Skip to main content
Business Central8 min read ·

Dynamics 365 Business Central Update 28.5: 11 Fixes, 3 Risks, and What to Check First

Update 28.5 ships 11 fixes, but three of them — a blocked codeunit, tighter web request security, and new duplicate-record cleanup — are worth checking before they reach your live environment.

Software updates often feel like an IT responsibility, but they directly impact daily operations. When an ERP update changes how records are created, how external tools connect, or how invoices are generated, the effects ripple through your financial reporting, customer experience, and audit trails.

Microsoft Dynamics 365 Business Central Update 28.5 (deployed September 2026) introduces 11 specific fixes. While nothing in this release is fundamentally disruptive, three changes introduce quiet operational risks: the generation of duplicate records, blocked background code, and tighter integration security.

The 2-minute triage: are you affected?

Use this quick-reference guide to determine if your Business Central environment requires immediate review.

  1. 01If your organization relies on custom add-ons, scheduled jobs, or integrations: you must review the Codeunit 248 restriction and the new Web Request security rules.
  2. 02If your organization uses Field Service, Outlook, or AI invoice processing: you need to check for duplicate assets, duplicate emails, and utilize the new Payables Agent cleanup fix.
  3. 03If your organization imports goods or ships directly from suppliers: you should review the import invoice fix and the vendor inventory warning patch.
  4. 04If your organization operates in Spain, Belgium, or the Czech Republic: look into the SII telemetry, Belgian discount updates, and Czech address fixes.
  5. 05If your organization has users with highly customized home screens: you need to check the Role Center overwrite fix to ensure dashboards are not reset.

The 11 updates at a glance

Here is exactly what changed, categorized by the level of operational risk. Risk ratings are general guidance — actual risk depends on your active modules and custom extensions.

High risk updates

  1. 01Codeunit 248 blocked in background/API sessions: custom jobs or third-party integrations could silently stop working without triggering an immediate error screen.
  2. 02Web Request Management security tightened: outbound connections to outside services and APIs may be blocked until security permissions are updated.

Medium risk updates

  1. 01Duplicate Field Service customer assets: resolves a bug that created split service histories and inaccurate physical customer asset records.
  2. 02Duplicate records from the Outlook connector: fixes an issue that caused cluttered communication histories on customer cards when saving previously retrieved emails.
  3. 03Payables Agent clean-up utility added: unwanted AI-generated invoice records can now be removed safely without risking ledger corruption.
  4. 04Import purchase invoice fix: resolves the delayed posting of imported goods and associated freight charges.
  5. 05Role Center overwrite fix: prevents users' customized home screens from resetting to default when an administrator refreshes the user list.

Low to medium risk updates

  1. 01Vendor location "insufficient inventory" fix: prevents valid drop-shipment orders from being falsely blocked by inaccurate inventory warnings.
  2. 02Belgian invoice payment discounts fixed: ensures accurate early-payment discount amounts are reflected on exported invoices.
  3. 03InterCompany and SII telemetry improved: allows for faster administrative troubleshooting for Spanish tax reporting and group company document exchanges.
  4. 04Czech "Report Address Source" setting added: ensures the correct legal registered address appears on official company reports.

Deep dive: the three primary business risks behind these changes.

Risk 1: custom code and external integrations breaking

Security and performance upgrades are necessary, but they often expose vulnerabilities in older, custom-built extensions.

Codeunit 248 restrictions (Build 55427): a codeunit is a block of logic that performs a specific task. Microsoft now prevents codeunit 248 from running in background sessions (silent scheduled tasks) or API sessions (when external software connects to Business Central). If a custom nightly job relies on this code, it will fail overnight without warning, leaving reports inaccurate by morning.

Web Request security (Build 54378): Web Request Management acts as the gatekeeper for outgoing connections. Microsoft has tightened these protocols. If you have custom extensions sending data to external platforms, they may suddenly lose connection until the security settings are adjusted by a developer.

Risk 2: duplicate and unwanted records

Duplicate data quietly erodes trust in your ERP. Four fixes in this update address runaway record creation.

Field Service assets & Outlook connector (Builds 55486 & 55108): completing integrated Field Service work orders previously risked creating a duplicate copy of a customer's physical asset. Similarly, retrieving an email that had already been saved to Business Central created duplicate communication logs. Both bugs have been patched to keep customer cards clean.

The Payables Agent cleanup (Build 55330): the AI-assisted Payables Agent occasionally generated unwanted invoice entries when reading PDFs. Because deleting AI records manually can be risky, Microsoft has introduced a built-in utility to safely wipe these errors.

Risk 3: supply chain and financial compliance

Minor system miscalculations can cause major delays at month-end or during compliance audits.

Purchasing & inventory (Builds 55233 & 54976): this update resolves a bug that prevented teams from posting purchase invoices for imported goods. It also patches a false "insufficient inventory" warning that was blocking valid customer drop-shipment orders from being sent to vendors.

The safe-update action plan

Updates execute smoothly when environments are audited beforehand. To prevent disruptions, follow this standard deployment checklist.

  1. 01Test in a sandbox: never deploy an update directly to your live environment. Push the update to a sandbox (a secure replica of your system) first.
  2. 02Audit custom code: have your development team or ERP partner scan all custom extensions for Codeunit 248 dependencies.
  3. 03Check integrations: run a test payload through your highest-priority API connections to ensure the new Web Request security rules do not block the transmission.
  4. 04Clean existing duplicates: while the update prevents new duplicates from forming, you must manually merge or delete existing duplicate Field Service assets and Outlook emails.
  5. 05Verify financial exports: run a test batch of purchase invoices and regional tax exports to confirm data formatting remains intact.

Frequently asked questions

  1. 01What exactly is Business Central Update 28.5? It is a targeted deployment of 11 operational fixes and security improvements released by Microsoft between September 9 and September 30, 2026, impacting the Finance, Service, and Administration modules.
  2. 02Do I need to do anything to install the update? For Business Central Online (SaaS) users, Microsoft pushes the update automatically. However, you are responsible for testing how the update interacts with your unique customizations before it hits your live environment.
  3. 03Will this update break my existing customizations? It is a strong possibility. The Codeunit 248 restriction and the enhanced web request security protocols are highly likely to disrupt older, unmaintained custom code.
  4. 04Will the update delete my existing duplicate records automatically? No. The Microsoft patches only prevent the system from creating new duplicates moving forward. You must use the new Payables Agent utility or manual deletion to clean up legacy duplicates.
  5. 05We are a small business. Do these updates apply to us? Yes. If you utilize the Outlook connector, drop shipments, or any external software integrations, your environment is impacted regardless of your user count or transaction volume.
Free review

Update Readiness Review

ForgeSolutionz's Dynamics 365 specialists will test your specific customizations in a secure sandbox, flag any API vulnerabilities, and provide a clear, technical action plan to keep your operations running without interruption.

Book a consultation