Technical deep-dives on SoD governance, license optimization, XDS/TPF, Entra ID security, and ITGC audit preparation — written for CFOs, IT Directors, and Microsoft Partners.
The exact AOT duty names auditors scan for, why each conflict creates fraud exposure, and how the Entra ID provisioning gap makes standard SoD checks unreliable.
Microsoft confirmed: BC and M365 Admin Center are two separate systems. Most IT teams discover this at renewal — at significant and recoverable cost.
Native SoD checks ignore Entra ID group assignments. Your compliance reports show zero conflicts while users silently hold toxic access combinations.
The User License Counts report is deprecated. Hard enforcement is live. Users without the correct license are now blocked — not warned. Here is what changed.
Row-level security from a single role — but XDS has a critical OData bypass gap most architects miss. Here is the complete architecture and performance guidance.
BC has no native SoD engine. The entire governance burden falls on permission set design and administrative discipline. Here is the methodology.
The four-layer hierarchy every IT Director must understand before designing roles — and how entry points determine license tier and audit exposure.
The five data extracts auditors always request, what they look for in each, and the 90-day readiness checklist to avoid material weakness findings.
A four-step methodology to identify, engineer, and recover premium license waste. How 31 of 34 users were downsized without disrupting a single operational workflow.
Hybrid F&O and BC environments create a dual governance challenge. The same business risk surfaces differently in each ERP. Here is the translation framework.