Unified Administrator Management Dynamics 365 , Finance, and Operations—Now in Preview
Microsoft has released a public preview of unified management of the System Administrator role in unified environments: once enabled, administrators can be added and removed in Dataverse, and a role that exists only in Finance and Operations is removed. Prerequisites, activation, and known limitations.
Enabling unified management of the System Administrator role makes Power Platform admin center the authoritative source for administrator roles in a unified environment. Administrators and their role assignments are then stored in Dataverse and synchronized to Finance and Operations. This feature is in public preview and requires explicit activation: nothing changes in an environment until it has been activated there.
The key consideration before this activation is the status of existing roles. Synchronization does not remove any users from Finance and Operations, but it does remove administrator roles that exist only in Finance and Operations and not in Dataverse, to prevent role discrepancies. An administrator known only on the Finance and Operations side therefore loses their role at the time of synchronization.
| Element | Value |
|---|---|
| Status | Public preview |
| Platform Version | Platform Update 72 (PU72), 7.0.7996.61 or later |
| Solution Version | Unified User Management 9.3.3445.2 or later |
| Activation Location | Feature management in the Finance and Operations application |
| Role to enable | System Administrator in Dataverse , and Finance and Operations |
Status and versions as of September 9, 2026, according to Microsoft documentation.
Unified Environments and Power Platform admin center
A unified environment is a Power Platform environment with a Dataverse foundation, in which multiple applications Dynamics 365 can be installed and hosted alongside low-code applications, feeds, and sites. The environment exposes two runtime addresses: one for customer engagement applications and one for finance and operations applications. Microsoft justifies the consolidation of administrators through this structure— Dataverse , and finance and operations are fundamentally part of the same unified environment, and a System Administrator should therefore be able to manage administrative tasks for both from a single location.
As of February 16, 2026, Microsoft no longer allows the creation of implementation projects cloud in Lifecycle Services for Dynamics 365 Finance, Dynamics 365 Supply Chain Management, and Dynamics 365 Project Operations, and is directing new customers to the Power Platform admin center . Customers who already have active Lifecycle Services projects can continue to use them. This console also manages other governance settings for Power Platform, such as the licensing policy applied by a Managed Environment.
How Activation Changes the Environment
Microsoft describes three effects: the Power Platform admin center becomes the authoritative source; administrators and their role assignments are maintained in Dataverse; and updates are automatically synchronized to Finance and Operations.
After activation, any changes to System Administrators must be made in Dataverse, and the corresponding changes are blocked in Finance and Operations. The creation, viewing, modification, and deletion of System Administrators are synchronized to Finance and Operations when performed from the web Power Platform ,admin center , or Dataverse, including role assignments made directly or by an Owner-type team.
Note: Microsoft recommends changing the Environment admin role only during a scheduled downtime window, so as not to interrupt active batch jobs or ongoing processes.
Required Platform and Solution Versions
This feature is available only in environments running Platform Update 72 (PU72) version 7.0.7996.61 or later, and the Unified User Management solution version 9.3.3445.2 or later.
The solution is updated from the environment: Environment > Resources > Dynamics apps or Applications; search for Unified User Management, then click Update if the status shows "Update available."
The number 7.0.7996.61 is a platform build, not a service update number. The service update schedule for unified environments—which covers only environments managed via Power Platform admin center —lists platform version 7.0.7996.33 for service update 10.0.48. Therefore, simply noting the service update number is not enough to draw a conclusion: you must check the environment’s platform build.
Enable the feature and verify that it is active
Activation requires a user who has the System Administrator role in both Dataverse and Finance and Operations. It is performed from the Finance and Operations application: System Administration > Workspace > Feature Management; select " All," then activate (Preview) Unified Admin User Management.
Microsoft then suggests verifying this visually: the Dataverse environment admins should appear in the Finance and Operations application, and their presence confirms that the administrators are unified and synchronized from Dataverse.
The Environment Admin, or Provisioning Admin
Each finance and operations environment has an Environment Admin, who is designated when the environment is created and is also known as the provisioning admin. The "Admin" user ID always refers to the Environment Admin.
This role cannot be removed as long as there are no other System Administrators. If there is another System Administrator and the current Environment Admin is removed via the Power Platform admin center , the system automatically promotes another System Administrator. Furthermore, the Environment Admin role—or provisioning—can only be removed when the environment has at least three System Administrators; if there are fewer than three, removal is not supported.
The "Environment Admin" user can be changed in two ways.
- Set up Environment Admin in the Finance and Operations application. Select a user who has the System Administrator role, and then set them up as Environment Admin.
- Remove the System Administrator role in the Power Platform admin center . The path is Manage > Environments, select the relevant environment, Settings, open “Users s + Permissions,” Users, the user, Manage roles, uncheck System Administrator, then Save. During synchronization, the system removes the role and automatically promotes another user to System Administrator.
Microsoft cites reduced reliance on a single user as one of the benefits of this unification. This issue ties into the question of which accounts actually control a tenant Microsoft 365, which is addressed here at the environment level.
Manage Administrators Through an Owner Team
The System Administrator role is also assigned to a team, not just a single user. In the Power Platform admin center , navigate to Manage > Environments, select an environment, go to Settings, open " Users , and permissions," Teams, then Create Team. In the New Team form, set Team Type to Owner —this is the type used by Finance and Operations. Next, add users to the team, assign the System Administrator role to the team, and then save. All team members become System Administrators in Finance and Operations, and synchronization occurs asynchronously.
When the System Administrator role is removed from a team, all team members lose administrator access in Finance and Operations, except for those who hold the role directly. Adding a user to a team that holds the role grants that user administrator access; removing the user from the team causes them to lose that access, but they retain the System User role. These changes are also synchronized asynchronously.
Both actions are performed on the page Teams : click the three dots next to the team, then select “Manage security roles” to check or uncheck “System Administrator,” or select “Manage Team members” to add or remove members.
Known Limitations
Teams that are not of the "Owner" type are not supported in public preview. Only teams with a "Team type " of " Owner" are used for administrator management; teams of other types do not allow for the provisioning or management of System Administrator access.
Microsoft also documents a known issue with admin provisioning. If, when the environment has fewer than three administrators, the existing admin is deleted or their System Administrator role is revoked in Dataverse, the changes to admin provisioning may not be reflected in Finance and Operations. Microsoft recommends verifying that the environment has at least three administrators before taking action in Dataverse. If the operation has already been performed and the provisioning admin remains locked out, you must add another administrator in Dataverse, then use “Make Environment Admin” on the page Users once the change has been reflected in Finance and Operations.
What to Check Before Activating
- The platform build of the environment and the version of the Unified User Management solution.
- The list of System Administrators for Finance and Operations, compared to the list in Dataverse : a role that appears on only one side disappears during synchronization.
- The number of system administrators in the environment, since removing the Environment Admin role requires at least three.
- The type of teams that hold the role; the preview only supports Owner teams.
- The scheduled downtime window during which you will modify the Environment Admin role, so as not to interrupt batch processing.
Our Reading
For Dynamics 365 finance and operations administrators, the order of operations matters more than the activation itself. Synchronization does not push roles that exist only in finance and operations up to Dataverse ; instead, it removes them. An administrator known only on the Finance and Operations side therefore loses access, and it is the comparison of the two lists that prevents this from happening—not a configuration setting. This comparison takes place before activation; afterward, the role has already been removed.
Having three System Administrators does not trigger the activation, but rather the removal of the Environment Admin role—and this is the same condition mentioned in the known issue. An environment with only one or two appointed administrators would therefore be wise to add more before needing to remove one.
There are two limitations to the preview status: teams that are not of the “Owner” type are excluded from the scope, and changes to admin provisioning may not be reflected in Finance and Operations under three administrators. Enable the feature in a sandbox environment, verify that the Dataverse environment admins appear there, and then roll it out to production.
Microsoft Sources
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 139 articles, all of which are freely available.

