The D365 F&O Security Role Architecture — Duties, Privileges, and Entry Points Explained
The four-layer hierarchy every IT Director must understand before designing roles — and how entry points determine license tier and audit exposure.
XDS in D365 F&O — How to Stop Role Sprawl Without Duplicate Roles
Row-level security from a single role — but XDS has a critical OData bypass gap most architects miss. Here is the complete architecture.
How to Configure Emergency "Firefighter" Access in D365 F&O to Pass IT Audits
Persistent SysAdmin access is an automatic material weakness. Build compliant Just-In-Time access using Entra ID PIM, database logging, and automated alerts.
Securing Vendor Bank Details in D365 F&O: A Complete Guide to the Table Permissions Framework
XDS is bypassed by OData and Open in Excel. TPF provides kernel-level field security that auditors actually accept. Step-by-step VendBankAccount lockdown.
Securing D365 F&O Sandbox Environments: How to Mask Sensitive Data During Production-to-UAT Refreshes
A database refresh copies live vendor bank accounts, customer addresses, and employee data into UAT. Developers see everything. Here is the automated fix.
The Entra ID Provisioning Gap That Bypasses D365 SoD Checks Entirely
Native SoD checks ignore Entra ID group assignments. Your compliance reports show zero conflicts while users silently hold toxic access combinations.
BC Permission Sets — How to Build a Defensible SoD Framework Without a Native Engine
BC has no native SoD engine. The entire governance burden falls on permission set design. Here is the RIMDE model, dangerous combinations, and audit methodology.
The 6 SoD Conflict Pairs Every D365 F&O Audit Will Flag
The exact AOT duty names auditors scan for, why each conflict creates fraud exposure, and how the Entra ID gap makes standard SoD checks unreliable.
The SoD Translation Matrix — Mapping D365 F&O Duties to BC Permission Sets
Hybrid F&O and BC environments create a dual governance challenge. The same business risk surfaces differently in each ERP. Here is the translation framework.
D365 F&O Multiplexing Explained: How Power Apps Can Trigger License Audit Fines
Routing users through Power Apps or API middleware does not reduce license requirements. Microsoft's backend telemetry sees straight through to the human clicking the button.
D365 F&O Licensing in 10.0.49 — What Changed and What to Check Now
The User License Counts report is deprecated. Hard enforcement is live. Users without the correct license are now blocked — not warned.
BC Team Member vs. Essential License: The Exact Table Limits That Trigger Non-Compliance
The $8 Team Member license has hardcoded write limitations enforced by Microsoft telemetry. The 3 custom objects rule catches most implementations off guard.
Why Disabling a User in BC Does Not Release Their M365 License
BC and M365 Admin Center are two separate systems. Most IT teams discover this at renewal — at significant and recoverable cost.