Microsoft's roadmap says the logging makes data export events auditable, which matters for compliance, security investigations and understanding how people use Business Central. Before you file this under "solved data-leak problem," it helps to know what the new signal records and what it doesn't.
Why this matters: people have asked for it for years
Admins have wanted this for a long time. On the mibuso community forum, a Business Central 21 on-premises user pointed out that by default, Business Central allows lists to be exported to Excel using the standard "Open in Excel" function. They said they had tried to check if this functionality was being tracked in some way, for example through the raising of an event or with telemetry data, but I wasn't very successful. That question went without a good answer for a while. The new event now answers it, at least for newer versions.
What the Open in Excel action does
Microsoft's Business Central documentation describes two related actions. On list pages such as a list of customers, sale orders, or invoices, you can export the list to Microsoft Excel and view it there, and you can either select the Open in Excel action or the Edit in Excel action on the page.
Open in Excel is the one-way option. With it, you can make changes to the records in Excel, but you can't publish the changes back to Business Central. You can only save the changes to the Excel file, without affecting data in Business Central. Microsoft also notes that Excel respects filters on the page that limit the records shown.
Where the file ends up depends on your setup. As Business Central MVP Yun Zhu has explained, if your organization has configured OneDrive for system features, the Excel workbook is opened in your browser by using Excel for the web. If you're not using OneDrive for system features, the workbook is downloaded to your device. That matters when you investigate an event. The same telemetry record could mean a file in your OneDrive or a file on an endpoint's local disk.
Section summary: Open in Excel is a one-way, filter-aware export. Until now admins couldn't see it in telemetry, and the workbook can end up in OneDrive or on a local device depending on configuration.
What the event records
The Microsoft Learn article "Analyze Open in Excel telemetry" applies to Business Central 2026 release wave 2 and later. It defines one event, RT0056, which fires when a user successfully opens a page in Excel. The message format is Open in Excel: {pageName}, and the user_Id dimension holds the user's telemetry ID, which you can match to a person from the user card.
The custom dimensions documented by Microsoft are:
| Dimension | What it tells you |
|---|---|
aadTenantId | Microsoft Entra tenant ID (shows "common" on-premises without Entra authentication) |
alObjectId / alObjectName | ID and name of the page opened in Excel |
alObjectType | Always Page |
clientType | Client that opened the session, such as Web or Background |
companyName | The current company |
component / componentVersion | Business Central Server and its version |
environmentName / environmentType | Environment name and type, such as Production or Sandbox |
eventId | RT0056 |
extensionId, extensionName, extensionPublisher, extensionVersion | The extension that defines the page |
The extension fields are a nice extra. If a partner's add-on page is behind a lot of exports, you can see that directly.
What it does not record
The scope is narrow, and Microsoft documents it that way:
- Successful opens only. The documented trigger is a successful open, so failed attempts don't appear.
- No content. None of the documented fields record which rows were in the workbook, which filters were applied, or how many records were included.
- Nothing after the export. The event can't tell you whether the file was shared, emailed or copied to a USB stick.
- Edit in Excel isn't covered here. The documentation only covers the Open in Excel action, so don't assume Edit in Excel produces RT0056.
Think of RT0056 as a record that the export happened, not as data-loss prevention. Downstream controls such as Purview, OneDrive sharing policies and endpoint protection still have to cover what happens to the file.
How to start monitoring
1. Make sure telemetry is enabled
Business Central sends telemetry to Azure Application Insights. You need an Application Insights resource, and the environment must be configured to send data to it. Microsoft distinguishes environment-level telemetry from app/extension-level telemetry, and RT0056 is about environment activity. In the Business Central admin center, telemetry guidance has long directed admins to open the environment to be connected, and click Define in the Applicaiton Insights Connection String.
Older partner guidance from ABCC Group warns that this change can trigger an environment restart. It advises admins to plan to do this during non-working hours to avoid disruptions. Check how your current version behaves before you click Save in the middle of the day.
2. Run Microsoft's sample query
Microsoft's sample KQL query looks back 60 days in the traces table:
traces
| where timestamp > ago(60d)
| where customDimensions.eventId == 'RT0056'
| project timestamp
, message
, aadTenantId = customDimensions.aadTenantId
, environmentName = customDimensions.environmentName
, environmentType = customDimensions.environmentType
, companyName = customDimensions.companyName
, clientType = customDimensions.clientType
, alObjectId = customDimensions.alObjectId
, alObjectName = customDimensions.alObjectName
, extensionName = customDimensions.extensionName
, extensionPublisher = customDimensions.extensionPublisher
, extensionVersion = customDimensions.extensionVersion
You can tell it's working when the query returns rows after a test user opens a list in Excel in the configured environment. If you get nothing, check these things first:
- The environment is on 2026 release wave 2 or later.
- The connection string points to the Application Insights resource you're querying.
- The test happened inside your time window.
3. Fit it to your governance questions
A few practical ways to extend the sample, based on general KQL practice rather than Microsoft guidance:
- Group by
alObjectNameto see which pages are exported most often. Customer and vendor lists are the usual suspects. - Filter to
environmentType == "Production"so sandbox testing doesn't clutter your audit view. - Add
user_Idto the projection so you can map events back to people.
Microsoft says alerting is available through Azure Application Insights alerts, Logic Apps or Power Automate.
Costs and caveats
Application Insights charges for data ingestion and retention, so a busy finance team that exports constantly will add to your bill. Microsoft doesn't publish a per-event cost for RT0056.
Retention also shapes what you can audit. If your workspace keeps 30 days of data, a 60-day query won't find older events.
User attribution needs one more check. user_Id is a telemetry ID, not a name, so confirm that telemetry IDs are assigned in your environment before you promise HR or legal that you can identify who exported a file.
Section summary: RT0056 is worth having, but whether it holds up in an investigation depends on correct Application Insights wiring, enough retention, and user-ID mapping you've actually tested.
The bottom line
This is a small feature with real impact for Business Central admins and partners. It finally gives a long-standing forum question a supported answer: who opened which page in Excel, in which company and environment. It isn't a full audit trail of data movement and shouldn't be sold internally as one. Turn telemetry on, test the query, set retention to match your compliance needs, and treat RT0056 as one piece of evidence alongside the rest of your Microsoft 365 security tooling.
References
- Dynamics 365 Business Central: Governance and administration - Monitor usage of Open in Excel with telemetry Microsoft 365 Roadmap · 2026-09-30T23:31:03.389585Z
- Analyze Open in Excel telemetry - Business Central | Microsoft Learn learn.microsoft.com
- Tracking the standard "Open in Excel" in BC21 (On-Premise) — mibuso.com forum.mibuso.com