In IFS Mobile Work Order (MWO), Security Groups and Entity Configuration
defines how access, data synchronization, and mobile functionality operate in
IFS Mobile Work Order (MWO). These elements determine what data is available
on mobile devices, which features and workflows are accessible, and how efficiently
the system performs. Together, they ensure a stable, predictable, and optimized
mobile experience within IFS Cloud.
This content applies to System Administrators, Solution Consultants, and
technical roles responsible for configuring MWO access, data synchronization,
and mobile capabilities.
In MWO, Security Groups and Entities operate as coordinated components that control:
Correct configuration ensures:
Security Groups are functional groupings that define both
data synchronization and feature availability within the mobile application.
They control:
If required Security Groups are missing:
Security Groups are granted through Permission Sets rather than being assigned directly to end users.

Security groups that are no longer required can be revoked to reduce unnecessary access and minimize synchronization overhead.
For example, security groups related to unused functionality such as Request Quotation , Service Quotation or Purchasing can be removed to streamline the configuration.

Entities represent the data objects that are synchronized between IFS Cloud and the mobile application, such as tasks, activity types, and materials.
Each entity:
Entities determine:
Entities assigned to Security Groups can be reviewed under
Synchronization Rules.
Note: Online-only
entities are not included in Synchronization Rules.

A Permission Set in IFS Cloud :
Without a Permission Set:

The configuration process connects Security Groups, Entities, and Permission Sets to establish a complete setup.
This flow includes the following steps:
These elements work together to ensure that the correct data and functionality
are available to mobile users.
Navigate to: Solution Manager / Access Control / Permission Sets
(see above Permission Sets )
Note : This is typically the
LTU permission set granted to MWO end users. It is also possible
to create a Permission Set to grant access to IFS Service MWO and/or IFS Maintenance
MWO features and functions.
Ensure the Permission Set:
Projection access is mandatory for sending mobile transactions to the server.
Note : Administrators can manage IFS Cloud Mobile apps from the IFS Cloud Web using the MOBILE_APP_ADMIN permission set, which grants full access to Solution Manager / Mobile Apps features.
Navigate to: Solution Manager / Mobile Apps / Administration
/ Security Grants and Entity Filters / Security Grants by Permission Set
For the Permission Set:
Missing Security Groups are a common cause of missing pages in MWO.
IFS Service MWO app supports both Work Order based and Request based service solutions. If the customer uses only the Work Order based service process , it is important to avoid granting Request‑specific Security Groups, as they provide no functional value in that scenario. Excluding unnecessary Security Groups can also improve client performance by reducing the amount of irrelevant data synchronized to the mobile device.
These can be ignored when using the Work Order–based service solution:
These can be ignored when using the Request‑based service solution:
Navigate to: Solution Manager / Mobile Apps / Configuration / Synchronization Rules
For each synchronized entity:
Note : Depending on how frequently the entity data changes, the schedule can be adjusted accordingly.
Security Groups act as containers for entities, making it easier to:
Entity Filters reduce data volume and improve performance.
Navigate to: Solution Manager / Mobile Apps / Administration / Security Grants and Entity Filters / Entity Filters
It is possible to:
Examples:
Filters apply at the row level, not at the UI level.
Note : If entity synchronization is not required , it can be fully restricted by applying a filter such as 1=0


The Synchronized Volume indicates which entities sync the largest volumes
of data. Filter by App Name and end‑user Device ID
(avoid using a super user) to view real‑time data load.

After making changes:

Correct configuration of MWO Security Groups and Entities ensures:
Security Groups define what, Entities define which data, and Permission Sets define who gets access.