📖 Security & Governance Wiki

D365 F&O & Business Central Technical Reference

15 verified technical guides covering SoD governance, license optimization, XDS/TPF, Entra ID security, ITGC audit preparation, and data privacy — written for CFOs, IT Directors, and Microsoft Partners.

🔐
Security & Role Architecture
5 articles
Concepts

The D365 F&O Security Role Architecture — Duties, Privileges, and Entry Points Explained

The four-layer hierarchy every IT Director must understand before designing roles — and how entry points determine license tier and audit exposure.

XDS in D365 F&O — How to Stop Role Sprawl Without Duplicate Roles

Row-level security from a single role — but XDS has a critical OData bypass gap most architects miss. Here is the complete architecture.

How-to Guides

How to Configure Emergency "Firefighter" Access in D365 F&O to Pass IT Audits

Persistent SysAdmin access is an automatic material weakness. Build compliant Just-In-Time access using Entra ID PIM, database logging, and automated alerts.

Securing Vendor Bank Details in D365 F&O: A Complete Guide to the Table Permissions Framework

XDS is bypassed by OData and Open in Excel. TPF provides kernel-level field security that auditors actually accept. Step-by-step VendBankAccount lockdown.

Securing D365 F&O Sandbox Environments: How to Mask Sensitive Data During Production-to-UAT Refreshes

A database refresh copies live vendor bank accounts, customer addresses, and employee data into UAT. Developers see everything. Here is the automated fix.

💸
Licensing & Cost Optimization
5 articles
Strategy

Reducing D365 F&O License Costs by 92% — The Role Redesign Methodology

A four-step methodology to identify and recover premium license waste. How 31 of 34 users were downsized without disrupting a single operational workflow.

D365 Finance & Operations

D365 F&O Multiplexing Explained: How Power Apps Can Trigger License Audit Fines

Routing users through Power Apps or API middleware does not reduce license requirements. Microsoft's backend telemetry sees straight through to the human clicking the button.

D365 F&O Licensing in 10.0.49 — What Changed and What to Check Now

The User License Counts report is deprecated. Hard enforcement is live. Users without the correct license are now blocked — not warned.

Business Central

BC Team Member vs. Essential License: The Exact Table Limits That Trigger Non-Compliance

The $8 Team Member license has hardcoded write limitations enforced by Microsoft telemetry. The 3 custom objects rule catches most implementations off guard.

Why Disabling a User in BC Does Not Release Their M365 License

BC and M365 Admin Center are two separate systems. Most IT teams discover this at renewal — at significant and recoverable cost.