To connect ProcureDesk with Microsoft Dynamics 365 Business Central, you need to register ProcureDesk as an application in Microsoft Azure, grant the required Business Central API permissions, and authorize the same application inside Business Central.
Follow the steps below in order.
Step 1: Open App Registrations in Azure
Sign in to the Azure Portal.
Use the search bar at the top and search for App registrations.
You can also navigate to:
Microsoft Entra ID → App registrations
Open App registrations.
Step 2: Register the ProcureDesk Application
Click + New registration.
Enter the following information:
Name: ProcureDesk
Supported account types: Accounts in this organizational directory only
Leave the Redirect URI section blank for now. We will configure the required redirect URIs later.
Click Register.
The application will now be created.
Step 3: Save the Application and Tenant IDs
After registration, you will be taken to the application's Overview page.
Copy and save the following values:
Application (client) ID
Directory (tenant) ID
You will need both values later.
The Application (client) ID identifies the ProcureDesk application, while the Directory (tenant) ID identifies your Microsoft organization. These are different values, so make sure they are not interchanged.
Step 4: Create a Client Secret
From the ProcureDesk App Registration, select Certificates & secrets from the left-hand menu.
Under Client secrets, click + New client secret.
Enter the following:
Description: ProcureDesk
Expires: Select an expiration period based on your organization's security policy. For example, 24 months.
Click Add.
Once the secret is created, immediately copy the value shown under Value and save it securely.
The Client Secret Value is required for the integration. The Secret ID is not required.
The Secret Value is displayed only when the secret is created. If you leave the page without copying it, you will need to create a new secret.
Step 5: Add the Dynamics 365 Business Central API
From the ProcureDesk App Registration, select API permissions.
Click + Add a permission.
Select Dynamics 365 Business Central.
If it is not immediately visible, search for Dynamics 365 Business Central.
Step 6: Add the Required Application Permissions
After selecting Dynamics 365 Business Central, choose Application permissions.
Do not select Delegated permissions.
Add the following permissions:
API.ReadWrite.All
Automation.ReadWrite.All
Click Add permissions.
You should now see both permissions listed under Dynamics 365 Business Central with the permission type shown as Application.
Step 7: Grant Admin Consent
While still on the API permissions page, click Grant admin consent for [Your Organization].
Confirm the action when prompted.
Verify that the Status column shows Granted for the Business Central permissions.
If admin consent has not been granted, authentication or Business Central API access may fail.
Step 8: Configure Redirect URIs
Return to the ProcureDesk App Registration and select Authentication from the left-hand menu.
Click + Add a platform and select Web.
Add the following Redirect URIs:
If consent will be granted from within Business Central, also add:
Click Configure.
If the Web platform has already been configured, use Add URI to add any missing URLs.
Do not remove any existing redirect URIs unless your IT team has confirmed that they are no longer required.
Step 9: Open Microsoft Entra Applications in Business Central
The Azure configuration alone does not provide the application access to Business Central.
Sign in to the Business Central environment that ProcureDesk will connect to.
This may be your Production, Sandbox, or UAT environment.
Use the Business Central search and search for:
Microsoft Entra Applications
Open the Microsoft Entra Applications page.
Step 10: Add ProcureDesk to Business Central
On the Microsoft Entra Applications page, click New.
Enter the following information:
Client ID: Paste the Application (client) ID copied from Azure.
Description: ProcureDesk
State: Enabled
Make sure the value entered in the Client ID field is the Application (client) ID, not the Directory (tenant) ID.
Step 11: Assign Business Central Permission Sets
On the ProcureDesk Microsoft Entra Application record, locate the User Permission Sets section.
Assign the permission sets required for ProcureDesk to access the relevant Business Central data.
ProcureDesk typically requires access to areas including:
Companies
Vendors
Items
Dimensions
Purchase Orders
Purchase Order Lines
Purchase Receipts
Purchase Invoices
A commonly used Business Central permission set is:
D365 BUS FULL ACCESS
Your Business Central administrator may choose to use more restricted permission sets as long as they provide access to all objects required by the integration.
If your Business Central environment uses custom APIs or extensions for ProcureDesk, make sure the Entra application also has permission to those extension objects.
Once the permission sets have been assigned, confirm that the application is still Enabled.
Step 12: Identify the Business Central Environment Name
ProcureDesk needs the exact name of the Business Central environment it should connect to.
Examples include:
Production
Sandbox
COMPANY_UAT
The environment name can be found in the Business Central Admin Center or from the Business Central environment URL.
Save the exact environment name.
A standard Business Central API URL follows this format:
Step 13: Identify the Business Central Company ID
ProcureDesk also requires the Business Central Company ID.
The Company ID is a system GUID and is different from the company display name.
Once authentication has been configured, the available companies can be retrieved using:
GET
A successful response will look similar to:
{ "value": [ { "id": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx", "name": "Example Company", "displayName": "Example Company" } ] }Locate the company that ProcureDesk will connect to and copy the value from the id field.
That value is the Business Central Company ID.
If you are unable to retrieve the Company ID, your ProcureDesk implementation contact can assist once the authentication setup has been completed.
Step 14: Confirm the OAuth Token Endpoint
ProcureDesk uses Microsoft's OAuth 2.0 token endpoint to authenticate with Business Central.
The token endpoint follows this format:
Replace {tenant-id} with the Directory (tenant) ID copied earlier.
For example:
The Business Central authentication scope is:
Step 15: Test the Business Central Connection
Before completing the setup, confirm that the application can access Business Central.
The simplest API test is:
GET
Use the access token generated for the ProcureDesk application.
If the connection has been configured correctly, Business Central should return the available companies.
If you receive an authentication or authorization error, review the troubleshooting section below.
Step 16: Send the Required Information to ProcureDesk
Once all of the steps above are complete, send the following information to your ProcureDesk Account Manager or Implementation Manager:
Application (Client) ID
Directory (Tenant) ID
Client Secret Value
Business Central Environment Name
Business Central Company ID
OAuth 2.0 Token Endpoint
Please share the Client Secret Value using the secure method provided by your ProcureDesk contact.
You do not need to send the following:
Secret ID
Object ID
OAuth Authorization Endpoint
Make sure you send the Client Secret Value, not the Secret ID.
Troubleshooting
Application could not be found in the directory
Confirm that:
The Client ID is the Application (client) ID.
The Tenant ID is the Directory (tenant) ID.
The Client ID and Tenant ID have not been swapped.
The App Registration was created in the correct Microsoft tenant.
Authentication_InvalidCredentials
If Business Central returns an Authentication_InvalidCredentials error, verify that:
The ProcureDesk App Registration exists in the correct tenant.
API.ReadWrite.All was added as an Application permission.
Admin consent has been granted.
The Client Secret Value is correct and has not expired.
The correct Tenant ID is being used.
The correct Business Central environment name is being used.
ProcureDesk has been added under Microsoft Entra Applications inside Business Central.
The Client ID entered in Business Central exactly matches the Application (client) ID from Azure.
The Business Central application is Enabled.
The required Business Central permission sets have been assigned.
Redirect URI error when granting consent
If Business Central displays an error similar to:
AADSTS50011: The redirect URI does not match the redirect URIs configured for the application
go to:
Azure Portal → App registrations → ProcureDesk → Authentication
Under the Web platform, add:
Save the changes and try granting consent again.
Access token works but Business Central API calls fail
If Microsoft successfully generates an access token but Business Central rejects API requests, open:
Business Central → Microsoft Entra Applications → ProcureDesk
Confirm that:
The Client ID is correct.
The application is Enabled.
The required User Permission Sets have been assigned.
Azure API permissions and Business Central permission sets are separate. Both must be configured.
Custom API or extension returns an authorization error
If standard Business Central APIs work but a custom endpoint does not, confirm that:
The extension is installed in the same Business Central environment.
The custom API is published and available.
The ProcureDesk Entra Application has permission to the extension's objects.
Any extension-specific permission set has been assigned to the ProcureDesk Entra Application.
Setup Checklist
Before confirming that the setup is complete, verify that:
ProcureDesk App Registration has been created in the Azure Portal.
Application (Client) ID has been saved.
Directory (Tenant) ID has been saved.
Client Secret has been created.
Client Secret Value has been saved.
Dynamics 365 Business Central API has been added.
API.ReadWrite.All has been added as an Application permission.
Automation.ReadWrite.All has been added as an Application permission.
Admin consent has been granted.
Required Redirect URIs have been configured.
ProcureDesk has been added under Microsoft Entra Applications in Business Central.
The correct Client ID has been entered in Business Central.
The application is Enabled.
Required Business Central permission sets have been assigned.
Business Central Environment Name has been identified.
Business Central Company ID has been identified.
OAuth 2.0 Token Endpoint has been identified.
The Business Central connection has been successfully tested.
Once all of the above are complete, send the required information to your ProcureDesk contact to complete the integration setup.