📖 Security & Governance Wiki

D365 F&O & Business Central Security Knowledge Base

Technical deep-dives on SoD governance, license optimization, XDS/TPF, Entra ID security, and ITGC audit preparation — written for CFOs, IT Directors, and Microsoft Partners.

The 6 SoD Conflict Pairs Every D365 F&O Audit Will Flag

The exact AOT duty names auditors scan for, why each conflict creates fraud exposure, and how the Entra ID provisioning gap makes standard SoD checks unreliable.

Why Disabling a User in BC Does Not Release Their M365 License

Microsoft confirmed: BC and M365 Admin Center are two separate systems. Most IT teams discover this at renewal — at significant and recoverable cost.

The Entra ID Provisioning Gap That Bypasses D365 SoD Checks Entirely

Native SoD checks ignore Entra ID group assignments. Your compliance reports show zero conflicts while users silently hold toxic access combinations.

D365 F&O Licensing in 10.0.49 — What Changed and What to Check Now

The User License Counts report is deprecated. Hard enforcement is live. Users without the correct license are now blocked — not warned. Here is what changed.

XDS in D365 F&O — How to Stop Role Sprawl Without Duplicate Roles

Row-level security from a single role — but XDS has a critical OData bypass gap most architects miss. Here is the complete architecture and performance guidance.

BC Permission Sets — How to Build a Defensible SoD Framework Without a Native Engine

BC has no native SoD engine. The entire governance burden falls on permission set design and administrative discipline. Here is the methodology.

The D365 F&O Security Role Architecture — Duties, Privileges, and Entry Points Explained

The four-layer hierarchy every IT Director must understand before designing roles — and how entry points determine license tier and audit exposure.

How to Prepare for a D365 F&O ITGC Audit — What Auditors Extract and What They Flag

The five data extracts auditors always request, what they look for in each, and the 90-day readiness checklist to avoid material weakness findings.

Reducing D365 F&O License Costs by 92% — The Role Redesign Methodology

A four-step methodology to identify, engineer, and recover premium license waste. How 31 of 34 users were downsized without disrupting a single operational workflow.

The SoD Translation Matrix — Mapping D365 F&O Duties to BC Permission Sets

Hybrid F&O and BC environments create a dual governance challenge. The same business risk surfaces differently in each ERP. Here is the translation framework.