You are currently viewing Business Central Security Update: What Changed This Quarter
Business Central Security Update: What Changed This Quarter

Business Central Security Update: What Changed This Quarter

Introduction

The third quarter of 2026 brought a series of security, compliance, and governance enhancements to Dynamics 365 Business Central, primarily delivered through the minor cumulative updates, versions 28.2 through 28.4, of the 2026 Release Wave 1 cycle. Unlike a major feature release, this quarter’s updates focused less on new functionality and more on hardening the platform itself, tightening data security boundaries, and getting ahead of the governance questions that come with running AI agents inside a live ERP system. For IT and security teams managing Business Central, understanding these changes matters because several of them shift responsibilities onto administrators, particularly around permissions and legacy API usage.

This blog will cover the following points

  1. The core security and architecture hardening changes rolled out this quarter
  2. Updates to identity and access management, including the new Permission Analysis Page
  3. What changed around AI governance and data boundaries for Copilot and agents
  4. Why deprecated legacy APIs require action from your team
  5. Why the right implementation partner matters, and how Sysamic can help

Core Security and Architecture Hardening

Three changes stand out under this heading. Hardened URI validation introduced stricter protocols within the internal HTTP client, validating external connection targets more rigorously before data moves out of the environment, which directly reduces the risk of server-side request forgery style exploits. AL runtime memory protection upgraded the system application backend with deeper memory isolation boundaries, preventing memory leaks and unintended data exposure between extensions during complex processing tasks, a meaningful fix for environments running many third-party AL extensions side by side. Mandatory security patches, reaching up through update 28.4 in August 2026, addressed critical operational stability hotfixes and vulnerability remediations across both cloud and on-premises environments, underscoring that these were not optional updates to defer.

Identity and Access Management

Access control saw some of the most administrator-facing changes this quarter. Microsoft completed the rollout of native support for Microsoft Entra security groups within local hybrid and on-premises deployments, letting administrators map internal infrastructure roles directly to Entra rather than maintaining separate standalone user group tables, which simplifies identity management for organizations running hybrid environments. A dedicated Permission Analysis Page was also introduced, giving security administrators a comprehensive view of effective permissions so they can audit exactly what a user has access to across tables and functions and debug conflicting permission sets without piecing it together manually. Alongside this, the platform formally deprecated legacy API v1.0, meaning organizations still relying on it need to migrate custom web integrations to API v2.0 to keep standard OAuth 2.0 authentication and modern secure data contracts in place.

AI Governance and Data Boundaries

With the continued rollout of the Microsoft Copilot ecosystem and autonomous agents, including the Payables and Expense agents, this quarter also addressed where agent-related data actually gets processed. Starting July 1, 2026, Copilot and agent requests may be processed in different Azure geographies, and administrators now have a dedicated Copilot and agent capabilities page to manage those data residency preferences directly, rather than leaving it as a default setting nobody reviews. For organizations with strict data governance requirements, including Japan-based subsidiaries operating under local compliance expectations, this is one of the more consequential changes this quarter, since it puts data location decisions explicitly in IT’s hands rather than assuming Microsoft’s default routing is acceptable for every environment.

Why This Matters for Your Team

Treating this quarter’s updates as routine maintenance would be a mistake. The Permission Analysis Page and Entra group rollout both point toward a broader shift where identity and access management in Business Central increasingly mirrors enterprise-grade security practices, and the API v1.0 deprecation has a hard deadline that custom integrations need to meet before they break. Reviewing your organization’s agent data residency settings, auditing effective permissions, and confirming no custom integrations still depend on the deprecated API should all be on this quarter’s IT checklist.

Conclusion

This quarter’s Business Central updates were less about new capabilities and more about closing the gaps that come with running a modern, AI-integrated ERP system at scale. Getting ahead of the permission audit, the API migration, and the new agent data residency settings now will save far more effort than reacting to a broken integration or a compliance question later.

Sysamic K.K. is a Tokyo-based Microsoft Dynamics 365 Business Central partner with more than 20 years of experience helping companies keep their ERP environments secure and compliant. We help clients review permission structures, migrate legacy integrations to current APIs, and configure Copilot and agent data residency settings correctly for Japan operations and beyond. If your team needs help auditing your Business Central environment against this quarter’s changes, we would be glad to help. Email us at info@sysamic.com or fill out our contact form here to get in touch.