XrmToolSuite.TeamPermissionExplorer
1.2026.7.10
dotnet add package XrmToolSuite.TeamPermissionExplorer --version 1.2026.7.10
NuGet\Install-Package XrmToolSuite.TeamPermissionExplorer -Version 1.2026.7.10
<PackageReference Include="XrmToolSuite.TeamPermissionExplorer" Version="1.2026.7.10" />
<PackageVersion Include="XrmToolSuite.TeamPermissionExplorer" Version="1.2026.7.10" />
<PackageReference Include="XrmToolSuite.TeamPermissionExplorer" />
paket add XrmToolSuite.TeamPermissionExplorer --version 1.2026.7.10
#r "nuget: XrmToolSuite.TeamPermissionExplorer, 1.2026.7.10"
#:package XrmToolSuite.TeamPermissionExplorer@1.2026.7.10
#addin nuget:?package=XrmToolSuite.TeamPermissionExplorer&version=1.2026.7.10
#tool nuget:?package=XrmToolSuite.TeamPermissionExplorer&version=1.2026.7.10
👥 Team Permission Explorer
An XrmToolBox plugin that makes team access, membership, and inheritance visible and reviewable — a per-team profile (members, roles, effective privileges, owned records, inheriting users) plus a risk-findings list — so you can find over-privileged, empty, and orphaned teams. Read-only; only names and counts are emitted, no secrets.
Features
- Browse & filter teams — the full team list loads via
RetrieveAll, filterable by team type (owner / access / AAD security / AAD office); the filter and last selection persist in settings. An in-memory search box filters the loaded grid by name or business unit instantly (no re-query). - Members & roles — a members grid and an assigned-roles grid per team, with member and role counts in the team header; members are fetched lazily off the UI thread.
- Effective table-privilege matrix — resolved via the shared
PrivilegeEngine.ResolveEffectiveover the team's grants (deepest scope per privilege), so you see resolved access, not just role names. - Inheritance — the list of users inheriting the team's permissions (team members via teammembership → systemuser).
- Owned records — a summary of team-owned records by table, using aggregate/count FetchXML grouped by
owningteam(no full retrieves); a failed table degrades to 0. - Risk findings — teams flagged for cleanup, each with a severity and its evidence
(rules in
TeamRiskRules):- No members (non-AAD) → Medium
- No roles → Medium
- Over-privileged (Deep/Global on ≥10 privileges) → High
- Duplicate role (same role via multiple teams / listed twice) → Low
- Orphaned (0 members AND 0 owned records) → Medium
- otherwise → Info "No team risks detected"
- Compare two teams — diff two teams' effective privileges (
PrivilegeEngine.Diff) plus the roles unique to each side, to consolidate duplicates.
The tool shares the effective-privilege engine (XrmToolSuite.Core.Privileges) with the Privilege Gap
Analyzer (SEC01) rather than re-deriving privileges. The collector never throws — per-source failures become
progress notes / Info findings.
Exports
Excel, PDF, CSV, and HTML. A ReportModel drives the shared Excel (ClosedXML) and native PDF
(PdfSharp/MigraDoc-GDI) exporters; CSV/HTML via BCL writers. Only names and counts are emitted (no secrets).
Help & Support
A right-aligned Help button opens a Help & Support dialog with Documentation, Report an issue,
and a support link, each opened in the browser. The tool implements IHelpPlugin and IGitHubPlugin, so
XrmToolBox's own tool-menu links resolve to the same GitHub project (kkora/XrmToolSuite).
Build & install
This tool is not a single-DLL tool — it ships the Excel/PDF export dependency chains (the ClosedXML + PdfSharp/MigraDoc-GDI DLLs). The one-step build copies the whole chain into the XrmToolBox Plugins root for you:
dotnet build src\Tools\XrmToolSuite.TeamPermissionExplorer\XrmToolSuite.TeamPermissionExplorer.csproj -c Release -p:DeployToXTB=true
Then restart XrmToolBox and open Team Permission Explorer. For a manual copy to another machine, copy
every DLL from the tool's bin\Release\net48\ folder — flat in the Plugins root, never a subfolder — or
XrmToolBox silently drops the tool. Full details in ./DEPLOYMENT.md and the suite guide
Deployment_Guide_XrmToolBox.md.
Usage
- Connect to your environment (System Customizer or higher recommended).
- Load teams; filter by team type and/or search by name/business unit, then select a team.
- Review its members, roles, effective privilege matrix, owned-record counts, and risk findings.
- (Optional) Compare against a second team to spot duplicates.
- Export the team security report in any of the supported formats.
Notes & limitations
- Read-only; only names and counts are exported — no secrets.
- One blocked table does not abort the scan: the collector degrades a failed query to an informational finding / progress note.
- SDK-free risk rules are unit-tested in
testing/UnitTests/TeamPermissionExplorerTests.cs.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET Framework | net48 is compatible. net481 was computed. |
-
- XrmToolBox (>= 1.2025.10.74)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.2026.7.10 | 154 | 7/11/2026 |
| 1.2026.7.9 | 123 | 7/11/2026 |
| 1.2026.7.8 | 129 | 7/11/2026 |
| 1.2026.7.7 | 126 | 7/11/2026 |
| 1.2026.7.6 | 126 | 7/10/2026 |
| 1.2026.7.5 | 118 | 7/9/2026 |
| 1.2026.7.3 | 127 | 7/7/2026 |
1.2026.7.10: Package health - deterministic CI builds with SourceLink and embedded symbols (PDB inside the DLL), and the package now links its GitHub source repository. No functional change to any tool.