{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "dynamics-365-sales",
    "name": "Microsoft Dynamics 365 Sales",
    "vendor": "Microsoft",
    "vendorUrl": "https://www.microsoft.com/dynamics-365/products/sales",
    "kind": "http-api",
    "category": "crm",
    "summary": "Microsoft's sales CRM for accounts, contacts, leads and opportunities. Its data is held in Dataverse and reached through the Dataverse Web API (OData v4), SDKs for .NET and Python, and the Dataverse MCP server.",
    "url": "https://www.anchorterminal.com/tools/dynamics-365-sales",
    "markdownUrl": "https://www.anchorterminal.com/tools/dynamics-365-sales.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dynamics-365-sales.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dynamics-365-sales.json",
    "repo": "https://github.com/microsoft/PowerPlatform-DataverseClient-Python",
    "license": "Proprietary service under the Microsoft Product Terms. The Python SDK and the @microsoft/dataverse npm package are MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "packages": [
      {
        "registry": "pypi",
        "name": "PowerPlatform-Dataverse-Client"
      },
      {
        "registry": "npm",
        "name": "@microsoft/dataverse"
      },
      {
        "registry": "nuget",
        "name": "Microsoft.PowerPlatform.Dataverse.Client"
      }
    ],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 through Microsoft Entra ID is the only route. A person registers an app in the customer's Entra tenant. For delegated access it takes the Dynamics 365 delegated permission (access as organisation users) and the scope `\u003cenvironment-url\u003e/user_impersonation`. For server-to-server access an administrator creates an application user with a security role, and the app uses a client secret or certificate with `\u003cenvironment-url\u003e/.default`. The Dataverse MCP server takes the `mcp.tools` permission, and a Power Platform administrator must allow each client app ID per environment. Only Copilot Studio is allowed by default. No API-key path.",
    "pricing": "paid",
    "pricingNotes": "Sales Professional $65, Enterprise $105 and Premium $150 a user a month, paid yearly, per the pricing page, which says prices vary by country. The Web API has no separate charge. An application user needs no paid licence and draws on a tenant pool of requests. Since 15 December 2025, Dataverse MCP calls from agents built outside Copilot Studio are billed in Copilot Credits unless the user holds a Dynamics 365 Premium or Microsoft 365 Copilot licence. A 30-day trial and the free Power Apps Developer Plan let a team start without a contract. Card requirements were not stated (checked 2026-10-08).",
    "priceSummary": "$65 / seat-mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Dataverse Web API docs, the Dataverse MCP docs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 15,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 2921,
      "pypiWeekly": 10702,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview",
    "capabilities": [
      "crm.records",
      "crm.pipeline",
      "crm.activities",
      "crm.search",
      "crm.webhooks"
    ],
    "tags": [
      "hosted",
      "official",
      "oauth",
      "enterprise",
      "mcp",
      "odata",
      "webhooks",
      "python",
      "dotnet",
      "closed-source",
      "sla",
      "audit-log"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 69.7,
      "grade": "B",
      "agentReady": false,
      "rank": 150,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 86,
        "maintenance": 79,
        "payments": 25,
        "reliability": 65,
        "schema": 81,
        "security": 74,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Graded on the Dataverse Web API, with the Dataverse MCP server noted. Service health for a tenant is in the Power Platform and Microsoft 365 admin centres, behind an admin sign-in. The unauthenticated page at status.cloud.microsoft exists, and Microsoft's docs describe it as the place for updates when the admin portals are unavailable. It rendered no components for our reader (10 of 20, a departure from the full 20 because the page with history needs a login). No readable incident history (5). Service protection limits are published per user and web server at 6,000 requests and 20 minutes of execution time per five-minute window, and 52 concurrent requests, plus 40,000 requests per licensed user per 24 hours (15). 429 responses carry Retry-After with retry guidance, and upsert on alternate keys with If-Match gives safe retries for writes (15). The SLA for Microsoft Online Services dated 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Sales Enterprise and Professional (10). Web API v9.2 and the MCP endpoint /api/mcp are generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "Each environment serves an OData v4 service document and a CSDL $metadata document at /api/data/v9.2/$metadata, and Learn publishes a table reference. No public OpenAPI document was found (18 of 25). learn.microsoft.com/llms.txt returns 404, but Learn returns Markdown for requests with `Accept: text/markdown`, which is how we read every page (10). The docs state purpose and limits, such as no `$skip` and a 5,000-row page ceiling. The published MCP tool descriptions are one line each (15 of 20). Entity types are typed in CSDL, but queries are OData strings and the MCP `read_query` tool takes a SQL SELECT string (12 of 15). Request and response examples on each page, a status code table with named errors, and a JSON error format with optional detail annotations (13 of 15). The version is in the URL (v9.2), with weekly Dataverse service update release notes. The MCP tool changes are noted without a date (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 86,
          "points": 13.98,
          "reason": "`$select`, `$top` and `Prefer: odata.maxpagesize` size responses. The MCP server has 15 tools, some of them for schema changes and files (22 of 25). `$filter`, `@odata.nextLink` paging with pages up to 5,000 rows, and no `$skip` (20). Errors are JSON with a code and message, a documented status code table and optional annotations with a help link (17 of 20). PATCH on an alternate key upserts, `If-Match` and `If-None-Match` limit it to update or create, and ETags give optimistic concurrency. The MCP delete tools are described as running only after explicit user approval. We did not read the live tool list, so readOnlyHint and destructiveHint are unconfirmed (15 of 20). Official SDKs for .NET (Microsoft.PowerPlatform.Dataverse.Client 1.2.27) and Python (PowerPlatform-Dataverse-Client 1.1.0). The docs say Microsoft ships no other language libraries for the Web API (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 74,
          "points": 12.95,
          "reason": "OAuth 2.0 through Microsoft Entra ID is the only route, with delegated sign-in or an application user holding a client secret or certificate. The OAuth scopes are coarse (`user_impersonation`, `.default`, `mcp.tools`) and the limits come from Dataverse security roles (26 of 30). Security roles set privileges per table and the MCP server follows them and row-level security. Each MCP client app must be allowed per environment by an administrator, and only Copilot Studio is on by default. The delete tools are described as needing explicit user approval, but Microsoft's sample agent instructions on the configuration page tell the agent not to ask before deleting (17 of 20). Lead, contact and email text written by outsiders reaches the model, and the MCP pages we read give no injection guidance (3 of 15). Dataverse auditing logs record changes and user access, readable through the Web API, once an administrator turns it on. It does not cover retrieve operations (13 of 15). SOC 2 Type 2 lists Dynamics 365 and security.txt points to MSRC and the bounty policy, but the file's Expires date of 23 September 2026 has passed (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "No x402, MPP or L402 (0). Seat prices are public at $65, $105 and $150 a user a month, paid yearly. MCP calls from agents built outside Copilot Studio are billed in Copilot Credits at published credit counts, and we did not read a dollar price per credit (10). The Dynamics 365 trial page states 30 days free and the Power Apps Developer Plan is a free Dataverse environment with Web API access. Neither page says whether a card is needed (15 of 20). A person registers an app in Entra ID and an administrator creates the application user or allows the MCP client (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 79,
          "points": 6.91,
          "reason": "Dataverse service update 9.2.26094 went to early release on 2 October 2026, and the Python SDK 1.1.0 was published on 7 October 2026 (30). Service updates are weekly, with nine listed since 7 August, each with release notes (20). Public release notes and community forums. We did not check how issues on the SDK repositories are answered (10 of 15). Current official SDKs for .NET and Python and the npm MCP proxy @microsoft/dataverse 1.0.81 of 26 September 2026. The official MCP registry lists only third-party Dataverse and Dynamics servers (13 of 15). The Python SDK is marked Production/Stable for Python 3.10 and later. CI was not checked because GitHub's API refused us for its rate limit (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 60, provenance 90",
          "reason": "Closed service under the Microsoft Product Terms for Dynamics 365, with MIT SDKs (15). The privacy statement, last updated September 2026, says customer agreements control for enterprise products and points to the Product Terms and the Data Protection Addendum of 22 May 2026, which we did not read. Its retention wording is general, and its line on using data to train AI models is not reconciled with the enterprise terms in what we read (18 of 30). The Power Platform deprecations page was updated on 6 October 2026 with dated notices, and the Web API docs state how versions stay compatible. The MCP tool removals carry no date (15 of 20). The region is chosen per environment, with an EU Data Boundary. We did not read a subprocessor list (12 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`$select`, `$top` and `Prefer: odata.maxpagesize` size responses. The MCP server has 15 tools, some of them for schema changes and files (22 of 25). `$filter`, `@odata.nextLink` paging with pages up to 5,000 rows, and no `$skip` (20). Errors are JSON with a code and message, a documented status code table and optional annotations with a help link (17 of 20). PATCH on an alternate key upserts, `If-Match` and `If-None-Match` limit it to update or create, and ETags give optimistic concurrency. The MCP delete tools are described as running only after explicit user approval. We did not read the live tool list, so readOnlyHint and destructiveHint are unconfirmed (15 of 20). Official SDKs for .NET (Microsoft.PowerPlatform.Dataverse.Client 1.2.27) and Python (PowerPlatform-Dataverse-Client 1.1.0). The docs say Microsoft ships no other language libraries for the Web API (12 of 15).",
          "maintenance": "Dataverse service update 9.2.26094 went to early release on 2 October 2026, and the Python SDK 1.1.0 was published on 7 October 2026 (30). Service updates are weekly, with nine listed since 7 August, each with release notes (20). Public release notes and community forums. We did not check how issues on the SDK repositories are answered (10 of 15). Current official SDKs for .NET and Python and the npm MCP proxy @microsoft/dataverse 1.0.81 of 26 September 2026. The official MCP registry lists only third-party Dataverse and Dynamics servers (13 of 15). The Python SDK is marked Production/Stable for Python 3.10 and later. CI was not checked because GitHub's API refused us for its rate limit (6 of 10).",
          "payments": "No x402, MPP or L402 (0). Seat prices are public at $65, $105 and $150 a user a month, paid yearly. MCP calls from agents built outside Copilot Studio are billed in Copilot Credits at published credit counts, and we did not read a dollar price per credit (10). The Dynamics 365 trial page states 30 days free and the Power Apps Developer Plan is a free Dataverse environment with Web API access. Neither page says whether a card is needed (15 of 20). A person registers an app in Entra ID and an administrator creates the application user or allows the MCP client (0).",
          "reliability": "Graded on the Dataverse Web API, with the Dataverse MCP server noted. Service health for a tenant is in the Power Platform and Microsoft 365 admin centres, behind an admin sign-in. The unauthenticated page at status.cloud.microsoft exists, and Microsoft's docs describe it as the place for updates when the admin portals are unavailable. It rendered no components for our reader (10 of 20, a departure from the full 20 because the page with history needs a login). No readable incident history (5). Service protection limits are published per user and web server at 6,000 requests and 20 minutes of execution time per five-minute window, and 52 concurrent requests, plus 40,000 requests per licensed user per 24 hours (15). 429 responses carry Retry-After with retry guidance, and upsert on alternate keys with If-Match gives safe retries for writes (15). The SLA for Microsoft Online Services dated 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Sales Enterprise and Professional (10). Web API v9.2 and the MCP endpoint /api/mcp are generally available (10).",
          "schema": "Each environment serves an OData v4 service document and a CSDL $metadata document at /api/data/v9.2/$metadata, and Learn publishes a table reference. No public OpenAPI document was found (18 of 25). learn.microsoft.com/llms.txt returns 404, but Learn returns Markdown for requests with `Accept: text/markdown`, which is how we read every page (10). The docs state purpose and limits, such as no `$skip` and a 5,000-row page ceiling. The published MCP tool descriptions are one line each (15 of 20). Entity types are typed in CSDL, but queries are OData strings and the MCP `read_query` tool takes a SQL SELECT string (12 of 15). Request and response examples on each page, a status code table with named errors, and a JSON error format with optional detail annotations (13 of 15). The version is in the URL (v9.2), with weekly Dataverse service update release notes. The MCP tool changes are noted without a date (13 of 15).",
          "security": "OAuth 2.0 through Microsoft Entra ID is the only route, with delegated sign-in or an application user holding a client secret or certificate. The OAuth scopes are coarse (`user_impersonation`, `.default`, `mcp.tools`) and the limits come from Dataverse security roles (26 of 30). Security roles set privileges per table and the MCP server follows them and row-level security. Each MCP client app must be allowed per environment by an administrator, and only Copilot Studio is on by default. The delete tools are described as needing explicit user approval, but Microsoft's sample agent instructions on the configuration page tell the agent not to ask before deleting (17 of 20). Lead, contact and email text written by outsiders reaches the model, and the MCP pages we read give no injection guidance (3 of 15). Dataverse auditing logs record changes and user access, readable through the Web API, once an administrator turns it on. It does not cover retrieve operations (13 of 15). SOC 2 Type 2 lists Dynamics 365 and security.txt points to MSRC and the bounty policy, but the file's Expires date of 23 September 2026 has passed (15 of 20).",
          "transparency": "Closed service under the Microsoft Product Terms for Dynamics 365, with MIT SDKs (15). The privacy statement, last updated September 2026, says customer agreements control for enterprise products and points to the Product Terms and the Data Protection Addendum of 22 May 2026, which we did not read. Its retention wording is general, and its line on using data to train AI models is not reconciled with the enterprise terms in what we read (18 of 30). The Power Platform deprecations page was updated on 6 October 2026 with dated notices, and the Web API docs state how versions stay compatible. The MCP tool removals carry no date (15 of 20). The region is chosen per environment, with an EU Data Boundary. We did not read a subprocessor list (12 of 20)."
        },
        "sources": [
          {
            "what": "Dataverse Web API overview",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "service protection API limits",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/api-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "request limits and allocations",
            "url": "https://learn.microsoft.com/en-us/power-platform/admin/api-request-limits-allocations",
            "seen": "2026-10-08"
          },
          {
            "what": "compose HTTP requests and handle errors",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/compose-http-requests-handle-errors",
            "seen": "2026-10-08"
          },
          {
            "what": "page results",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/query/page-results",
            "seen": "2026-10-08"
          },
          {
            "what": "update, delete and upsert",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/update-delete-entities-using-web-api",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth with Dataverse",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/authenticate-oauth",
            "seen": "2026-10-08"
          },
          {
            "what": "server-to-server authentication",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/build-web-applications-server-server-s2s-authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse MCP server and tool list",
            "url": "https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse MCP for non-Microsoft clients",
            "url": "https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp-other-clients",
            "seen": "2026-10-08"
          },
          {
            "what": "configure the Dataverse MCP server",
            "url": "https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp-disable",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse MCP FAQ",
            "url": "https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp-faq",
            "seen": "2026-10-08"
          },
          {
            "what": "Copilot Credit billing rates",
            "url": "https://learn.microsoft.com/en-us/microsoft-copilot-studio/requirements-messages-management",
            "seen": "2026-10-08"
          },
          {
            "what": "Dynamics 365 Sales pricing",
            "url": "https://www.microsoft.com/en-us/dynamics-365/products/sales/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA for Microsoft Online Services, 1 October 2026",
            "url": "https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services",
            "seen": "2026-10-08"
          },
          {
            "what": "service health guidance",
            "url": "https://learn.microsoft.com/en-us/power-platform/admin/check-online-service-health",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse released versions",
            "url": "https://learn.microsoft.com/en-us/power-platform/released-versions/dataverse",
            "seen": "2026-10-08"
          },
          {
            "what": "Power Platform deprecations",
            "url": "https://learn.microsoft.com/en-us/power-platform/important-changes-coming",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse auditing",
            "url": "https://learn.microsoft.com/en-us/power-platform/admin/manage-dataverse-auditing",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/use-webhooks",
            "seen": "2026-10-08"
          },
          {
            "what": "Dataverse search",
            "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/search/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "opportunity table reference",
            "url": "https://learn.microsoft.com/en-us/dynamics365/developer/reference/entities/opportunity",
            "seen": "2026-10-08"
          },
          {
            "what": "Power Apps Developer Plan",
            "url": "https://learn.microsoft.com/en-us/power-platform/developer/plan",
            "seen": "2026-10-08"
          },
          {
            "what": "SOC 2 Type 2 scope",
            "url": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
            "seen": "2026-10-08"
          },
          {
            "what": "Product Terms for Dynamics 365",
            "url": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftDynamics365/MCA",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statement",
            "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.microsoft.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK on PyPI",
            "url": "https://pypi.org/pypi/PowerPlatform-Dataverse-Client/json",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP proxy on npm",
            "url": "https://registry.npmjs.org/@microsoft/dataverse",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=dataverse",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: incident history, because status.cloud.microsoft rendered only a title and tenant service health needs an admin sign-in",
          "unchecked: whether the 30-day trial or the Power Apps Developer Plan needs a card. The trial sign-up pages we tried on Learn returned 404",
          "unchecked: the dollar price of a Copilot Credit, which sets the cost of MCP calls from agents built outside Copilot Studio",
          "unchecked: the text of the Data Protection Addendum of 22 May 2026 and the subprocessor list",
          "unchecked: CI and issue handling on microsoft/PowerPlatform-DataverseClient-Python, because GitHub's API refused us for its rate limit",
          "When the MCP tools describe_table, list_tables and fetch were removed, and how much notice was given. The docs note the change without a date",
          "Whether the live MCP tools set readOnlyHint or destructiveHint, and which transport the remote endpoint speaks",
          "Whether the SLA covers Sales Premium, which the Sales section heading does not name",
          "The lead said no Dynamics MCP docs were found. The Dataverse MCP server is documented under Power Apps and is generally available. A Sales-specific MCP page we tried returned 404"
        ]
      },
      "negative": 0,
      "verdict": "Dynamics 365 Sales data sits in Dataverse, reached through the OData v4 Web API or the Dataverse MCP server with 15 tools. Service protection limits are published and 429 responses carry Retry-After. Access needs an Entra app registration and an administrator, and the public service health page showed no history to our reader.",
      "bestFor": "Organisations already on Dynamics 365 or Microsoft 365 that want an agent to work inside existing security roles.",
      "strengths": [
        "Limits are published per user and web server. 6,000 requests and 20 minutes of execution time per five minutes, and 52 concurrent requests",
        "429 responses carry Retry-After, and PATCH on an alternate key upserts, so a retried write does not create a duplicate",
        "OAuth 2.0 through Microsoft Entra ID only, with every call inside the Dataverse security roles of the user or application user",
        "The Dataverse MCP server is generally available at /api/mcp with 15 tools, and each client app must be allowed per environment",
        "The October 2026 SLA pays a 25 per cent credit when Sales Enterprise or Professional uptime falls below 99.9 per cent"
      ],
      "weaknesses": [
        "No public OpenAPI document. The contract is an OData CSDL $metadata document served by each environment behind sign-in",
        "A person registers an app in Entra ID and a Power Platform administrator enables it. No keyless route was found",
        "Service health for a tenant sits behind an admin sign-in, and status.cloud.microsoft showed no components or history to our reader",
        "MCP calls from agents built outside Copilot Studio are billed in Copilot Credits unless the user holds a Premium or Microsoft 365 Copilot licence",
        "The MCP tools describe_table, list_tables and fetch were removed and search was renamed. The notice in the docs carries no date"
      ],
      "agentNotes": [
        "Send `OData-MaxVersion: 4.0`, `OData-Version: 4.0` and `Accept: application/json`, and name columns with `$select` on every read",
        "Page with `Prefer: odata.maxpagesize` (up to 5,000) and follow `@odata.nextLink`. `$skip` is not supported",
        "On 429, wait the seconds in Retry-After. The `x-ms-ratelimit-*` headers are for debugging, not pacing",
        "Use PATCH on an alternate key to upsert, and add `If-Match: *` when an update must not create a record",
        "For MCP, call `describe` for logical table and column names before `read_query`. Update any allow list that still names `describe_table`, `list_tables` or `fetch`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 69.7
        }
      ],
      "editorialScores": {
        "ergonomics": 86,
        "maintenance": 79,
        "payments": 25,
        "reliability": 65,
        "schema": 81,
        "security": 74,
        "transparency": 60
      },
      "provenanceScore": 90
    },
    "connect": {
      "install": "pip install PowerPlatform-Dataverse-Client",
      "http": "curl \"https://$DATAVERSE_ORG.api.crm.dynamics.com/api/data/v9.2/accounts?\\$select=name\u0026\\$top=5\" \\\n  -H \"Authorization: Bearer $DATAVERSE_ACCESS_TOKEN\" \\\n  -H \"Accept: application/json\" \\\n  -H \"OData-MaxVersion: 4.0\" \\\n  -H \"OData-Version: 4.0\"",
      "claudeCode": "claude mcp add dataverse -t stdio -- npx -y @microsoft/dataverse mcp https://yourorg.crm.dynamics.com",
      "config": {
        "mcpServers": {
          "dataverse": {
            "args": [
              "-y",
              "@microsoft/dataverse",
              "mcp",
              "https://yourorg.crm.dynamics.com"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/crm.records",
      "tool": "https://letme.dev/dynamics-365-sales"
    },
    "sameCompany": [
      "azure-foundry-fine-tuning",
      "azure-ai-content-safety",
      "azure-speech-to-text",
      "azure-text-to-speech",
      "microsoft-agent-framework",
      "microsoft-execution-containers",
      "microsoft-entra-agent-id",
      "azure-key-vault",
      "azure-devops-mcp",
      "microsoft-learn-mcp",
      "playwright-mcp",
      "azure-mcp",
      "azure-maps",
      "azure-translator",
      "microsoft-graph-calendar",
      "microsoft-teams",
      "power-automate",
      "microsoft-advertising-api",
      "microsoft-excel-graph",
      "outlook-mail-graph"
    ],
    "notable": [
      "The Web API is OData v4 at https://\u003corg\u003e.api.crm.dynamics.com/api/data/v9.2/, and the docs say all data operations go through the same organisation service as the SDK for .NET (https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview)",
      "Service protection limits per user and web server are 6,000 requests and 20 minutes of execution time in a five-minute sliding window, and 52 concurrent requests. 429 responses carry Retry-After (https://learn.microsoft.com/en-us/power-apps/developer/data-platform/api-limits)",
      "The Dataverse MCP server is at https://{dataverseOrgName}.crm.dynamics.com/api/mcp with 15 tools, among them search_data, read_query, create_record, update_record, delete_record and describe. A preview endpoint is at /api/mcp_preview (https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp)",
      "The MCP tools describe_table, list_tables and fetch were removed in favour of describe, and the data search tool was renamed search_data (https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp-faq)",
      "Since 15 December 2025, Dataverse MCP tools are charged in Copilot Credits when called by agents built outside Copilot Studio, except for holders of Dynamics 365 Premium or Microsoft 365 Copilot licences (https://learn.microsoft.com/en-us/power-apps/maker/data-platform/data-platform-mcp)",
      "The SLA for Microsoft Online Services dated 1 October 2026 sets service credits of 25, 50 and 100 per cent below 99.9, 99 and 95 per cent uptime for Sales Enterprise and Professional (https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services)"
    ],
    "area": "business",
    "details": [
      {
        "label": "API",
        "value": "Dataverse Web API, OData v4, JSON only, at https://\u003corg\u003e.api.crm.dynamics.com/api/data/v9.2/. Sales tables such as lead, opportunity and quote sit beside account, contact and activity tables"
      },
      {
        "label": "MCP server",
        "value": "Official, generally available at https://\u003corg\u003e.crm.dynamics.com/api/mcp, or through the local proxy `npx @microsoft/dataverse mcp \u003corg URL\u003e`. 15 tools. Preview tools at /api/mcp_preview"
      },
      {
        "label": "MCP tools",
        "value": "search_data, search, create_record, update_record, delete_record, create_table, update_table, delete_table, read_query, describe, upsert_skill, delete_skill, init_file_upload, commit_file_upload, file_download"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 through Microsoft Entra ID. Delegated sign-in, or an application user with a client secret or certificate. Access follows Dataverse security roles"
      },
      {
        "label": "Rate limits",
        "value": "Per user and web server, 6,000 requests and 20 minutes of execution time per five minutes, and 52 concurrent requests. 40,000 requests per licensed user per 24 hours, and a tenant pool of 500,000 plus 5,000 per licence for application users"
      },
      {
        "label": "Errors",
        "value": "JSON error with code and message. 429 carries Retry-After. `Prefer: odata.include-annotations=\"*\"` adds sub-codes and a help link"
      },
      {
        "label": "Paging",
        "value": "`Prefer: odata.maxpagesize` up to 5,000 rows a page and `@odata.nextLink`. `$top` limits rows. `$skip` is not supported"
      },
      {
        "label": "Safe writes",
        "value": "PATCH on an alternate key upserts. `If-Match` and `If-None-Match` restrict it to update or create. ETags for optimistic concurrency"
      },
      {
        "label": "Webhooks",
        "value": "Dataverse webhooks POST JSON for server events, synchronously or asynchronously. Azure Service Bus is the queued alternative"
      },
      {
        "label": "Search",
        "value": "Dataverse search at /api/search/v2.0/ and through the Web API, relevance-ranked across tables"
      },
      {
        "label": "SDKs",
        "value": "Python PowerPlatform-Dataverse-Client 1.1.0 (7 October 2026, MIT), .NET Microsoft.PowerPlatform.Dataverse.Client 1.2.27, npm @microsoft/dataverse 1.0.81 (26 September 2026, MIT)"
      },
      {
        "label": "Audit",
        "value": "Dataverse auditing logs record changes and user access once turned on per environment, table and column. Readable through the Web API. Retrieve operations are not audited"
      },
      {
        "label": "SLA",
        "value": "Service credit of 25 per cent below 99.9 per cent uptime, 50 below 99 and 100 below 95, for Sales Enterprise and Professional, per the SLA dated 1 October 2026"
      },
      {
        "label": "Free tier",
        "value": "30-day Dynamics 365 trial. Power Apps Developer Plan is a free Dataverse development environment with Web API access, disabled after 30 days without use"
      }
    ],
    "unitPrices": [
      {
        "item": "Sales Professional",
        "unit": "seat-month",
        "usd": 65,
        "note": "paid yearly"
      },
      {
        "item": "Sales Enterprise",
        "unit": "seat-month",
        "usd": 105,
        "note": "paid yearly"
      },
      {
        "item": "Sales Premium",
        "unit": "seat-month",
        "usd": 150,
        "note": "paid yearly, MCP access to Dynamics 365 data not charged in Copilot Credits"
      }
    ],
    "provenance": {
      "legalEntity": "Microsoft Corporation",
      "domain": "microsoft.com",
      "domainRegistered": "1991-05-02",
      "domainNote": "Each environment's API answers on a dynamics.com host such as https://\u003corg\u003e.crm.dynamics.com, a Microsoft domain. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
      "endpointOnVendorDomain": true,
      "terms": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftDynamics365/MCA",
      "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
      "statusPage": "https://status.cloud.microsoft",
      "changelog": "https://learn.microsoft.com/en-us/power-platform/released-versions/dataverse",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The terms link is the Microsoft Product Terms page for Dynamics 365 Services under the Microsoft Customer Agreement, which names Sales Professional, Enterprise and Premium. It showed no effective date.",
        "The Microsoft privacy statement was last updated in September 2026 and says customer agreements control for enterprise and developer products. Customer data is governed by the Products and Services Data Protection Addendum, latest English version 22 May 2026, published only as a .docx download at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.",
        "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08, with MSRC as the contact.",
        "status.cloud.microsoft rendered only a title for our reader. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in.",
        "RDAP for microsoft.com gives a registration date of 1991-05-02 and MarkMonitor Inc. as registrar. dynamics.com was not looked up."
      ],
      "score": 90,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Microsoft Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "microsoft.com, registered 1991-05-02 (35 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "microsoft.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 3 of the 7 things a reader expects",
          "points": 6.6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.cloud.microsoft",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftDynamics365/MCA",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 4369,
          "points": 6.6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": false
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Microsoft reserves the right to suspend or remove access to Azure Communication Services for Customer or its end users that do not comply with the Messaging Policy."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer may not acquire new or additional From SA SLs."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Service Level Agreement"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Listed products carry minimum licence quantities that must be kept up for the whole agreement term.",
              "quote": "These minimum purchases must be maintained through agreement term."
            },
            {
              "date": "2026-10-08",
              "text": "Copilot components powered by Azure OpenAI fall under the Privacy and Security terms, while any component powered by Bing stays under Bing terms.",
              "quote": "The Privacy \u0026 Security terms apply to any Copilot features powered by Azure OpenAI service that are included within Microsoft Dynamics 365 Core Services or Dynamics 365 EU Data Boundary Services, except that any component powered by Bing remains subject to Bing terms."
            },
            {
              "date": "2026-10-08",
              "text": "For voice services run on Azure Communication Services, the customer must tell users of its application when a call or meeting is recorded or transcribed.",
              "quote": "It is your responsibility to ensure that the users of your application are notified when recording or transcription are enabled in a call or meeting."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://privacy.microsoft.com/en-us/privacystatement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 33580,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
              "says": "Names a period of 7 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Service providers that help us determine your device’s location."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
              "costsPoints": true
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We also disclose personal data for digital advertising purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
              "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
            },
            {
              "date": "2026-10-08",
              "text": "Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them.",
              "quote": "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing."
            },
            {
              "date": "2026-10-08",
              "text": "Microsoft staff manually review some results of automated systems, including AI, against the source data.",
              "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/dynamics-365-sales.json",
    "live": {
      "slug": "dynamics-365-sales",
      "vendorStatus": {
        "page": "https://status.cloud.microsoft",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:38:27.838807107Z"
      },
      "pages": [
        {
          "url": "https://learn.microsoft.com/en-us/power-platform/released-versions/dataverse",
          "kind": "changelog",
          "status": 404,
          "checkedAt": "2026-10-08T18:21:44.313857877Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftDynamics365/MCA",
          "kind": "terms",
          "status": 502,
          "checkedAt": "2026-10-08T18:29:16.982750104Z",
          "changedAt": "0001-01-01T00:00:00Z"
        }
      ],
      "updatedAt": "2026-10-08T19:38:27.838807107Z"
    }
  }
}
