← Back to documentation
Microsoft Dynamics 365 Business Central logo

Connect Microsoft Business Central to TrustBill

A step-by-step guide for SME admins. About 15 minutes, done once. After this, sales invoices posted in Business Central flow to the UAE FTA automatically.

~15 minutes, one time

Register app, grant permission, paste credentials. No coding.

Your creds stay in your tenant

You register in your own Entra tenant. We never see your Microsoft password.

Zero clicks per invoice

Post in BC as usual — we pick it up and file with the FTA in minutes.

Before you start

  • You need Business Central admin access and Azure/Entra admin access on your organisation's Microsoft tenant. (Usually the same person.)
  • Have your TrustBill SME login handy — you'll paste the credentials into Settings → Business Central at the end.
  • Keep a scratch pad open — you'll copy 4 values along the way (tenant id, client id, client secret, environment name).
1

Register an app in Microsoft Entra

About 6 min

Sign in to the Azure portal with an account that can register apps in your Microsoft tenant. Then create a new App Registration — TrustBill will use it to read invoices from Business Central.

1a. Create the App Registration

  1. Open Azure Portal → App registrations and click New registration.
  2. Name it TrustBill Connector.
  3. Under Supported account types, pick Accounts in this organizational directory only.
  4. Leave Redirect URI blank on this page — we add it in sub-step 1c below.
  5. Click Register. You'll land on the Overview page.
  6. Copy the Directory (tenant) ID and Application (client) ID from the Overview page — you'll paste them into TrustBill at the end.

1b. Create a Client Secret — read this carefully

  1. In the left menu of your app, click Certificates & secrets → + New client secret.
  2. Description: TrustBill sync. Expiry: 24 months. Click Add.
  3. The page reloads showing a table with four columns: Description · Expires · Value · Secret ID.
  4. Copy the Value column immediately — before you click anywhere else. The Value is a long opaque string that contains tildes ~, dots ., hyphens - and underscores _ (about 40 characters). This is what TrustBill needs.

⚠ Do NOT copy the Secret ID column by mistake

The Secret ID column shows a UUID (e.g. fea75778-279b-4f10-b99b-d8e481a40e14). This is not the secret TrustBill wants — it's just an identifier for the row.

A real Client Secret Value looks like this:
KUs8Q~-gPHYt.CNo3FhADz~YQEjA3BnjsjZ_YcxH

If what you copied looks like a UUID (xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx), you grabbed the wrong column. Create a new secret and copy the Value column instead — Azure masks the Value after you leave the page, so the old row cannot be recovered.

Tip · If you leave the secret page without copying the value, Azure won't show it again. Just create another secret — the old one can be deleted safely as long as no other app uses it.

1c. Add a Redirect URI for Business Central consent

TrustBill itself uses the client-credentials flow (no redirect needed), but Business Central's "Grant Consent" button requires one. Without it, you'll hit error AADSTS500113: No reply address is registered in Step 3.

  1. In the left menu of your app, click Authentication.
  2. Click + Add a platform → choose Web.
  3. In the Redirect URIs box, paste exactly:https://businesscentral.dynamics.com/OAuthLanding.htm
  4. Leave both checkboxes (Access tokens and ID tokens) unchecked.
  5. Click Configure at the bottom.
2

Grant Business Central permission

About 2 min

Now tell Microsoft that this app is allowed to read Business Central data on your organisation's behalf.

  1. Still in the app you just created, open API permissions.
  2. Click Add a permission → APIs my organization uses. Search for Dynamics 365 Business Central and pick it.
  3. Choose Application permissions, tick app_access, and add it.
  4. Back on the permissions list, click Grant admin consent for {your tenant}. A green tick should appear next to app_access.

Tip · The "Grant admin consent" button requires a Global Admin. If your account can't grant it, ask an admin to click that one button. Nothing else about the setup requires admin rights afterwards.

3

Add the app inside Business Central

About 5 min

Microsoft has now allowed the app at the tenant level. Business Central also needs to know it should trust this app — a separate step inside BC itself. The order of the clicks below matters — do them exactly as written or BC will reject the app at run time with a 401 error that is hard to recover from.

⚠ Why the order matters

Business Central's "Grant Consent" button takes a snapshot of whatever permission sets are attached at the moment you click it. If you click Grant Consent before adding D365 BUS FULL ACCESS, BC consents to an empty permission set and TrustBill will get a 401 on every call, even though everything looks correct afterwards.

The fix in that case is a full reset (see Troubleshooting at the bottom of this page) — avoid it by following the order below.

3a. Open the Microsoft Entra Applications page

  1. Open Business Central as a BC admin.
  2. Press Alt + Q (or click the magnifier icon) and type Microsoft Entra Applications. Click the result under Pages and tasks.
  3. On older BC releases this page is called Azure Active Directory Applications. Same page, older name.

3b. Create the record (keep State = Disabled for now)

  1. Click + New. An empty row appears.
  2. In the Client ID column, paste the Application (client) ID you copied in Step 1.
  3. In Description, type TrustBill Connector.
  4. Leave State = Disabled. (BC only lets you edit permission sets while the record is Disabled — if you enable it now, the "New Line" button in the next sub-step will be greyed out.)
  5. Click the row to open the card view.

3c. Attach a permission set (now, while State = Disabled)

  1. On the card, scroll to the User Permission Sets section at the bottom.
  2. Click + New Line.
  3. Permission Set: type D365 BUS FULL ACCESS and pick it from the dropdown. On BC v23 and newer the equivalent may be called D365 BUS PREMIUM — if D365 BUS FULL ACCESS is not in the dropdown, use Premium instead.
  4. Company: leave blank (applies to all companies).
  5. Extension Name auto-fills — don't touch it.
  6. Tab out of the row so BC saves it. You should see one row listed. If "New Line" is greyed out, go back to 3b and make sure State is set to Disabled.

BC v23+ blocks SUPER on application users

If someone tells you to use SUPER for the TrustBill Connector, BC will refuse — SUPER has been locked for Entra app users since BC 23 for security. Use D365 BUS FULL ACCESS or D365 BUS PREMIUM instead.

3d. NOW set State = Enabled

  1. Go back to the top of the card.
  2. Change State from Disabled to Enabled.
  3. BC may ask "Do you want to grant consent for this app?" — click Yes.

3e. LAST — click Grant Consent in the ribbon

  1. At the top of the card you'll see a Grant Consent action (gear-with-sparkle icon). Click it.
  2. A Microsoft sign-in popup opens. Sign in with your Global Admin account and click Accept.
  3. You should see the message "Consent was given successfully."

If you see AADSTS500113 (No reply address registered)

You missed sub-step 1c. Go back to Azure Portal → your app → Authentication → add platform Web with redirect URI https://businesscentral.dynamics.com/OAuthLanding.htm. Then come back and click Grant Consent again.

4

Note your BC environment name

About 1 min

TrustBill needs to know which BC environment to talk to (most SMEs have just one; some have a sandbox alongside production).

  1. Inside Business Central, go to Help & Support → Troubleshooting.
  2. The environment name appears at the top — usually production for the live tenant. Copy that word exactly (lower case).

Microsoft's admin center environments guide also lists all your environments if you can't find it in-app.

5

Paste it all into TrustBill

About 2 min

You should now have four values on your scratch pad. Open TrustBill and paste them into the wizard.

Directory (tenant) ID

00000000-0000-0000-0000-000000000000

Application (client) ID

00000000-0000-0000-0000-000000000000

Client secret

•••••••••••••••••••••••••••••

Environment name

production
  1. In TrustBill, open Settings → Business Central and click Get started.
  2. Paste the four values. The Connect screen now shows a 5-stage checklist (Form validation → Entra token → BC authentication → BC authorization → Save connection) — a red ✗ tells you exactly which stage failed and how to fix it.
  3. Pick the BC Company to sync (you can add more later).
  4. Click Start sync. Sales invoices posted in BC will start flowing within a few minutes.

If something doesn't work

When you click Connect in TrustBill, the screen shows a 5-stage checklist (Form validation → Entra token → BC authentication → BC authorization → Save connection). The red ✗ tells you which stage failed. Match it to the sections below.

Stage 2 failed — "Business Central rejected your credentials."

  • Secret ID vs Secret Value mix-up. You pasted a UUID like fea75778-279b-4f10-b99b-d8e481a40e14 — that's the Secret ID, not the Value. Create a new secret in Azure and copy the Value column (long string with ~, ., -, _). See Step 1b above.
  • Secret expired. Azure client secrets expire on the schedule you picked at creation (default 24 months). Rotate the secret in Azure → Certificates & secrets, and re-paste. Everything else stays as-is.

Stage 3 failed — "BC auth refused the token"

  • Grant Consent inside BC was never done. Granting admin consent in Azure (Step 2) is not the same as clicking Grant Consent on the TrustBill Connector card inside BC (Step 3e). You need both.
  • Grant Consent was clicked before the permission set was added. BC's consent captures permissions at click time — adding the permission set afterwards doesn't retroactively update the consent. Fix: do the Full Reset procedure below.
  • Error AADSTS500113: No reply address registered. You skipped Step 1c. Go to Azure → your app → Authentication → add platform Web with redirect URI https://businesscentral.dynamics.com/OAuthLanding.htm.

Stage 4 failed — "BC accepted the token but denied the request"

  • Permission set too narrow or missing. The TrustBill Connector user needs D365 BUS FULL ACCESS (or D365 BUS PREMIUM on BC v23+). Open the TrustBill Connector card in BC, set State = Disabled, add the permission set, set State = Enabled, re-grant consent.
  • Admin consent on app_access was not granted in Azure. Go back to Step 2 and look for the green tick next to app_access.

Full reset — do this if 401 persists after fixing the obvious things

BC's Service Principal (SPN) mapping can get stuck when consent is granted in the wrong order. The only fix is to delete the SPN in Azure, delete the record in BC, and recreate both from scratch in the correct order. Takes ~3 minutes.

  1. Delete the SPN in Azure. Open Enterprise Applications. Search TrustBill Connector, click the row, then Properties → Delete → confirm. This only removes the SPN; your App Registration (with Client ID + Secret) stays intact.
  2. Delete the record in BC. BC → Microsoft Entra Applications → click the TrustBill Connector row → Delete (trash icon) → confirm.
  3. Recreate in BC — in this exact order: + New → paste Client ID → set Description → leave State = Disabled → add permission set → then set State = Enabled → then click Grant Consent → sign in → Accept.

Still stuck? Open a Microsoft Business Central support ticket

If the full-reset procedure above doesn't clear it, the issue is on Microsoft's side (environment-level API gate or stuck SPN mapping). Only Microsoft support can see the real reason — the error message BC returns is deliberately vague for security reasons; the actual rejection reason is in Microsoft's internal logs, keyed by the Correlation ID shown in TrustBill's error card.

  1. Open admin.microsoft.com → Support → New service request.
  2. Product: Dynamics 365 Business Central.
  3. Paste this description:
    Service-to-service (client credentials) authentication is being rejected with HTTP 401 "Authentication_InvalidCredentials" on all Business Central API endpoints, despite a correctly configured Microsoft Entra Application with Grant Consent completed and D365 BUS FULL ACCESS attached. Entra issues a valid token with roles: ['app_access']. BC rejects the token itself before permission evaluation. Tenant: <your tenant GUID> Environment: Production BC version: <see Admin Center> Correlation IDs: <paste from TrustBill's error card>
  4. Microsoft usually responds within one business day. The fix on their side is a tenant-level SPN reset not exposed in the Admin Center UI.

Ready to connect?

Once you've pasted your Azure credentials the sync starts within a few minutes. You keep working in Business Central exactly as you do today.