Showing posts with label D365FO. Show all posts
Showing posts with label D365FO. Show all posts

Friday, September 12, 2025

Privileged User Management in Dynamics 365 Finance and Supply Chain Management (D365F&SCM)



PRIVILEGED USER MANAGEMENT IN DYNAMICS 365 FINANCE AND SUPPLY CHAIN MANAGEMENT (D365F&SCM)

CONTENT

Introduction
Importance of time-bound security role assignment
Enabling time-bound security role assignment
Configuring time-bound security role assignment
Temporary Role Management
Privileged User Management
Demo
Conclusion

INTRODUCTION 

Managing privileged access is one of the most critical aspects of ERP security. In many organizations, users occasionally require elevated permissions—for example, to troubleshoot, perform testing, or complete month-end tasks. The problem arises when these elevated permissions remain active longer than necessary, creating security risks, compliance issues, and audit findings.

To address this challenge, Dynamics 365 Finance & Supply Chain Management (D365F&SCM) introduces time-bound role assignments as part of the User Security Governance module. 

  • This feature allows administrators to grant elevated roles to users only for a defined period via Temporary role management form.  Once the time expires, the system automatically revokes access.
  • At the same time, all activities performed under temporary access are tracked and logged, giving organizations the transparency needed for compliance and governance via Privileged user management.

In this article, we will cover why time-bound assignments matter, how to set them up, walk through a demo scenario, and explore how to monitor and audit their usage.

IMPORTANCE OF TIME-BOUND ROLE ASSIGNMENTS

Time-bound assignments are a practical answer to the problem of “standing” privileged access. Here’s why they are so important:

1. Compliance and Auditability: Regulations such as SOX and internal ITGC frameworks require organizations to demonstrate that elevated access is both controlled and temporary. Permanent administrator rights are a common audit finding because they create opportunities for inappropriate or undocumented activity.

Time-bound roles directly support compliance by ensuring access is limited to a defined window, automatically revoked afterward, and fully logged. This provides auditors with clear evidence that access management controls are designed and operating effectively.

From a segregation of duties (SOD) perspective, temporary assignments can also help organizations prove that conflicts are managed. If a role temporarily grants a user conflicting capabilities (e.g., vendor setup and payment release), the short validity period and audit trail demonstrate that the risk was identified, limited, and monitored.

2. Reduced Risk: Long-term administrator or finance manager roles create opportunities for fraud or unauthorized changes. Temporary assignments reduce this risk by limiting access to the minimum necessary time.

3. Operational Flexibility: Users can still be granted elevated roles to complete tasks without waiting for lengthy manual processes. The system handles the removal automatically.

4. Transparency: Security teams and auditors can easily review who had privileged access, for how long, and what actions they performed. This closes the loop between granting access and proving it was used responsibly.

ENABLING TIME-BOUND SECURITY ROLE ASSIGNMENT

Before you can use this functionality, ensure that the User Security Governance feature is enabled:

1. Go to System administration > Workspaces > Feature management.

2. Search for User security governance.

3. Select Enable now.











Once enabled, the feature is available under:

System administration > Security > Security governance > Temporary role management

and

System administration > Security > Security governance > Privileged user management

CONFIGURING TIME-BOUND SECURITY ROLE ASSIGNMENT

A complete solution consists of two configuration components:

  • Assigning temporary security roles to users through the Temporary Role Management form.
  • Monitoring and tracking their system activities using Privileged User Management.



Temporary Role Management

Temporary role management lets system administrators assign temporary roles to a specific user account for a specific amount of time (known as a session). This feature is useful when a user in a company is away from work for a period, or if a role must temporarily be divided among multiple users. When the session ends, the user account returns to its original roles.

Note: Do not forget to add System user, otherwise below error will appear



Privileged User Management

Privileged user management lets system administrators schedule a session for selected user accounts. All user interactions are recorded in Dynamics 365 finance and operations apps during that session, if the user decides to continue using Dynamics 365 finance and operations after reading the consent on the landing page. This feature is useful when some elevated privileged accounts are used for auditing purposes. It helps ensure that users aren't performing any unauthorized activities in the system and keeps a recording of it, in case it's later needed for audit or compliance reviews.

System administrators can choose to enable or disable the given user account once the session begins. As soon as the session ends, the account returns to its original state.



DEMO

Scenario

A specific user (Dogan) requires the Accountant role for 30 minutes to perform troubleshooting.

To maintain compliance, the System administrator will temporarily assign this role and record the user’s activities to ensure that no configuration changes are made that could create material impact

Solution Overview

The solution requires two configurations:

  • Assign the role temporarily via the Temporary role management form.
  • Record user activities via the Privileged user management form.

Assigning the Accountant Role Temporarily

Navigate to System administration > Security > Security governance > Temporary role management

1. Create a new entry and assign the User ID.

2. Choose whether the temporary role will be merged with existing roles or replace them.

3. Enter the start and end time of the assignment. 

In this scenario, the role is assigned for 30 minutes (4:00 - 4:30)

4. Select the temporary roles to be assigned (Accountant and System user).

5. Change the entry's status to Planned so that batch job can process it.

Note: Original roles can be viewed in the Original roles fast tab.

Required setup is as shown below:



The next step is to configure a recurring batch job that processes pending temporary role assignments:

  • This setup is a one-time task.
  • Once scheduled, the batch job will periodically run and update assignments based on entries in the Temporary role management form.






When processed, the entry status will be updated to Active.



The role assignment will then appear as shown:



Privileged User Management

Navigate to System administration > Security > Security governance > Privileged user management

1. Create a new line and assign the User ID.

2. Enter the start and end time for task recording. In this scenario, recording runs for 25 minutes (4:05 - 4:30).

3. Change the entry's status to Approved so that batch job can process it.

4a. Setup the batch job if there isn't one working actively.

4b. No need to setup a batch job if there is one working actively.







Note that batch job runs and updates entry status to Approved.



At this point, the user receives a notification that their session is being recorded.



When the temporary role assignment  expires, the entry status becomes Finished.



When task recording expires, privileged user management entry's status becomes Ended.



Reviewing Recorded Activities

Recorded file can now be downloaded.



Downloaded recording file can now be uploaded into Security diagnostics for task recording form.

Navigate to System administration > Security > Security diagnostics for task recordings



Select Open from this PC.



Click Browse.



Select downloaded recording file.



After upload completes, the system displays all recorded security entry points and the screens visited by the user.

At this point, the demonstration is complete: the user was granted temporary access, their session was recorded, and the resulting file was analyzed for transparency. This end-to-end process illustrates how D365FO provides both operational flexibility and the necessary audit trail to support compliance requirements.



Conclusion

Temporary role assignments and privileged user activity recordings provide organizations with a structured way to balance operational needs and compliance requirements. By enabling short-term access to sensitive roles and automatically tracking the resulting activities, D365FO helps ensure that users can perform troubleshooting or exception handling without creating long-term segregation of duties risks. From a SOX and internal controls perspective, this capability is critical because it demonstrates that access is both time-bound and monitored, reducing the likelihood of unauthorized configuration changes or material misstatements. Establishing this governance framework not only strengthens audit readiness but also promotes a culture of accountability and transparency across the organization.

Monday, September 1, 2025

User Security Governance in Dynamics 365 Finance and Supply Chain Management (D365F&SCM)

















USER SECURITY GOVERNANCE IN DYNAMICS 365 FINANCE AND SUPPLY CHAIN MANAGEMENT (D365F&SCM)

CONTENT

Overview
User security governance features
Conclusion

OVERVIEW

User Security Governance in Dynamics 365 Finance and Operations (D365FO) provides organizations with a structured framework to define, monitor, and manage user access, ensuring users have only the permissions necessary for their roles. This new Security Governance feature is available in the System administration module. It was introduced in preview with version 10.0.43 (2025 release wave 1) and became generally available with version 10.0.44, requiring activation in the Feature Management workspace.

The solution focuses on core capabilities such as detailed reporting for segregation of duties (SOD) and privileged access, process-based role and duty management, creation of new roles from existing objects, temporary role assignments, and privileged user management for time-bound access. These features simplify permission setup, particularly during new implementations, help prevent unauthorized activity, reduce errors, and support regulatory compliance with built-in audit and reporting tools. By aligning user roles with appropriate license types, organizations can also achieve cost efficiency while maintaining control and transparency across their security model.

USER SECURITY GOVERNANCE FEATURES

User security governance provides the following functionality:

Design process-based security roles, duties and privileges: A process hierarchy provides a way to organize and manage the business processes in your company. After you define the process hierarchy for your company, you can assign various tasks, and define roles, entry points, and privileges according to the business requirements. This feature has 2 components.

Security category: Security categories are custom-defined labels or tags used within “Process roles maintain” to group and categorize roles by business stream, department, function, or any logical grouping relevant to your organization. My sample categories are as follows.

Go to System administration > Security > Security governance > Security category


Process hierarchy: The process hierarchy is the foundation of organizing security role components in Dynamics 365 Finance and Operations. This step is critical because it ensures that security design aligns with how the business actually operates. Organizations should invest sufficient time in analyzing and identifying the tasks that are relevant to their specific business processes.








Once the applicable tasks are defined, the system provides the framework to configure and fine-tune security roles.

Go to System administration > Security > Security governance > Security process roles maintain

Within this screen, you can:

  • Create new roles.
  • Rename and restructure existing roles.
  • Organize tasks under the appropriate role.
  • Create duties and privileges manually.
  • Generate duties and privileges automatically from task recordings.










By carefully managing the process hierarchy, companies establish a clear and logical security structure that not only meets compliance requirements but also simplifies ongoing maintenance and scalability of security in D365FO

Lastly, synchronize function syncs any changes done directly into security duties and privileges on the Core security configuration page.

When duties, privileges, and roles are created from Security governance and published to core security configuration, users can edited them in Security configuration by either adding or removing entry points. By doing this, the security object is different between two pages.

To restore changes from security configuration into security governance, use the Synchronize feature by selecting a process hierarchy level.

Go to System administration > Security > Security governance > Security process role maintain.

On the header, select Synchronize to use the feature.







Other Features

This new module allows admins to 

  • Grant time-bound elevated privileges to dedicated accounts through privileged user management. We will discuss this in the next article in detail.
  • Continuously monitor segregation of duties and separation of privileges. Define a threshold, and control the creation of duties/privileges that have overlapping entry points.
  • Use the security audit trail to track changes that are made in user security governance.

CONCLUSION

User Security Governance in D365F&SCM introduces a governance framework that links security design directly to business processes. By leveraging a process hierarchy, organizations can create meaningful security models that align with how operations are actually performed, rather than relying on generic role structures. The module also addresses long-standing challenges such as managing privileged accounts, offering time-bound elevated access that reduces risk exposure while supporting operational needs.

Built-in monitoring and reporting, including segregation of duties analysis and audit trails, provide the transparency required for compliance and external reviews. At the same time, features such as task-based duty generation and synchronization with core security simplify ongoing maintenance and keep design consistent across environments. When combined with licensing optimization, these capabilities deliver both stronger controls and measurable cost efficiency.

In practice, this module helps organizations balance usability, compliance, and scalability. It reduces manual effort, minimizes audit risks, and provides a flexible structure that can evolve with the business. For companies seeking to strengthen their control environment in Dynamics 365 while streamlining administration, User Security Governance represents a significant step forward.

Sunday, June 15, 2025

Designing Approval Workflows in Dynamics 365 Finance with a SOX-Compliance Lens











DESIGNING APPROVAL WORKFLOWS IN DYNAMICS 365 FINANCE WITH A SOX-COMPLIANCE LENS

CONTENT

Introduction
Why Every SOX Control Framework Must Include Robust Approval Workflows
How D365FO Workflow Maps to SOX Control Objectives
Control Design Choices That Auditors Will Question
Test of Design (TOD) - Configuring a SOX-ready Purchase Order Approval
Test of Effectiveness (TOE) - Executing a Sample Purchase Order Workflow
Extra: Workflow Escalation: Ensuring Control Continuity
Conclusion

INTRODUCTION 

In today’s regulatory landscape, internal controls are no longer optional—they are an operational necessity. For organizations subject to the Sarbanes-Oxley Act (SOX), especially Section 404, demonstrating that transactions are properly authorized, reviewed, and traceable is critical to passing an external audit. Dynamics 365 Finance and Operations (D365FO) offers built-in workflow capabilities that, when thoughtfully configured, can enforce these control requirements directly within the system. This article explores how to design and implement approval workflows in D365FO that satisfy SOX compliance expectations, with a focus on practical configuration guidance, control alignment, and audit-readiness.

WHY EVERY SOX CONTROL FRAMEWORK MUST INCLUDE ROBUST APPROVAL WORKFLOWS

Section 404 of the Sarbanes-Oxley Act (SOX) requires management to assert—and external auditors to attest—that the company maintains effective internal control over financial reporting. In practice that means every financially significant transaction must be:

1. Authorized by the right people,

2. Executed in line with documented policies, and

3. Evidenced so that an auditor can reconstruct who approved what, when, and why.

Dynamics 365 Finance & Operations (D365FO) contains a flexible workflow engine that can satisfy all three conditions—if you design it properly. Approvals, when combined with Segregation of Duties (SoD) rules, prevent the classic “create and approve my own transaction” scenario that violates SOX assertions.

HOW D365FO WORKFLOW MAPS TO SOX CONTROL OBJECTIVES

To effectively support SOX compliance, organizations must align system capabilities with specific control objectives—and Dynamics 365 Finance offers the features needed to do just that.








CONTROL DESIGN CHOICES THAT AUDITORS WILL QUESTION

Even with strong workflow tools, poorly structured configurations can raise red flags during audits; understanding what auditors scrutinize helps avoid preventable issues.





CONFIGURING A SOX-READY PURCHASE ORDER APPROVAL (TEST OF DESIGN - the parts auditors ask for)

The steps below follow a purchase order (PO) scenario because POs hit multiple SOX-sensitive accounts—Commitments, Accruals, and ultimately COGS. Replicate the same pattern for vendor invoices, journal vouchers, or project change orders.

Scenario

  • Every PO must be approved by a Procurement Manager who is not the originator.
  • POs ≥ USD 25 000 receive a second approval from Finance.

Step 1 Enable change management for POs

1.Navigate to Procurement and sourcing > Setup > Procurement and sourcing parameters.

2.On the General tab, activate Enable change management.





3.Set Allow override of settings per vendor to No to prevent policy bypass.



Step 2 Create a new workflow

1.Navigate to Procurement and sourcing > Setup > Procurement and sourcing workflows.

2.Click New > Select Purchase order workflow.



3.Click Run.








4.Workflow editor is loaded.








5.Workflow editor pops-up.















Step 3 Add approval elements

1.In the graphical editor, drag Approve purchase order onto the canvas.



2.Double click on the approval element.


3.Select the sub-approval step and go to step properties.




Step 4 Approval step configuration

Basic settings: Directives for the approver.



Assignment: Approver assignment.

Select participant.


Switch to Role based tab.

Select User group participants in the type of participant.

Select Purchase order approvals in the participant field.



Let's add another approval step ford the Director review & approval.








Basic settings: Directives for the approver director.



Assignment: Approver assignment. Select the director's name here.





Condition: Indicate if this step will be executed under a certain condition.

According to our scenario, order needs to be approved by the director if purchase order's total amount is equal or greater than $25K. 














Save and activate the workflow.

New workflow is ready.










Note that first level approval will be sent to "Purchase order approval" user group. Let's make sure that the user group has the correct users.

Navigate to System administration > Users > User groups



Make sure that approvers are in the correct users.

Another important workflow control is to prevent the submitter from approving the workflow.

Navigate to System administration > Workflow > Workflow parameters.






Note: I will not activate this parameter for the demo purpose.

EXECUTING A SAMPLE PO APPROVAL  TO DEMONSTRATE EVIDENCE (TEST OF EFFECTIVENESS - the parts auditors ask for)

Go to Procurement and sourcing > Purchase orders > All purchase orders and create a new PO.

I've created a purchase order and submitted it to workflow approval.

Click Workflow > Submit

Enter a justification comment.

Workflow approval step 1 has been created.


Log in as Approver user. In the work items assigned to me section, open the record.


 
Let's approve the order by selecting Workflow > Approve.

The next step is to check workflow history to see if there is an action item. Note that there is another approval pending, the director approval due to the total amount is greater than $25K.

Let's approve the order, again. 

Check the workflow history now. Note that the approval workflow is now completed. 

AUDIT NOTE: Retrieving evidence is the most important point here. Take necessary screenshots of workflow history that shows approver user IDs, timestamps, comments and system/workflow version - exportable to excel for auditors.

Note that order status is now Complete.



NOTE: Demonstrate at least two additional edge cases

  • Requester tries to approve own PO—system throws an error and says submitter cannot be approver;
  • Approver misses 1-day SLA—workflow escalates automatically. Details have been explained below.

EXTRA: Workflow Escalation: Ensuring Control Continuity

In a SOX-compliant environment, timeliness of approvals is just as critical as the approval itself. Workflow escalation ensures that if an approver does not take action within a defined time frame, the task is automatically reassigned to another authorized user—typically a control owner. 

In Dynamics 365 Finance, escalation is configured within the workflow step properties:

Navigate to the approval step in the workflow editor and find the related step, open the properties.











Under "Time limits", set a duration (e.g., 1 day).















Go to Escalation tab.















My configuration says:

▶️ If the workflow step is not approved in 1 day, then it will be assigned to user admin,

▶️ If the workflow step is not approved in 4 hours, then it will be assigned to user Dadiyaman,

▶️ If the workflow step is not approved in 2 hours, then it will be automatically Rejected.

This mechanism ensures control continuity, avoids bottlenecks, and demonstrates that the organization has safeguards against delayed approvals—an important consideration during SOX audits.

CONCLUSION

Designing effective approval workflows in Dynamics 365 Finance is not just a matter of system configuration—it is a control activity that directly supports SOX compliance. When implemented with a clear understanding of control objectives, approval workflows can enforce proper authorization, support Segregation of Duties, and generate the audit evidence needed to validate financial governance.

This article demonstrated how to design and execute a SOX-compliant purchase order approval process in D365FO, from activating change management to enforcing dual-level approvals and workflow escalation. Each workflow design choice—such as preventing self-approvals, using value-based conditions, or defining time-bound escalation paths—should be mapped back to a specific control objective in your organization’s risk and control matrix (RCM).

Ultimately, the goal is to move beyond simply routing transactions for approval. A properly designed workflow provides assurance to management and auditors that transactions are reviewed by the appropriate personnel, decisions are logged and traceable, and control breakdowns are systematically prevented. With D365FO’s workflow engine, compliance teams can build these safeguards directly into the business process—creating a strong line of defense against financial misstatements and audit findings.

Understanding Telemetry Pricing for Dynamics 365 Finance & Operations (D365FO)

UNDERSTANDING TELEMETRY PRICING FOR DYNAMICS 365 FINANCE AND OPERATIONS (D365FO) CONTENT Introduction D365FO Telemetry Capabilities Key Pric...