1. Overview
1.1 What the integration does
- Connects one Dynamics 365 Sales environment to one Noux organization through Microsoft sign-in (OAuth 2.0)
- Creates or links a Noux Sales Room for a Dynamics Opportunity
- Shows the room and its visit statistics on the Opportunity form, through the Noux panel
- Writes notes to the Opportunity Timeline when things happen in the room
1.2 The two parts
The panel needs the connection. The connection works without the panel: rooms can be linked to Opportunities from Noux, and notes are written to the Timeline.
1.3 Security model at a glance
- OAuth 2.0 authorization code flow with PKCE (S256), for both the connection and each seller’s panel sign-in
- Every seller signs in to Microsoft from the panel, and Noux checks that seller’s read access to the Opportunity in Dynamics before showing anything
- Access is re-checked every 15 seconds while the panel is visible
- Noux does not store sellers’ Microsoft tokens
- All Dynamics API calls are made by the Noux backend, never by the browser
- One Dynamics environment can be connected to only one Noux organization at a time
- The solution contains no secrets
2. Requirements
Sellers do not need a Noux account to see the panel or to open Preview room. A Noux account is required only for Create room, Edit room and the Settings link.
3. Permissions
3.1 What Noux asks Microsoft for
Noux uses one Microsoft Entra application, Noux Dynamics Integration. It requests delegated permissions only, so Noux always acts as a signed-in user and never with application-wide rights.3.2 Why the connection account needs broad read access
Noux uses the connection account to ask Dynamics two questions about each seller: is this user still enabled, and can this user read this Opportunity? Answering them for other users requires organization-level Read on Opportunity and User. A seller-level account may work for its own records, but it cannot reliably check other users’ access, and those sellers see Noux Dynamics connection needs to be reconnected. The same account writes the Timeline notes, so the notes appear in Dynamics as created by that account.3.3 Admin consent in Microsoft Entra
The first sign-in in a tenant needs consent to the permissions above. Most organizations block ordinary users from granting it. Those sellers see Microsoft’s “Need admin approval” screen, and the panel says Your organization’s IT administrator needs to approve Noux before you can sign in. An administrator grants consent once, in either way:- While connecting Dynamics in Noux: tick Consent on behalf of your organization on the Microsoft screen.
- In the Entra admin center, at any time: Identity → Applications → Enterprise applications → Noux Dynamics Integration → Permissions → Grant admin consent.
3.4 Permissions in Noux
- Managing the Dynamics connection requires a signed-in member of the Noux organization.
- Linking a room to an Opportunity requires permission to edit that room in Noux.
- Integration data is scoped to the Noux organization that owns the connection.
4. How it works
4.1 Components
- Noux application (
https://noux.app) — handles Microsoft sign-in, the connection, room creation and linking, and all Dynamics API calls. - Noux database (PostgreSQL on Aiven, EU) — stores the connection, room-to-Opportunity links and panel sessions.
- Noux Dynamics Opportunity Panel — a managed Power Apps solution (publisher Noux Digital Oy) with one code component and one placeholder column,
noux_panelhost. - Microsoft identity platform and Dataverse Web API — sign-in and the Dynamics data API.
4.2 Connecting Dynamics
- A Noux user selects Connect Dynamics 365 and signs in to Microsoft.
- Noux lists the Dynamics environments that account can use, and the user chooses one.
- Noux stores the connection for that environment and starts using it for access checks, Opportunity lookups and Timeline notes.
state. Noux refreshes the connection’s access token as needed. If the refresh stops working, for example after a password change or a revoked consent, settings and the panel ask for a reconnect.
4.3 Seller sign-in from the panel
- The seller selects Sign in to Noux in the panel. A Microsoft pop-up opens.
- The panel starts the sign-in with a form submission from the Dynamics page to Noux. Noux accepts it only from the connected environment’s own address.
- Microsoft returns the result to Noux. Noux reads which Dynamics user signed in, then discards the Microsoft token.
- Noux gives the panel a short-lived credential and a random renewal handle, which the panel keeps in the browser.
4.4 Access checks
Each time the panel loads data, and every 15 seconds while it is visible, Noux asks Dynamics whether the seller is still an enabled user and can still read that Opportunity. If not, the panel stops showing the room. When a record is reassigned away from a seller, the panel reflects it within about 15 seconds. The panel pauses in a hidden tab.4.5 Data read from Dynamics
- Opportunity: ID, name, status, and the ID and name of its account. Used to name a new room (“Account — Opportunity”) and to link it.
- User: the seller’s Dynamics user ID and whether the user is disabled.
- Access: whether that user can read the Opportunity.
- Environments: the list of environments available to the connection account, during connection only.
4.6 Data written to Dynamics
Noux creates notes on the Opportunity Timeline. It does not update Opportunity fields or create any other records.
Note content is sanitized before it is sent.
4.7 What Noux stores
- Connection: the environment’s organization ID, name, address and Microsoft tenant ID, and the connection account’s access and refresh tokens
- Room links: which Opportunity ID belongs to which Noux room (one room per Opportunity)
- Panel sessions: a hash of the renewal handle, the seller’s Dynamics user ID, the environment and an expiry time. No Microsoft token for the seller.
- Audit trail: who connected, reconnected and disconnected Dynamics, and when
4.8 What stays in the seller’s browser
The panel keeps a random renewal handle in the browser for up to 30 days. Other scripts or customizations running on the same Dynamics site could read it. The handle gives access only to panel data and room preview links for Opportunities the seller can read, and Noux keeps re-checking that access.5. Set up the integration
5.1 Connect Dynamics in Noux
- In Noux, open Settings → Integrations → Dynamics 365.
- Select Connect Dynamics 365 and sign in with the connection account (see section 2).
- Choose the environment when asked.
5.2 Import the solution
Noux sends a managed solution file named likeNouxDynamicsOpportunityPanel_1_0_0_0_managed.zip.
- Open make.powerapps.com and select the Dynamics 365 Sales environment (top right).
- Go to Solutions → Import solution → Browse, choose the file, then Next → Import.
- Wait for “Import successful”. The solution appears as Noux Dynamics Opportunity Panel, publisher Noux Digital Oy.
5.3 Put the panel on the Opportunity forms
Do this for every Opportunity main form your sellers open. Administrators usually see more forms than sellers do, so check which forms the sales roles use.- In Power Apps, go to Tables → Opportunity → Forms.
- Open an Opportunity main form used by sellers.
- Add a section where the panel should appear. A one-column section works best.
- From the field list, drag noux_panelhost into that section.
- With the field selected, open Components → + Component → Noux Opportunity Panel, tick Web, and select Done.
- Tick Hide label for the field, so only the panel is visible.
- Save, then Publish.
- Repeat for every other seller-visible Opportunity main form.
5.4 Check it as a seller
Sign in as a non-administrator seller, ideally in a private window, and open an Opportunity they own.- The panel shows Sign in required. Select Sign in to Noux.
- A Microsoft pop-up appears. It closes automatically after a successful sign-in.
- The panel shows the room card, or Create room for this deal when the Opportunity has no room yet.
5.5 Link an existing room
To link a room that already exists, open the room’s settings in Noux, go to the Dynamics 365 section and enter the Opportunity ID. You find the ID in the address of the Opportunity in Dynamics (id=...).
6. What sellers see
7. Upgrade, disconnect and uninstall
Upgrade. Import the newer file the same way as in section 5.2. Do not delete the existing solution first. Form placement, sellers’ sign-ins and linked rooms survive an upgrade. Sellers may need one hard refresh (Ctrl/Cmd+Shift+R) afterwards. Disconnect. Disconnecting in Noux → Settings → Integrations → Dynamics 365 removes the stored tokens and all seller sessions, unlinks every room from its Opportunity, and releases the environment so that another Noux organization can connect it. The rooms and their content are not deleted. Reconnecting later does not restore the links. Before you confirm, Noux lists the rooms that will be unlinked. Uninstall the panel.- Remove the noux_panelhost field and its section from every form it was added to, then save and publish each form.
- Go to Solutions, select Noux Dynamics Opportunity Panel, and choose Delete.
8. Troubleshooting
9. Limits
- English only. The panel and solution labels are English regardless of the user’s language.
- Manual form placement. The solution does not edit standard forms.
- Desktop browsers. Chrome and Edge are verified. The Dynamics mobile app is not supported.
- Restrictive Content Security Policy. An enforced
form-actionthat excludeshttps://noux.appblocks the panel sign-in. - Accounts blocked only in Entra. Noux checks whether the Dynamics user is disabled. If an account is blocked in Microsoft Entra but its Dynamics user stays enabled, an existing panel session can continue until Dynamics reflects the change or the session reaches its 30-day maximum.
- One environment per Noux organization, and one Noux organization per environment.