
A step-by-step guide for SME admins. About 15 minutes, done once. After this, sales invoices posted in Business Central flow to the UAE FTA automatically.
~15 minutes, one time
Register app, grant permission, paste credentials. No coding.
Your creds stay in your tenant
You register in your own Entra tenant. We never see your Microsoft password.
Zero clicks per invoice
Post in BC as usual — we pick it up and file with the FTA in minutes.
Before you start
About 6 min
Sign in to the Azure portal with an account that can register apps in your Microsoft tenant. Then create a new App Registration — TrustBill will use it to read invoices from Business Central.
1a. Create the App Registration
TrustBill Connector.1b. Create a Client Secret — read this carefully
TrustBill sync. Expiry: 24 months. Click Add.~, dots ., hyphens - and underscores _ (about 40 characters). This is what TrustBill needs.⚠ Do NOT copy the Secret ID column by mistake
The Secret ID column shows a UUID (e.g. fea75778-279b-4f10-b99b-d8e481a40e14). This is not the secret TrustBill wants — it's just an identifier for the row.
A real Client Secret Value looks like this:KUs8Q~-gPHYt.CNo3FhADz~YQEjA3BnjsjZ_YcxH
If what you copied looks like a UUID (xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx), you grabbed the wrong column. Create a new secret and copy the Value column instead — Azure masks the Value after you leave the page, so the old row cannot be recovered.
Tip · If you leave the secret page without copying the value, Azure won't show it again. Just create another secret — the old one can be deleted safely as long as no other app uses it.
1c. Add a Redirect URI for Business Central consent
TrustBill itself uses the client-credentials flow (no redirect needed), but Business Central's "Grant Consent" button requires one. Without it, you'll hit error AADSTS500113: No reply address is registered in Step 3.
https://businesscentral.dynamics.com/OAuthLanding.htmAbout 2 min
Now tell Microsoft that this app is allowed to read Business Central data on your organisation's behalf.
app_access, and add it.app_access.Tip · The "Grant admin consent" button requires a Global Admin. If your account can't grant it, ask an admin to click that one button. Nothing else about the setup requires admin rights afterwards.
About 5 min
Microsoft has now allowed the app at the tenant level. Business Central also needs to know it should trust this app — a separate step inside BC itself. The order of the clicks below matters — do them exactly as written or BC will reject the app at run time with a 401 error that is hard to recover from.
⚠ Why the order matters
Business Central's "Grant Consent" button takes a snapshot of whatever permission sets are attached at the moment you click it. If you click Grant Consent before adding D365 BUS FULL ACCESS, BC consents to an empty permission set and TrustBill will get a 401 on every call, even though everything looks correct afterwards.
The fix in that case is a full reset (see Troubleshooting at the bottom of this page) — avoid it by following the order below.
3a. Open the Microsoft Entra Applications page
3b. Create the record (keep State = Disabled for now)
TrustBill Connector.3c. Attach a permission set (now, while State = Disabled)
D365 BUS FULL ACCESS and pick it from the dropdown. On BC v23 and newer the equivalent may be called D365 BUS PREMIUM — if D365 BUS FULL ACCESS is not in the dropdown, use Premium instead.BC v23+ blocks SUPER on application users
If someone tells you to use SUPER for the TrustBill Connector, BC will refuse — SUPER has been locked for Entra app users since BC 23 for security. Use D365 BUS FULL ACCESS or D365 BUS PREMIUM instead.
3d. NOW set State = Enabled
3e. LAST — click Grant Consent in the ribbon
If you see AADSTS500113 (No reply address registered)
You missed sub-step 1c. Go back to Azure Portal → your app → Authentication → add platform Web with redirect URI https://businesscentral.dynamics.com/OAuthLanding.htm. Then come back and click Grant Consent again.
About 1 min
TrustBill needs to know which BC environment to talk to (most SMEs have just one; some have a sandbox alongside production).
production for the live tenant. Copy that word exactly (lower case).Microsoft's admin center environments guide also lists all your environments if you can't find it in-app.
About 2 min
You should now have four values on your scratch pad. Open TrustBill and paste them into the wizard.
Directory (tenant) ID
00000000-0000-0000-0000-000000000000Application (client) ID
00000000-0000-0000-0000-000000000000Client secret
•••••••••••••••••••••••••••••Environment name
productionWhen you click Connect in TrustBill, the screen shows a 5-stage checklist (Form validation → Entra token → BC authentication → BC authorization → Save connection). The red ✗ tells you which stage failed. Match it to the sections below.
fea75778-279b-4f10-b99b-d8e481a40e14 — that's the Secret ID, not the Value. Create a new secret in Azure and copy the Value column (long string with ~, ., -, _). See Step 1b above.https://businesscentral.dynamics.com/OAuthLanding.htm.D365 BUS FULL ACCESS (or D365 BUS PREMIUM on BC v23+). Open the TrustBill Connector card in BC, set State = Disabled, add the permission set, set State = Enabled, re-grant consent.app_access was not granted in Azure. Go back to Step 2 and look for the green tick next to app_access.BC's Service Principal (SPN) mapping can get stuck when consent is granted in the wrong order. The only fix is to delete the SPN in Azure, delete the record in BC, and recreate both from scratch in the correct order. Takes ~3 minutes.
If the full-reset procedure above doesn't clear it, the issue is on Microsoft's side (environment-level API gate or stuck SPN mapping). Only Microsoft support can see the real reason — the error message BC returns is deliberately vague for security reasons; the actual rejection reason is in Microsoft's internal logs, keyed by the Correlation ID shown in TrustBill's error card.
Service-to-service (client credentials) authentication is being rejected
with HTTP 401 "Authentication_InvalidCredentials" on all Business Central
API endpoints, despite a correctly configured Microsoft Entra Application
with Grant Consent completed and D365 BUS FULL ACCESS attached. Entra
issues a valid token with roles: ['app_access']. BC rejects the token
itself before permission evaluation.
Tenant: <your tenant GUID>
Environment: Production
BC version: <see Admin Center>
Correlation IDs: <paste from TrustBill's error card>Once you've pasted your Azure credentials the sync starts within a few minutes. You keep working in Business Central exactly as you do today.