Independent Security Architecture, SoD Conflict Resolution, and Entra ID Governance across D365 Finance & Operations and Business Central — delivered entirely without system access.
Three structural gaps that persist in D365 F&O and Business Central environments long after go-live — and cost organisations far more than they realise.
Accumulating conflicting AOT duties in F&O or additive Permission Sets in BC gives individual users end-to-end control over critical financial processes — enabling ghost vendor fraud, fictitious invoices, and unauthorized disbursements without triggering a single system alarm. ITGC auditors flag these as material weaknesses regardless of workflow controls in place.
Disabling a user in D365 F&O or Business Central does not release the paid M365 license. Microsoft bills against Entra ID assignments — not ERP user status. One disabled user per month goes unnoticed. Multiply across a 200-user tenant over three years and the unrecovered spend becomes material. The User License Counts report is deprecated in 10.0.49 — most IT teams don't know what replaced it.
Microsoft confirmed: users provisioned via Entra ID security groups bypass the native D365 F&O SoD engine entirely. The compliance batch job only scans direct role assignments — it ignores the group layer. Your ITGC reports show zero conflicts while users silently hold VendVendorMasterMaintain and VendPaymApprove simultaneously. Validated publicly by Microsoft MVP Alex Meyer.
Upload two standard Excel exports from D365 F&O or Business Central. Instantly see inactive users consuming licenses, shared accounts bypassing audit trails, duplicate accounts, and your overall governance risk score. All processing runs 100% inside your browser — no data ever leaves your machine.
Structured security governance delivered without system access, without disruption, and without the cost of a Big 4 engagement.
A multinational manufacturing organisation with 34 users on premium Operations licenses. A full entry-point audit revealed the vast majority only required Activity or Team Member access. Through targeted role redesign — removing unnecessary premium menu items without disrupting any operational workflow — 31 of 34 users were downsized to significantly cheaper license tiers. No system downtime. No customisation. Delivered remotely in 5 days. Cost recovery realised at the next Microsoft EA renewal.
Exhaustive technical guides on SoD governance, license optimization, XDS/TPF, and Entra ID security — written for CFOs, IT Directors, and Microsoft Partners.
The exact AOT duty names auditors scan for, why each creates fraud exposure, and how the Entra ID gap breaks standard checks.
Read article →Microsoft confirmed: BC and M365 Admin Center are two separate systems. Most IT teams discover this at renewal — at significant cost.
Read article →Native SoD checks ignore Entra ID group assignments. Your compliance reports show zero conflicts while users silently hold toxic access.
Read article →The User License Counts report is deprecated. Hard enforcement is live. Users without the correct license are now blocked — not warned.
Read article →Row-level security from a single role — but XDS has a critical OData bypass gap most architects miss. Here is the complete architecture.
Read article →SoD governance, license optimization, XDS/TPF, ITGC audit prep, BC permission sets, and more.
Browse full wiki →Questions CFOs, IT Directors, and Finance Directors ask most before engaging.
VendVendorMasterMaintain and VendPaymApprove through group membership while the compliance report shows zero violations.VendInvoiceMaintain and VendPaymApprove in their security roles, the auditor records a conflict regardless of whether a workflow requires a separate approver. The security layer and the process layer are evaluated independently.System Administration → Security → Security Governance → License Usage Summary. Outside D365 F&O — Power Platform Admin Center → Licensing → Finance and Operations → Export to CSV. The PPAC report is now the authoritative source for license compliance reporting.Independent security architecture for global enterprises. Direct engagement with the specialist — no account managers, no sales process. Just a conversation about your environment.