For publicly traded companies, SOX Section 404 mandates an annual assessment of internal controls over financial reporting — which inherently relies on Information Technology General Controls (ITGC). When external auditors examine a D365 F&O environment, they pull system-generated data to verify access controls, SoD enforcement, and user lifecycle management.
The Five Data Extracts Auditors Always Request
When an ITGC audit commences, auditors issue a Prepared by Client (PBC) request list. For D365 F&O, they mandate five specific system-generated extracts — which must be provided exactly as exported, without manual manipulation.
System Administration → Inquiries → Security → User Role AssignmentsSystem Administration → Security → Segregation of Duties → Segregation of Duties ConflictsWhat Auditors Look For in Each Extract
User Role Assignments: Privilege creep — users who have accumulated conflicting functional roles over time, such as holding both AP Clerk and AR Clerk simultaneously, without older roles being revoked after a job transfer.
SoD Conflict Report: Unresolved violations. A critical governance reality: an SoD conflict at the security assignment level is a finding even if workflow approvals technically prevent the user from executing the transaction. The security assignment itself constitutes the failure.
Privileged Access List: Standard business users holding elevated IT rights that allow them to bypass financial controls or alter system configurations without change management oversight.
Terminated User Review: Timeline gaps. If an employee was terminated by HR on the 15th but their D365 F&O account remained active until the 20th, that gap is a control failure — regardless of whether the account was used.
System Administrator List: Named business users, external consultants, or generic shared accounts improperly assigned to this role.
The Most Common ITGC Findings
- Unresolved SoD conflicts: Rules configured during implementation but never monitored — leaving active violations sitting in the system
- Terminated users with active access: IT provisioning processes disconnected from HR offboarding
- Generic shared accounts: Integration User, Batch Admin — tasks that cannot be tied to a specific accountable individual
- Custom roles with unintentional conflict bundles: Vendor creation and payment generation combined without triggering native SoD alerts
What a Material Weakness Means
⚠️ Automatic Material Weakness — System Administrator Role
Assigning the System Administrator role to a non-IT user — a CFO, AP Manager, or functional consultant — is an automatic material weakness. The System Administrator role bypasses all SoD rules and audit logs. That user could create a fictitious vendor, process a fraudulent payment, and delete the transaction log without detection.
For public companies, a material weakness requires explicit disclosure in SEC filings — typically resulting in an immediate drop in stock price, loss of investor confidence, and vastly expanded substantive audit testing that drives up external audit fees by hundreds of thousands of dollars.
90-Day Readiness Checklist
System Administration → Security → Segregation of Duties → Segregation of Duties Conflicts and formally resolve all active violations. Do not rely on workflow as a substitute.A pre-audit governance review for D365 F&O — covering all five auditor extracts, SoD conflicts, terminated user access, and privileged account list — delivered within 48 hours. No system access required.