Skip to main content
Audience: Dynamics 365 administrators, Microsoft Entra administrators, IT security reviewers, and Noux customers setting up the integration The integration connects a Dynamics 365 Sales environment to a Noux organization and adds a Noux panel to the Opportunity form. A seller sees either Create room for this deal or the room card with its stats, Edit room and Preview room.

1. Overview

1.1 What the integration does

  • Connects one Dynamics 365 Sales environment to one Noux organization through Microsoft sign-in (OAuth 2.0)
  • Creates or links a Noux Sales Room for a Dynamics Opportunity
  • Shows the room and its visit statistics on the Opportunity form, through the Noux panel
  • Writes notes to the Opportunity Timeline when things happen in the room

1.2 The two parts

The panel needs the connection. The connection works without the panel: rooms can be linked to Opportunities from Noux, and notes are written to the Timeline.

1.3 Security model at a glance

  • OAuth 2.0 authorization code flow with PKCE (S256), for both the connection and each seller’s panel sign-in
  • Every seller signs in to Microsoft from the panel, and Noux checks that seller’s read access to the Opportunity in Dynamics before showing anything
  • Access is re-checked every 15 seconds while the panel is visible
  • Noux does not store sellers’ Microsoft tokens
  • All Dynamics API calls are made by the Noux backend, never by the browser
  • One Dynamics environment can be connected to only one Noux organization at a time
  • The solution contains no secrets

2. Requirements

Sellers do not need a Noux account to see the panel or to open Preview room. A Noux account is required only for Create room, Edit room and the Settings link.

3. Permissions

3.1 What Noux asks Microsoft for

Noux uses one Microsoft Entra application, Noux Dynamics Integration. It requests delegated permissions only, so Noux always acts as a signed-in user and never with application-wide rights.

3.2 Why the connection account needs broad read access

Noux uses the connection account to ask Dynamics two questions about each seller: is this user still enabled, and can this user read this Opportunity? Answering them for other users requires organization-level Read on Opportunity and User. A seller-level account may work for its own records, but it cannot reliably check other users’ access, and those sellers see Noux Dynamics connection needs to be reconnected. The same account writes the Timeline notes, so the notes appear in Dynamics as created by that account. The first sign-in in a tenant needs consent to the permissions above. Most organizations block ordinary users from granting it. Those sellers see Microsoft’s “Need admin approval” screen, and the panel says Your organization’s IT administrator needs to approve Noux before you can sign in. An administrator grants consent once, in either way:
  • While connecting Dynamics in Noux: tick Consent on behalf of your organization on the Microsoft screen.
  • In the Entra admin center, at any time: Identity → Applications → Enterprise applications → Noux Dynamics Integration → Permissions → Grant admin consent.
Consent does not give Noux access to data on its own. Every panel request still depends on the signed-in seller’s own Dynamics permissions.

3.4 Permissions in Noux

  • Managing the Dynamics connection requires a signed-in member of the Noux organization.
  • Linking a room to an Opportunity requires permission to edit that room in Noux.
  • Integration data is scoped to the Noux organization that owns the connection.

4. How it works

4.1 Components

  1. Noux application (https://noux.app) — handles Microsoft sign-in, the connection, room creation and linking, and all Dynamics API calls.
  2. Noux database (PostgreSQL on Aiven, EU) — stores the connection, room-to-Opportunity links and panel sessions.
  3. Noux Dynamics Opportunity Panel — a managed Power Apps solution (publisher Noux Digital Oy) with one code component and one placeholder column, noux_panelhost.
  4. Microsoft identity platform and Dataverse Web API — sign-in and the Dynamics data API.

4.2 Connecting Dynamics

  1. A Noux user selects Connect Dynamics 365 and signs in to Microsoft.
  2. Noux lists the Dynamics environments that account can use, and the user chooses one.
  3. Noux stores the connection for that environment and starts using it for access checks, Opportunity lookups and Timeline notes.
The flow uses PKCE and a single-use, server-side state. Noux refreshes the connection’s access token as needed. If the refresh stops working, for example after a password change or a revoked consent, settings and the panel ask for a reconnect.

4.3 Seller sign-in from the panel

  1. The seller selects Sign in to Noux in the panel. A Microsoft pop-up opens.
  2. The panel starts the sign-in with a form submission from the Dynamics page to Noux. Noux accepts it only from the connected environment’s own address.
  3. Microsoft returns the result to Noux. Noux reads which Dynamics user signed in, then discards the Microsoft token.
  4. Noux gives the panel a short-lived credential and a random renewal handle, which the panel keeps in the browser.
The session stays active while the seller keeps using the panel. It ends after 7 days without panel use or after 30 days in total, whichever comes first. A seller must also sign in again in a new browser or private window, when a different Dynamics user opens the panel in the same browser, or after Dynamics was disconnected in Noux.

4.4 Access checks

Each time the panel loads data, and every 15 seconds while it is visible, Noux asks Dynamics whether the seller is still an enabled user and can still read that Opportunity. If not, the panel stops showing the room. When a record is reassigned away from a seller, the panel reflects it within about 15 seconds. The panel pauses in a hidden tab.

4.5 Data read from Dynamics

  • Opportunity: ID, name, status, and the ID and name of its account. Used to name a new room (“Account — Opportunity”) and to link it.
  • User: the seller’s Dynamics user ID and whether the user is disabled.
  • Access: whether that user can read the Opportunity.
  • Environments: the list of environments available to the connection account, during connection only.
There is no bulk export or scheduled sync. Reads happen when a room is created or linked, and while a panel is open.

4.6 Data written to Dynamics

Noux creates notes on the Opportunity Timeline. It does not update Opportunity fields or create any other records. Note content is sanitized before it is sent.

4.7 What Noux stores

  • Connection: the environment’s organization ID, name, address and Microsoft tenant ID, and the connection account’s access and refresh tokens
  • Room links: which Opportunity ID belongs to which Noux room (one room per Opportunity)
  • Panel sessions: a hash of the renewal handle, the seller’s Dynamics user ID, the environment and an expiry time. No Microsoft token for the seller.
  • Audit trail: who connected, reconnected and disconnected Dynamics, and when
Tokens are stored in PostgreSQL on Aiven (EU), encrypted at rest by the platform, and reached over TLS. The Microsoft client secret is kept in Noux’s hosting configuration. It is not in the database and not in the solution.

4.8 What stays in the seller’s browser

The panel keeps a random renewal handle in the browser for up to 30 days. Other scripts or customizations running on the same Dynamics site could read it. The handle gives access only to panel data and room preview links for Opportunities the seller can read, and Noux keeps re-checking that access.

5. Set up the integration

5.1 Connect Dynamics in Noux

  1. In Noux, open Settings → Integrations → Dynamics 365.
  2. Select Connect Dynamics 365 and sign in with the connection account (see section 2).
  3. Choose the environment when asked.
Any member of the Noux organization can start this flow, but they must pick a sufficiently privileged Microsoft account when Microsoft asks which account to use. Settings then show who connected Dynamics and when.

5.2 Import the solution

Noux sends a managed solution file named like NouxDynamicsOpportunityPanel_1_0_0_0_managed.zip.
  1. Open make.powerapps.com and select the Dynamics 365 Sales environment (top right).
  2. Go to Solutions → Import solution → Browse, choose the file, then Next → Import.
  3. Wait for “Import successful”. The solution appears as Noux Dynamics Opportunity Panel, publisher Noux Digital Oy.
The solution does not change any form, view, security role, workflow or app by itself.

5.3 Put the panel on the Opportunity forms

Do this for every Opportunity main form your sellers open. Administrators usually see more forms than sellers do, so check which forms the sales roles use.
  1. In Power Apps, go to Tables → Opportunity → Forms.
  2. Open an Opportunity main form used by sellers.
  3. Add a section where the panel should appear. A one-column section works best.
  4. From the field list, drag noux_panelhost into that section.
  5. With the field selected, open Components → + Component → Noux Opportunity Panel, tick Web, and select Done.
  6. Tick Hide label for the field, so only the panel is visible.
  7. Save, then Publish.
  8. Repeat for every other seller-visible Opportunity main form.
The field is a placeholder. The panel never reads or writes its value. Also confirm that the app your sellers use includes the form you edited, and that the form’s security roles include the sellers’ roles.

5.4 Check it as a seller

Sign in as a non-administrator seller, ideally in a private window, and open an Opportunity they own.
  1. The panel shows Sign in required. Select Sign in to Noux.
  2. A Microsoft pop-up appears. It closes automatically after a successful sign-in.
  3. The panel shows the room card, or Create room for this deal when the Opportunity has no room yet.
To link a room that already exists, open the room’s settings in Noux, go to the Dynamics 365 section and enter the Opportunity ID. You find the ID in the address of the Opportunity in Dynamics (id=...).

6. What sellers see

7. Upgrade, disconnect and uninstall

Upgrade. Import the newer file the same way as in section 5.2. Do not delete the existing solution first. Form placement, sellers’ sign-ins and linked rooms survive an upgrade. Sellers may need one hard refresh (Ctrl/Cmd+Shift+R) afterwards. Disconnect. Disconnecting in Noux → Settings → Integrations → Dynamics 365 removes the stored tokens and all seller sessions, unlinks every room from its Opportunity, and releases the environment so that another Noux organization can connect it. The rooms and their content are not deleted. Reconnecting later does not restore the links. Before you confirm, Noux lists the rooms that will be unlinked. Uninstall the panel.
  1. Remove the noux_panelhost field and its section from every form it was added to, then save and publish each form.
  2. Go to Solutions, select Noux Dynamics Opportunity Panel, and choose Delete.
Dynamics refuses the delete while the field is still on any form. Deleting the solution removes the panel and the placeholder column. Noux rooms and Opportunity data are untouched. To also remove Noux’s permissions, delete Noux Dynamics Integration under Enterprise applications in the Entra admin center.

8. Troubleshooting

9. Limits

  • English only. The panel and solution labels are English regardless of the user’s language.
  • Manual form placement. The solution does not edit standard forms.
  • Desktop browsers. Chrome and Edge are verified. The Dynamics mobile app is not supported.
  • Restrictive Content Security Policy. An enforced form-action that excludes https://noux.app blocks the panel sign-in.
  • Accounts blocked only in Entra. Noux checks whether the Dynamics user is disabled. If an account is blocked in Microsoft Entra but its Dynamics user stays enabled, an existing panel session can continue until Dynamics reflects the change or the session reaches its 30-day maximum.
  • One environment per Noux organization, and one Noux organization per environment.