are read-only, and a message is displayed when hovering over users to indicate that the user is managed outside of R365.

Organizations using the brand connector will see: ‘User managed by [Brand Name]’. This label indicates the user is managed at the brand level and cannot be edited within the instance.

Security and Permissions Page

When the ‘API Users’ setting is disabled, checkboxes in the User subtabs of the User Role and Report Roles tabs are read-only, and a message is displayed when hovering over users to indicate that the user is managed outside of R365.

Organizations using the brand connector will see: ‘User managed by [Brand Name]’. This label indicates the user is managed at the brand level and cannot be edited within the instance.

User Roles - Users Subtab

Report Roles - Users Subtab

Mass Role Update

When the 'API Users' setting is disabled, API managed users are not editable in the Mass Role update tool and all fields for the API managed users are read-only, and a message is displayed when hovering over users to indicate that the user is managed outside of R365.

Organizations using the brand connector will see: ‘User managed by [Brand Name]’. This label indicates the user is managed at the brand level and cannot be edited within the instance.

Setup Assistant

When the 'API Users' setting is disabled, API managed users are not editable in the Setup Assistant and all fields for the API managed users are read-only except for reset password.