How does this affect me?
When a record is routed, the user that triggered action must have read access to the record being routed and the workstream to which the record is being routed. This requirement is not currently enforced.
Starting on the enforcement date, any routing triggered by a user who lacks read access on the record or the target workstream will be rejected with the message, "You do not have sufficient privileges to route this record."
This applies whenever a user account performs an action that triggers record routing, including when it is routed:
- through the Save & Route button in the UI,
- automatically via the route case attribute (attribute-based routing), or
- through the msdyn_ApplyRoutingRuleEntityRecord API (e.g., from a workflow, a Power Automate flow, custom plug-in, or custom code).
What action do I need to take?
Please review your routing scenarios and ensure the executing/calling user (or the account/connection under which the automation runs) has been granted a security role that provides read access to:
- The entity/table of the records being routed.
- The Workstream table (the specific workstreams targeted for routing).
If you need further assistance, please contact Microsoft Support.