For CFOs, Finance Directors, and IT Directors managing Microsoft Dynamics 365 Finance & Operations environments, passing an IT General Controls (ITGC) or SOX compliance audit requires strict governance over role-based security. The primary mechanism for preventing internal fraud and financial misstatement is enforcing Segregation of Duties (SoD). When a single user accumulates conflicting duties within D365 F&O, they gain end-to-end control over critical financial processes without independent oversight.
Auditors do not evaluate display names — they extract and analyze the Application Object Tree (AOT) security architecture. If your security matrix allows a user to both initiate and execute a financial transaction, the resulting audit findings will mandate immediate remediation, often incurring significant consulting costs to untangle over-privileged roles.
The 6 Conflict Pairs Every Audit Will Flag
What it enables: Create new vendor records and approve outgoing payments to those vendors.
Why auditors flag it: This is the exact mechanism required to execute ghost vendor fraud — create a vendor, modify banking details, approve payment to an external account. Classified as a material weakness in Procure-to-Pay governance.
What it enables: Draft general ledger journal entries and approve those same entries for final posting.
Why auditors flag it: Bypasses the four-eyes principle. Enables a user to draft deceptive journals and approve them instantly — concealing misappropriated funds or artificially inflating revenue without detection prior to period close.
What it enables: Generate purchase orders and independently approve those orders, committing the organisation to vendor spend without secondary authorisation.
Why auditors flag it: Circumvents purchasing policy workflows and expenditure controls. Exposes the business to unauthorised procurement, kickback schemes, and uncontrolled liability accumulation.
What it enables: Create and modify customer master records including credit limits, while also generating and posting invoices for those customers.
Why auditors flag it: Facilitates fictitious sales to inflate revenue metrics — create a shell customer and post fraudulent AR entries. Also enables lapping schemes to conceal intercepted incoming payments.
What it enables: Create purchase requisitions across all departments and post product receipts confirming goods have arrived.
Why auditors flag it: Breaks segregation between procurement initiation and warehouse receiving. Enables an employee to requisition inventory and falsify system receipts even if goods were diverted or never delivered.
What it enables: Manually enter vendor invoices into the AP ledger and authorise payment journals settling those invoices.
Why auditors flag it: Direct path for unauthorised cash disbursement — process a fraudulent invoice and force payment journal through approval workflows. Auditors classify this as a terminal failure in the AP disbursement cycle and it guarantees audit failure if found unmitigated.
The Entra ID Provisioning Gap
Identifying these AOT duty conflicts is only effective if the native SoD rule engine evaluates all user assignments. A critical governance gap exists with modern identity management: users provisioned via Entra ID security groups bypass the D365 F&O native SoD checks entirely.
If your organisation assigns D365 F&O security roles by mapping them to Entra ID groups rather than assigning them directly to the user record in D365, the standard SoD conflict batch jobs return false negatives. The system does not unpack the Entra ID group payload to evaluate intersecting duties at the user level. Your ITGC reports show zero conflicts while users silently hold conflicting duties like VendVendorMasterMaintain and VendPaymApprove.
Organisations must extract both D365 role assignments and Entra ID group memberships and cross-reference them externally to execute an accurate SoD analysis.
Configuring SoD Rules in D365 F&O
To enforce these conflict pairs natively:
- Navigate to
System administration → Security → Segregation of duties → Segregation of duties rules - Create a new rule mapping the First duty against the Second duty for each conflict pair above
- Set severity to High for Critical pairs, Medium for High pairs
- Once active, D365 blocks role assignments containing both duties without a documented mitigation override
This article covers the standard conflict pairs. A complete SoD governance review includes conflict analysis across all custom roles, Entra ID group provisioning audit, and license tier reconciliation — delivered within 48 hours from two standard exports.