ITGC-AM-004
Sarah Jenkins — VP of IT
D365 F&O · Cloud · v10.0.47
4 Hours per Incident
SysDatabaseLog · SPLUNK
Privileged Access Log Entries — Q3 2026
INC-2026-8804
✓ Closed — Reviewed
Request Date
28 July 2026
Requestor
David Sterling — D365 L3 Technical Lead
Approver
Sarah Jenkins — VP of IT
Business Justification
Critical production batch failure. Master Planning MRP explosion crashed. Required SysAdmin access to debug ReqTransPoFirm batch job failure and clear corrupt stranded tasks in BatchJob and Batch tables. Production planning engine fully offline — immediate remediation required.
Access Granted (UTC)
2026-07-28 02:15:00
Access Revoked (UTC)
2026-07-28 03:45:00
Duration
1h 30m — Within policy threshold
Actions Performed in System
1. Cleared 14 stranded batch tasks from BatchJob table via Table Browser — all tasks in ERROR state.
2. Restarted Master Planning periodic batch job (ReqTransPoFirm) via Batch Jobs administration screen.
3. Verified MRP explosion completed successfully — 847 planned orders generated.
4. No financial master data, vendor records, or transactional data was modified or accessed.
2. Restarted Master Planning periodic batch job (ReqTransPoFirm) via Batch Jobs administration screen.
3. Verified MRP explosion completed successfully — 847 planned orders generated.
4. No financial master data, vendor records, or transactional data was modified or accessed.
Audit Trail Reference
SPLUNK-LOG-8804 · Verified session activity cross-referenced against SysDatabaseLog telemetry — confirms scope limited to batch administration tables only
Sarah Jenkins
VP of IT · 28 Jul 2026
K. Patel
IT Audit Manager · 29 Jul 2026
CHG-2026-1192
✓ Closed — Reviewed
Request Date
05 August 2026
Requestor
Amina Rashid — D365 Functional Consultant
Approver
Sarah Jenkins — VP of IT
Business Justification
Zero-day quality update deployment mandated by Microsoft (Service Release 10.0.47 PU71). LCS package deployment requires SysAdmin rights to execute database synchronisation scripts, validate License Configuration keys in Maintenance Mode, and rotate environment certificates post-update. Planned change — approved via CHG board 03-Aug-2026.
Access Granted (UTC)
2026-08-05 22:00:00
Access Revoked (UTC)
2026-08-05 23:15:00
Duration
1h 15m — Within policy threshold
Actions Performed in System
1. Executed full database synchronisation (syncmode fullall) post service release deployment.
2. Validated License Configuration keys in Maintenance Mode — confirmed Inventory dimension 1 and core keys active.
3. Rotated SSL certificates for AOS endpoints via LCS Environment Maintain — Update settings.
4. Disabled Maintenance Mode. Verified AOS service restart successful.
5. No business transactions executed during session.
2. Validated License Configuration keys in Maintenance Mode — confirmed Inventory dimension 1 and core keys active.
3. Rotated SSL certificates for AOS endpoints via LCS Environment Maintain — Update settings.
4. Disabled Maintenance Mode. Verified AOS service restart successful.
5. No business transactions executed during session.
Audit Trail Reference
LCS-DEPLOY-1192 · Corroborated with LCS Environment History deployment log · CHG-2026-1192 approved change record
Sarah Jenkins
VP of IT · 05 Aug 2026
K. Patel
IT Audit Manager · 06 Aug 2026
INC-2026-8911
✓ Closed — Reviewed
Request Date
12 August 2026
Requestor
Thomas Clarke — Integration Specialist
Approver
Sarah Jenkins — VP of IT
Business Justification
Dual Write integration suspended following synchronous validation errors on CustTable via PreCommitPlugin. 12 Customer records stuck in failed sync state — blocking Sales Order creation for GCC entities. Elevated access required to reset Dual Write runtime configurations and force initial sync for affected records.
Access Granted (UTC)
2026-08-12 14:00:00
Access Revoked (UTC)
2026-08-12 14:30:00
Duration
30m — Within policy threshold
Actions Performed in System
1. Navigated to Data Management workspace — Dual Write entity maps.
2. Restarted Dual Write entity map Customers V3 (CustTable → Dataverse Account).
3. Triggered initial sync for 12 stuck customer records — all synced successfully to Dataverse.
4. Verified Dual Write integration status — all entity maps returned to Running state.
5. No master data modifications performed — sync operation only.
2. Restarted Dual Write entity map Customers V3 (CustTable → Dataverse Account).
3. Triggered initial sync for 12 stuck customer records — all synced successfully to Dataverse.
4. Verified Dual Write integration status — all entity maps returned to Running state.
5. No master data modifications performed — sync operation only.
Audit Trail Reference
SPLUNK-LOG-8911 · Dual Write sync history export · SysDatabaseLog confirms no CustTable field modifications during session
Sarah Jenkins
VP of IT · 12 Aug 2026
K. Patel
IT Audit Manager · 13 Aug 2026
Q3 2026 Quarterly Access Summary
3
Total Requests
3
Approved
0
Policy Breaches
100%
Independent Review Rate
Auditor Note: All privileged access sessions were pre-approved by the VP of IT, independently post-reviewed by the IT Audit Manager within 24 hours, and cross-referenced against SysDatabaseLog and SPLUNK telemetry. No policy violations, no unauthorised data access, and no sessions exceeding the 4-hour maximum duration policy were identified during Q3 2026.