← Back to Security Wiki
D365 F&O ITGC SOX August 2026 · 8 min read · Verified

How to Prepare for a D365 F&O ITGC Audit — What Auditors Extract and What They Flag

External auditors do not evaluate financial data directly. They evaluate the logical access controls protecting that data. If your ITGC framework fails, the financial audit fails — regardless of the accuracy of your general ledger.

For publicly traded companies, SOX Section 404 mandates an annual assessment of internal controls over financial reporting — which inherently relies on Information Technology General Controls (ITGC). When external auditors examine a D365 F&O environment, they pull system-generated data to verify access controls, SoD enforcement, and user lifecycle management.

The Five Data Extracts Auditors Always Request

When an ITGC audit commences, auditors issue a Prepared by Client (PBC) request list. For D365 F&O, they mandate five specific system-generated extracts — which must be provided exactly as exported, without manual manipulation.

1User Role Assignments
Path: System Administration → Inquiries → Security → User Role Assignments
Complete export of every active user and their assigned security roles across all legal entities.
2Segregation of Duties Conflict Report
Path: System Administration → Security → Segregation of Duties → Segregation of Duties Conflicts
Extract from the native SoD rule engine documenting all unresolved duty conflicts currently active in the system.
3Privileged Access List
Generated from User Role Assignments — filtered for administrative roles
Users holding high-risk administrative roles — Security Administrator, IT Manager, or custom roles with direct table update capabilities.
4Terminated User Access Review
Cross-reference: HR termination records vs D365 F&O active user list
Reconciliation of Human Resources termination records against the D365 F&O active user list for the entire audit period.
5System Administrator Account List
Subset of User Role Assignments — filtered for System Administrator role
All users assigned the native System Administrator role — which bypasses all system security controls.

What Auditors Look For in Each Extract

User Role Assignments: Privilege creep — users who have accumulated conflicting functional roles over time, such as holding both AP Clerk and AR Clerk simultaneously, without older roles being revoked after a job transfer.

SoD Conflict Report: Unresolved violations. A critical governance reality: an SoD conflict at the security assignment level is a finding even if workflow approvals technically prevent the user from executing the transaction. The security assignment itself constitutes the failure.

Privileged Access List: Standard business users holding elevated IT rights that allow them to bypass financial controls or alter system configurations without change management oversight.

Terminated User Review: Timeline gaps. If an employee was terminated by HR on the 15th but their D365 F&O account remained active until the 20th, that gap is a control failure — regardless of whether the account was used.

System Administrator List: Named business users, external consultants, or generic shared accounts improperly assigned to this role.

The Most Common ITGC Findings

What a Material Weakness Means

⚠️ Automatic Material Weakness — System Administrator Role

Assigning the System Administrator role to a non-IT user — a CFO, AP Manager, or functional consultant — is an automatic material weakness. The System Administrator role bypasses all SoD rules and audit logs. That user could create a fictitious vendor, process a fraudulent payment, and delete the transaction log without detection.

For public companies, a material weakness requires explicit disclosure in SEC filings — typically resulting in an immediate drop in stock price, loss of investor confidence, and vastly expanded substantive audit testing that drives up external audit fees by hundreds of thousands of dollars.

90-Day Readiness Checklist

1
Clean the System Administrator ListRestrict the System Administrator role strictly to named, dedicated IT personnel. Remove all business users, executives, and external partner accounts immediately.
2
Resolve SoD ConflictsNavigate to System Administration → Security → Segregation of Duties → Segregation of Duties Conflicts and formally resolve all active violations. Do not rely on workflow as a substitute.
3
Execute a Ghost User PurgeReconcile your HR termination list against the Microsoft 365 Admin Center and D365 F&O user list. Ensure all terminated employees are explicitly disabled in F&O.
4
Review Custom RolesAudit custom roles for hidden elevated privileges. Ensure users have the minimum necessary access required for their designated job function.
5
Validate Log IntegrityEnsure database logging is enabled for critical security setup tables and that these logs cannot be deleted by standard administrators.

A pre-audit governance review for D365 F&O — covering all five auditor extracts, SoD conflicts, terminated user access, and privileged account list — delivered within 48 hours. No system access required.