Architecture

Connect Business Central to Outlook, Teams and SharePoint in Microsoft 365

Set up Business Central email, the Outlook add-in, the Teams app, read-only access with Microsoft 365 licenses, OneDrive, and SharePoint storage for document attachments.

13 min read
On this page

To connect Business Central online to Microsoft 365, you configure six built-in integrations: email accounts that send through Exchange Online, the Business Central add-in for Outlook, the Business Central app for Microsoft Teams, read-only access for Microsoft 365-only users in Teams, OneDrive for opening and sharing files, and external file storage that keeps document attachments in a SharePoint library instead of the Business Central database. Each one is configured from a setup page in Business Central, and most also need a matching step in the Microsoft 365, Teams, Business Central or Entra admin portals. None of them needs custom code, but each has licensing and permission requirements that decide who actually gets the feature.

Who this is for and what you will have

This guide is for Microsoft 365 and Business Central administrators who want finance, sales and operations staff to work with ERP data from the Microsoft 365 apps they already use. At the end you will have:

  • Outbound email from Business Central through a shared mailbox in Exchange Online.
  • The Outlook add-in deployed to selected users or the whole organization.
  • The Teams app deployed by policy, with record cards working in chats and channels.
  • Employees without Business Central licenses able to read shared records in Teams.
  • OneDrive features configured, and document attachments stored in SharePoint.

The integration map

IntegrationWhat users getBusiness Central sideMicrosoft 365 side
Email accountsSend quotes, invoices and orders by emailSet Up Email Accounts, Email Scenario AssignmentExchange Online mailbox or shared mailbox
Outlook add-inCustomer and vendor details beside email; links from document numbersOutlook Add-in Centralized DeploymentIntegrated apps in the Microsoft 365 admin center
Teams appContact search, record cards, tabs, Share to TeamsTeams App Centralized Deployment, Card SettingsTeams apps > Setup policies in the Teams admin center
Microsoft 365 license accessRead-only view of shared records for non-Business Central usersLicense Configuration, admin center environment settingSupported Microsoft 365 licenses, optional security group
OneDriveOpen in OneDrive, Share, Excel and Word output opened onlineOneDrive SetupOneDrive provisioned per user
External file storageAttachments kept in SharePoint or Azure storageExternal File Accounts, File Scenario AssignmentEntra app registration with SharePoint site permission

Prerequisites

  • Business Central online. Teams integration and Microsoft 365 license access aren't available on-premises, and the Outlook add-in and email steps differ for on-premises.
  • A Microsoft 365 subscription in the same Microsoft Entra tenant, with Exchange Online and Teams.
  • Admin roles: Exchange Administrator for Outlook add-in deployment, Teams Administrator for Teams app deployment, and a SharePoint Administrator to grant site permissions.
  • In Business Central: the EMAIL - ADMIN permission set for email setup, and indirect, modify and delete permission on the Document Service Scenario table for OneDrive setup.

Step 1: Send email through Exchange Online

Business Central online email works only with Exchange Online; hybrid connections to on-premises Exchange aren't supported. Three connectors are available by default:

ConnectorSends fromUse when
Microsoft 365 ConnectorA shared mailbox, such as sales@contoso.comA department sends from one address
Current User ConnectorThe signed-in user's mailboxCorrespondence should come from individuals
SMTP ConnectorAn SMTP accountYou need service-to-service scenarios or Send As
  1. In Business Central, search for Set Up Email Accounts and add an account with the connector you need. You must have a default account; it handles every scenario you don't assign elsewhere.
  2. Open Email Scenario Assignment and map scenarios, for example sales documents to sales@contoso.com and purchase documents to purchasing@contoso.com.
  3. Check the Email rate limit on each account. The default for Microsoft 365 and Current User accounts is 30 messages per minute, matching Exchange Online, and Email Concurrency Limit defaults to 3 with a maximum of 10.

Everyone who sends must be a fully licensed Business Central user with a paid Exchange Online license; trial licenses don't work, and guests and delegated admins can't use the tenant's accounts. If you integrate through APIs with service-to-service authentication, the Microsoft 365 and Current User connectors can't authenticate the user, and Microsoft's guidance is to use the SMTP connector for that case. For SMTP, Microsoft recommends OAuth 2.0 authentication because Exchange Online is deprecating Basic authentication for SMTP.

Step 2: Deploy the Outlook add-in

The Business Central add-in for Outlook is two add-ins:

  • Contact insights shows customer or vendor information beside emails and appointments and lets users create and send documents such as sales quotes and invoices.
  • Document view turns document numbers in an email body into links to the document in Business Central.

To deploy for the organization with Centralized Deployment:

  1. In Business Central, search for Assisted Setup and start Outlook Add-in Centralized Deployment.
  2. Select the add-ins in the Deploy column and choose Download and Continue. A file named OutlookAddins.zip downloads.
  3. Extract Contact Insights.xml and Document View.xml.
  4. In the Microsoft 365 admin center, open Integrated apps > Upload custom apps, set App type to Office Add-in, and upload each manifest with Upload manifest file (.xml) from device.
  5. Assign users or groups and deploy.

You need at least the Exchange Administrator role, and users need a Microsoft 365 license. Allow up to 24 hours before users see the add-in; they may need to restart Outlook.

The add-in is bound to one environment: the environment name is written into the manifest when you download it. To use the add-in against a different environment, open that environment and deploy its manifests separately.

Step 3: Deploy the Teams app

The Business Central app for Teams needs a Teams license from a Microsoft 365 Business or Enterprise plan, Microsoft Teams EEA or a similar plan. Microsoft states that standalone plans such as Microsoft Teams (free) and Teams Essentials aren't supported for the app itself.

  1. In the Teams admin center, confirm the messaging policy for your users has Allow URL previews turned on. Without it, pasted Business Central links don't expand into cards.
  2. In Business Central, search for Teams App Centralized Deployment and select Next.
  3. In the Teams admin center, go to Teams apps > Setup policies, select or create a policy, choose Add apps, add Business Central, and save.
  4. Return to Business Central and select Done. The policy can take up to 24 hours to apply.

Codeunit 2718 Page Summary Provider must stay published as a web service; it's published by default and supplies the fields shown on cards.

Decide on card visibility before rollout. Once a card is sent to a chat, everyone in the conversation can see the fields on it, regardless of their Business Central license or permissions, and that copy is subject to Teams retention policies. If that's too open, run the Card Settings assisted setup and turn off Show record summary for the environment; cards then show only the Details button, which still enforces Business Central permissions. You can also block specific users from sending cards by turning off URL previews in their messaging policy, and Purview eDiscovery and content search apply to messages that contain cards.

Step 4: Give Microsoft 365-only users read access in Teams

Access with Microsoft 365 licenses lets employees who have a supported Microsoft 365 license but no Business Central license open records that colleagues share in Teams. It is read-only and Teams-only:

ClientAllowed
Business Central app for TeamsYes
Web client, mobile apps, APIsNo
Other Office integrationsNo

Supported plans include Microsoft 365 Business Basic, Business Standard, Business Premium, E3, E5, F1 and F3, Office 365 E1, E3, E5 and F3, among others, with the Teams service plan enabled. Users must be internal; guests are blocked automatically. The organization must also have at least one user with a Business Central license.

  1. In Business Central, search for License Configuration, open Microsoft 365, select the edit icon and turn on Customize permissions.
  2. Under Custom Permission Sets, add the permission sets these users should have. No permissions are granted by default. For a sandbox trial, Microsoft suggests D365 Read; in production, scope it to the tables people genuinely need.
  3. In the Business Central admin center, open Environments, select the environment, choose Modify for Access with Microsoft 365 licenses, turn it on and save. It's off by default and set per environment.
  4. Optionally, assign a Microsoft Entra security group to the environment so only its members can sign in.
  5. Deploy the Teams app to these users as well (Step 3). If you previously deployed only to licensed users, update the setup policy.

Step 5: Configure OneDrive

In Business Central online, OneDrive integration is on by default. Use the OneDrive Setup assisted setup to choose which features run through OneDrive:

  • Use for app features adds Open in OneDrive and Share to files such as document attachments, incoming documents and the Report Inbox.
  • Use for system features makes Open in Excel, Edit in Excel and reports saved as Excel or Word copy the file to OneDrive and open it in the browser.

Each user needs Business Central and OneDrive licenses, and OneDrive must be provisioned for them. The setting applies to all companies in the environment. If Business Central and OneDrive are in different countries or regions, files placed in OneDrive can cross data residency boundaries, so confirm your policy first.

Step 6: Store document attachments in SharePoint

By default attachments live in the Business Central database, which counts against capacity. External file storage moves them to Azure Blob Storage, Azure File Share or a SharePoint document library. Microsoft is explicit that once files are external, backing them up and controlling access is your responsibility.

Register an app with site-scoped access

In Microsoft Entra ID, register an app for the connector. For the default Microsoft Graph mode, the least-privileged option is the Graph application permission Sites.Selected, plus a write role on each site the connector uses. Sites.Selected grants nothing on its own, so a SharePoint administrator must add the site grant. The tenant-wide alternative, Sites.ReadWrite.All, is broader than the connector needs.

The grant can be made with Microsoft Graph PowerShell. Creating site permissions requires Sites.FullControl.All, and in delegated mode the signed-in user must be a SharePoint administrator and a member of the target site:

Connect-MgGraph -Scopes "Sites.FullControl.All"
 
$site = Invoke-MgGraphRequest -Method GET `
    -Uri "https://graph.microsoft.com/v1.0/sites/contoso.sharepoint.com:/sites/Finance"
 
$grant = @{
    roles = @("write")
    grantedToIdentities = @(@{
        application = @{
            id          = "<application-client-id>"
            displayName = "Business Central attachments"
        }
    })
} | ConvertTo-Json -Depth 5
 
Invoke-MgGraphRequest -Method POST `
    -Uri "https://graph.microsoft.com/v1.0/sites/$($site.id)/permissions" `
    -Body $grant -ContentType "application/json"

A 201 Created response with "roles": ["write"] confirms the grant. Repeat for every site the account will use.

Create the file account and assign the scenario

  1. In Business Central, search for External File Accounts and choose Add a file account.
  2. Select SharePoint, then enter an Account Name, the Tenant ID, Client ID and credentials of the app registration, the SharePoint Name and a Base Relative Folder Path such as Shared Documents/Attachments.
  3. Search for File Scenario Assignment, choose Assign scenarios, select the SharePoint account and assign Document Attachments - External Storage.
  4. On External Storage Setup, turn on Enabled and accept the warning, pick the Root folder, and decide whether Delete External File on Attachment Delete should remove the SharePoint file when the attachment is deleted in Business Central.
  5. Use Storage Sync to move existing attachments; only attachments added after you enable the feature go external automatically.

Business Central creates subfolders by environment, company and table, and appends a unique ID to each file name so two different invoices called invoice.pdf don't collide. After Copy Company or an environment restore, run Migrate Files on External Storage Setup, because the attachment records still point to the original folders.

Verify the setup

  1. Send a test sales quote from Business Central and confirm it leaves from the assigned mailbox.
  2. Open an email from a customer contact in Outlook and confirm Contact insights shows the customer.
  3. Paste a customer card link into a Teams chat and confirm it expands into a card.
  4. With a test user who has only a Microsoft 365 license, open Details on a shared card. A read-only Business Central page means access works.
  5. Attach a PDF to a sales order and confirm it appears in the SharePoint library under the expected folder, then open it from the FactBox.

Troubleshooting

"You aren't authorized to access this resource: https://graph.microsoft.com/.default." Documents were sent through an API using service-to-service authentication with the Microsoft 365 or Current User connector. Use the SMTP connector for that scenario.

Emails rejected by Exchange. The sender has no paid Exchange Online license, or is a guest or delegated admin. Assign a license or send from a shared mailbox account.

Outlook add-in doesn't appear. Centralized Deployment can take up to 24 hours. Have users restart Outlook, and check that the manifest came from the environment they use.

Business Central links don't turn into cards in Teams. Allow URL previews is off in the user's messaging policy, or the app isn't installed for that user yet.

Microsoft 365-only user can't open card details. Access isn't enabled on that environment, the user's plan isn't supported or has Teams disabled, or no permission sets were added under License Configuration.

Attachment upload fails with a SharePoint account. The app has Sites.Selected but no write grant on the site, or the base folder path doesn't exist. For legacy SharePoint REST mode on Business Central 28.0 or earlier, the app also needs access to the tenant root site for folder creation.

Closing checklist

  • Default email account set; scenarios mapped; senders licensed for Exchange Online.
  • Outlook add-in deployed from the right environment through Integrated apps.
  • Teams app in a setup policy; URL previews allowed; card record summary decision made.
  • Microsoft 365 license access enabled per environment with scoped permission sets.
  • OneDrive Setup reviewed for app and system features, with data residency confirmed.
  • SharePoint app registration on Sites.Selected with per-site write grants.
  • Document Attachments scenario assigned, existing files synced, backup plan in place for the library.

For the approval side of the same processes, such as signing off purchase requests before they reach Business Central, see building an approval workflow with Power Automate and SharePoint.

References

Questions people ask

Can users without a Business Central license see Business Central data in Teams?

Yes, if an administrator enables access with Microsoft 365 licenses on the environment. Users with a supported Microsoft 365 plan can then read Business Central records shared with them in Teams, but they can't edit data or use the web client, mobile apps or APIs.

How do I deploy the Business Central add-in for Outlook to everyone?

Run the Outlook Add-in Centralized Deployment assisted setup in Business Central to download OutlookAddins.zip, then upload the Contact Insights and Document View manifests in Integrated Apps in the Microsoft 365 admin center. It can take up to 24 hours for users to see the add-in.

Can Business Central store document attachments in SharePoint?

Yes. Create a SharePoint external file account backed by a Microsoft Entra app registration, then assign the Document Attachments - External Storage scenario to it. New attachments are stored in the SharePoint library, and the Storage Sync action can move existing ones.

Does Business Central email work with on-premises Exchange?

No. The email features of Business Central online work only with Exchange Online, and hybrid connections to on-premises Exchange aren't supported. Users who send email also need a paid Exchange Online license.

Business CentralMicrosoft 365OutlookMicrosoft TeamsSharePoint
  1. Build a multi-stage approval workflow with Power Automate and SharePoint

    Automate manager and finance approvals on SharePoint list items with the Power Automate Approvals connector, write decisions back to the list, and handle Teams, timeouts and the 30-day limit.

    Architecture13 min read
  2. Business Central API Webhooks: Create, Validate and Renew Subscriptions

    Receive Business Central change notifications instead of polling: build a validating receiver in Azure Functions, create a subscription, process notifications and renew before the three-day expiry.

    Architecture10 min read
  3. Business Central SOAP Retirement in v29: Migrate Page Web Services to APIs

    Version 29 removes SOAP endpoints on Microsoft pages in Business Central. Find the integrations that still call them with telemetry and move each one to API v2.0, a custom API or OData.

    Architecture12 min read