Skip to content
Van Oosten Advies B.V.

Last updated: September 19, 2026

CustomerGate 365: setup guide

From installing CustomerGate 365 to a first request through the customer portal, step by step. Written for the administrator of a Business Central environment, or for a partner doing it on their behalf. Screen names are as Business Central shows them in English.

Before you start

  • Business Central online, version 28.0 or later.
  • A website that uses the CustomerGate 365 web services, built by Van Oosten Software or by another developer. The web service reference describes what it has to call.
  • Two Microsoft Entra app registrations, one for the website and one for the catalog synchronization. The next step covers them.
  • An e-mail account in Business Central to send from, other than SMTP with a password.
  • A user with the SUPER permission set, for the installation and for Repair Permissions.
  • Optional: iFacto Steel 365 and DXSteel Doc Archive. If the customer uses them, install them first, in a company that has data: the app looks for them while it installs.

Register the two applications in Microsoft Entra

The website signs in to Business Central as two applications, each with its own client ID and secret, through the OAuth 2.0 client credentials flow. Register them in the Microsoft Entra admin center, under App registrations:

  1. Create an app registration for the website (requests and the customer portal) and one for the catalog synchronization.
  2. Give each registration the application permission API.ReadWrite.All of Dynamics 365 Business Central, and grant admin consent for it.
  3. Create a client secret, or a certificate, for each registration and give it to the website's developer. The secret stays with the website; it does not go into Business Central.
  4. Note the Application (client) ID of both registrations. You fill those in on CustomerGate Setup; Repair Permissions registers the applications in Business Central itself.

Install the app

Install CustomerGate 365 from AppSource as a user with the SUPER permission set. While the app is not yet publicly listed on AppSource, you install it through the preview link you receive from Van Oosten Software; your environment is added to the offer's preview audience for that. Without SUPER the app installs, but it cannot write its tenant permission sets. On installation, per company, it creates:

  • the number series WEBREQ (WEB000001 onwards) and WEBACCOUNT (ACC000001 onwards), and the setup record with its defaults;
  • two job queue entries, both on hold: the mail job every five minutes and the cleanup job daily at 02:00;
  • the web services the website calls;
  • the default archive categories, where DXSteel Doc Archive is installed;
  • the tenant permission sets, when a SUPER user installs the app.

Run the assisted setup

Open Assisted Setup and choose Set Up CustomerGate 365. The guide asks for the two client IDs, the e-mail settings and the portal address, and with Repair Permissions Now it also sets up the permissions when you choose Finish. Everything it asks is also on CustomerGate Setup, where you can change it later.

Repair the permissions

On CustomerGate Setup, check Website Client ID and Synchronization Client ID and choose Repair Permissions. It needs SUPER. The app registers both applications in Business Central if that has not happened yet, creates its tenant permission sets and assigns, for all companies:

The website application
VOA WEB API, VOA WEB PORTAL, VOA WEB BASELINE, VOA CG EXECUTE and VOA CG MAIL; plus VOA CG S365 ARCHIVE with the Steel 365 document archive, VOA CG DOCUMENTS with Portal Documents from Reports, and Continia's CDC BASIC where Continia Document Capture is installed.
The synchronization application
VOA WEB SYNC; plus VOA CG S365 SYNC with Steel 365.

Afterwards, the lines under Permissions and the line Website Permission Baseline should all be in order. Business Central applies changed permissions after a few minutes. Never give the website's applications D365 BASIC: it would let them read customers, contacts, sales documents and margins, which the app deliberately keeps out of their reach.

Give your own people access

Inside sales
VOA Web Inside Sales, shown as CustomerGate - Inside Sales: the daily work with requests, account requests, portal users, acceptances and the mail round.
Administrators
VOA Web Admin, shown as CustomerGate - Administration: the setup and the cleanup as well. Repair Permissions itself needs SUPER on top of it.
The job queue user
The user the job queue runs under needs VOA Web Inside Sales and the usual rights to send e-mail.

Set up e-mail

  1. Add an e-mail account in Business Central (E-mail Accounts) and make it the default account. Do not use SMTP with a password: Exchange Online switches off SMTP basic authentication by default from the end of December 2026.
  2. To send from another address, assign an account to the CustomerGate scenarios. There is no fallback to a built-in account: without a default account, nothing is sent at all.
  3. On CustomerGate Setup, fill in Notification E-mail and Inside Sales Language, and check Response Time (Working Days) against what your website promises.
  4. Fill in Portal Address once the portal is live. Until then, the e-mail about an approved account request says that the portal opens soon.

The five scenarios, under Scenarios on the e-mail account:

  • CustomerGate - Confirmation to Requester
  • CustomerGate - Notification to Inside Sales
  • CustomerGate - Message to Account Requester
  • CustomerGate - Account Request Notification to Inside Sales
  • CustomerGate - Customer Portal Sign-in Code

Turn on the two job queue entries

Both are installed on hold, so that installing the app sends no e-mail and erases nothing. Once the e-mail account, the notification address and the retention period are right, choose Turn On Both Jobs on CustomerGate Setup. It refuses while Cleanup Disabled is on or while no e-mail account can send.

The mail job
Sends confirmations and notifications, every five minutes. Send Pending E-mails Now runs a round by hand.
The cleanup job
Erases personal data after the retention period, daily at 02:00. Clean Up Personal Data Now runs a round by hand.

An update of the app never overwrites these two entries once they exist, so a schedule you changed yourself stays as it is.

Retention, and the copies of sent e-mails

Set Retention Period (Days) on CustomerGate Setup to what the privacy statement on your website promises; the default is 365 days. Business Central also keeps every sent message, including sign-in codes, in Sent Email, which the cleanup does not reach. Set a retention policy for Sent Email on the Retention Policies page, equal to the CustomerGate retention period; seven days is the minimum there.

Archive categories, for Steel 365 customers

Only where iFacto DXSteel Doc Archive is installed. The defaults are filled in during installation. Open Archive Categories from CustomerGate Setup, check which categories customers may see and as what, and choose Repair Permissions after every change, so the security filter on the archive follows.

Point the website at the environment

Give the website's developer the tenant, the name of the environment and the company. After Repair Permissions, wait a few minutes for Business Central to apply the permissions, then let the website run its own checks and a first catalog synchronization.

A first test through the portal

  1. Send an account request from the website, with an e-mail address you can read.
  2. Approve it in Account Requests: Select Customer, then Approve with the role Buyer.
  3. Sign in on the website with the code from the e-mail.
  4. Open a quote and a document, and accept a released quote once.
  5. Check Website Quote Acceptances in Business Central, and check that the confirmation and the notification have been sent.

What the status lines mean

CustomerGate Setup shows with status lines what is ready and what is not. They are the quickest check after every change:

Status lineIn orderOtherwise
voaPortal Web ServicePublishedNot published: the portal does not work. Publish the service on the Web Services page.
E-mail AccountPresentNo e-mail account, or accounts without a default: add an account and make it the default.
Mail Job StatusReadyOn hold, or no entry yet: nothing is sent. Choose Turn On Both Jobs.
Cleanup Job StatusReadyOn hold, or no entry yet: nothing is erased. Choose Turn On Both Jobs.
Awaiting Cleanup0Requests past their retention period still hold personal data: check the cleanup job and Cleanup Disabled.
Website Permission BaselineOK: no D365 BASIC on the website accountD365 BASIC is assigned to the website account: remove it there.
Tenant Permission SetsCompleteSets missing, or lines missing or different: choose Repair Permissions.
Document Archive FilterPresent, or not applicable without the archiveMissing: choose Repair Permissions; if that does not help, set the filter by hand on the archive line of the set.
AssignmentsOKAssignments missing: fill in the client IDs and choose Repair Permissions.
Steel 365 ModuleActive or OffInformation only: it follows from whether iFacto Steel 365 is installed.
Document ArchivePresent or Not presentInformation only: without the archive, the portal prints documents with your reports.

Where to go next