CRM Tool of the Week – POA Table Secret Decoder Ring

There are a couple tables in CRM that can be a real beast to work with. One of these tables is the PrincipalObjectAccess table, also know as the POA table. The POA table can be a pain to work with for 3 reasons:

  1. It’s Big
  2. It’s used by almost every query
  3. The Rights Mask values are hard to understand

There’s not much that can be done about the first two. But, thanks to CRM MVP Scott Sewell you can now easily encode and decode the Rights Mask values using his secret decoder ring.

What’s the problem with the Rights Access Mask?

The way CRM encodes the POA is no big secret. Each of the secrity permission like, read and write, has a value assocaited with it and they are all added together to calculate the rights mask value. At first it may seem like this would be a simple thing to enturpet, after all there are only a hand full of 9. But if you remember coin flipping excercises in math class this quickly adds up to 512 different possible values for the Rights Mask.

What does the Secret Decoder Ring do?

The POA Table Secret Decoder Ring is a simple to use Excel spreadsheet that Enodes and Decodes a Rights Mask Value letting. You can either set the security values in the left-hand column to get the Encoded Rights Mask value for that group of permissions or you can enter the Rights Mask value in the top of the right-hand column to see what set of permissions are for that value.



You can Download the POA Table Secret Decoder Ring from


More Information

For more information check Scott Sewell’s article on Customer Effective Blog


  1. Scott Sewell says:

    🙂 Thanks – Hope you find it as useful as I have in resolving questions I had about security. – There’s a ton more there, but this was the ‘key’ for me – once I understood what was happening, I was able to dive much deeper into it. —

    Let me know if you have suggestions / corrections –


    • Scott Sewell says:

      Oh! and I almost forgot – thanks for the “Unmasking” suggestion! – 🙂

      • CRMNerd says:

        No problem. It’s always fun to try and come up with catchy titles.

        • Elvin says:

          An exciting dsciourse is worth comment. I judge that you should make much on this issue, it mightiness not be a prejudice study but mostly fill are not sufficiency to communicate on much topics. To the next. Cheers like your Event Management Accelerator | xRM Advisors.

    • CRMNerd says:


      Anything that makes that table easier to understand is greatly appreciated.


      • Pavithran says:

        Cute – but I think your analogy leveas a little to be desired. Both of the technologies are relevant today, but the enterprise is much more versed in .NET does not give you the leap forward that cars vs horses did – But a nice jab anyway  even though it really adds nothing to the discussion.

    • Kamaldeep says:

      An unputdownable conicmmuating is worth statement. I believe that you should write more on this message, it might not be a sacred individual but mostly people are not enough to verbalize on such topics. To the succeeding. Cheers like your Event Management Accelerator | xRM Advisors.

    • Elisa says:

      Dear Scott, any chance that you can give me a working link to download the secret POA encoder/decoder? The link in this post and in the Hitachi website isn’t working any more 🙁

  2. Pat says:

    Thanks for the sensible criitque. Me and my neighbor were just preparing to do some research about this. We got a grab a book from our area library but I think I learned more clear from this post. I’m very glad to see such magnificent info being shared freely out there.

Leave a Reply

Your email address will not be published. Required fields are marked *