Last updated: September 19, 2026
CustomerGate 365: setup guide
From installing CustomerGate 365 to a first request through the customer portal, step by step. Written for the administrator of a Business Central environment, or for a partner doing it on their behalf. Screen names are as Business Central shows them in English.
Before you start
- Business Central online, version 28.0 or later.
- A website that uses the CustomerGate 365 web services, built by Van Oosten Software or by another developer. The web service reference describes what it has to call.
- Two Microsoft Entra app registrations, one for the website and one for the catalog synchronization. The next step covers them.
- An e-mail account in Business Central to send from, other than SMTP with a password.
- A user with the SUPER permission set, for the installation and for Repair Permissions.
- Optional: iFacto Steel 365 and DXSteel Doc Archive. If the customer uses them, install them first, in a company that has data: the app looks for them while it installs.
Register the two applications in Microsoft Entra
The website signs in to Business Central as two applications, each with its own client ID and secret, through the OAuth 2.0 client credentials flow. Register them in the Microsoft Entra admin center, under App registrations:
- Create an app registration for the website (requests and the customer portal) and one for the catalog synchronization.
- Give each registration the application permission API.ReadWrite.All of Dynamics 365 Business Central, and grant admin consent for it.
- Create a client secret, or a certificate, for each registration and give it to the website's developer. The secret stays with the website; it does not go into Business Central.
- Note the Application (client) ID of both registrations. You fill those in on CustomerGate Setup; Repair Permissions registers the applications in Business Central itself.
Install the app
Install CustomerGate 365 from AppSource as a user with the SUPER permission set. While the app is not yet publicly listed on AppSource, you install it through the preview link you receive from Van Oosten Software; your environment is added to the offer's preview audience for that. Without SUPER the app installs, but it cannot write its tenant permission sets. On installation, per company, it creates:
- the number series WEBREQ (WEB000001 onwards) and WEBACCOUNT (ACC000001 onwards), and the setup record with its defaults;
- two job queue entries, both on hold: the mail job every five minutes and the cleanup job daily at 02:00;
- the web services the website calls;
- the default archive categories, where DXSteel Doc Archive is installed;
- the tenant permission sets, when a SUPER user installs the app.
Run the assisted setup
Open Assisted Setup and choose Set Up CustomerGate 365. The guide asks for the two client IDs, the e-mail settings and the portal address, and with Repair Permissions Now it also sets up the permissions when you choose Finish. Everything it asks is also on CustomerGate Setup, where you can change it later.
Repair the permissions
On CustomerGate Setup, check Website Client ID and Synchronization Client ID and choose Repair Permissions. It needs SUPER. The app registers both applications in Business Central if that has not happened yet, creates its tenant permission sets and assigns, for all companies:
- The website application
- VOA WEB API, VOA WEB PORTAL, VOA WEB BASELINE, VOA CG EXECUTE and VOA CG MAIL; plus VOA CG S365 ARCHIVE with the Steel 365 document archive, VOA CG DOCUMENTS with Portal Documents from Reports, and Continia's CDC BASIC where Continia Document Capture is installed.
- The synchronization application
- VOA WEB SYNC; plus VOA CG S365 SYNC with Steel 365.
Afterwards, the lines under Permissions and the line Website Permission Baseline should all be in order. Business Central applies changed permissions after a few minutes. Never give the website's applications D365 BASIC: it would let them read customers, contacts, sales documents and margins, which the app deliberately keeps out of their reach.
Give your own people access
- Inside sales
- VOA Web Inside Sales, shown as CustomerGate - Inside Sales: the daily work with requests, account requests, portal users, acceptances and the mail round.
- Administrators
- VOA Web Admin, shown as CustomerGate - Administration: the setup and the cleanup as well. Repair Permissions itself needs SUPER on top of it.
- The job queue user
- The user the job queue runs under needs VOA Web Inside Sales and the usual rights to send e-mail.
Set up e-mail
- Add an e-mail account in Business Central (E-mail Accounts) and make it the default account. Do not use SMTP with a password: Exchange Online switches off SMTP basic authentication by default from the end of December 2026.
- To send from another address, assign an account to the CustomerGate scenarios. There is no fallback to a built-in account: without a default account, nothing is sent at all.
- On CustomerGate Setup, fill in Notification E-mail and Inside Sales Language, and check Response Time (Working Days) against what your website promises.
- Fill in Portal Address once the portal is live. Until then, the e-mail about an approved account request says that the portal opens soon.
The five scenarios, under Scenarios on the e-mail account:
- CustomerGate - Confirmation to Requester
- CustomerGate - Notification to Inside Sales
- CustomerGate - Message to Account Requester
- CustomerGate - Account Request Notification to Inside Sales
- CustomerGate - Customer Portal Sign-in Code
Turn on the two job queue entries
Both are installed on hold, so that installing the app sends no e-mail and erases nothing. Once the e-mail account, the notification address and the retention period are right, choose Turn On Both Jobs on CustomerGate Setup. It refuses while Cleanup Disabled is on or while no e-mail account can send.
- The mail job
- Sends confirmations and notifications, every five minutes. Send Pending E-mails Now runs a round by hand.
- The cleanup job
- Erases personal data after the retention period, daily at 02:00. Clean Up Personal Data Now runs a round by hand.
An update of the app never overwrites these two entries once they exist, so a schedule you changed yourself stays as it is.
Retention, and the copies of sent e-mails
Set Retention Period (Days) on CustomerGate Setup to what the privacy statement on your website promises; the default is 365 days. Business Central also keeps every sent message, including sign-in codes, in Sent Email, which the cleanup does not reach. Set a retention policy for Sent Email on the Retention Policies page, equal to the CustomerGate retention period; seven days is the minimum there.
Archive categories, for Steel 365 customers
Only where iFacto DXSteel Doc Archive is installed. The defaults are filled in during installation. Open Archive Categories from CustomerGate Setup, check which categories customers may see and as what, and choose Repair Permissions after every change, so the security filter on the archive follows.
Point the website at the environment
Give the website's developer the tenant, the name of the environment and the company. After Repair Permissions, wait a few minutes for Business Central to apply the permissions, then let the website run its own checks and a first catalog synchronization.
A first test through the portal
- Send an account request from the website, with an e-mail address you can read.
- Approve it in Account Requests: Select Customer, then Approve with the role Buyer.
- Sign in on the website with the code from the e-mail.
- Open a quote and a document, and accept a released quote once.
- Check Website Quote Acceptances in Business Central, and check that the confirmation and the notification have been sent.
What the status lines mean
CustomerGate Setup shows with status lines what is ready and what is not. They are the quickest check after every change:
| Status line | In order | Otherwise |
|---|---|---|
| voaPortal Web Service | Published | Not published: the portal does not work. Publish the service on the Web Services page. |
| E-mail Account | Present | No e-mail account, or accounts without a default: add an account and make it the default. |
| Mail Job Status | Ready | On hold, or no entry yet: nothing is sent. Choose Turn On Both Jobs. |
| Cleanup Job Status | Ready | On hold, or no entry yet: nothing is erased. Choose Turn On Both Jobs. |
| Awaiting Cleanup | 0 | Requests past their retention period still hold personal data: check the cleanup job and Cleanup Disabled. |
| Website Permission Baseline | OK: no D365 BASIC on the website account | D365 BASIC is assigned to the website account: remove it there. |
| Tenant Permission Sets | Complete | Sets missing, or lines missing or different: choose Repair Permissions. |
| Document Archive Filter | Present, or not applicable without the archive | Missing: choose Repair Permissions; if that does not help, set the filter by hand on the archive line of the set. |
| Assignments | OK | Assignments missing: fill in the client IDs and choose Repair Permissions. |
| Steel 365 Module | Active or Off | Information only: it follows from whether iFacto Steel 365 is installed. |
| Document Archive | Present or Not present | Information only: without the archive, the portal prints documents with your reports. |
Where to go next
- CustomerGate Setup
Every setting and status line on the setup page.
- Manual
Help per screen, from web requests to the setup page.
- Web service reference
The services, procedures and JSON keys a website calls.
- Support
How to ask for help, and what to send along.