▌READ BEFORE YOUR NEXT TRUE-UP.

Practical guides to D365 F&SC licensing and security analysis

Clear breakdowns of Dynamics 365 Finance & Supply Chain license types, security roles, and compliance risk, written from real audits and real true-ups. No vendor spin. No fluff.

NO FLUFF · REAL AUDIT SCENARIOS · WRITTEN BY A LICENSING EXPERT
✓ Verified against official Microsoft docs Dynamics 365 Licensing Guide → Security Role Reporting FAQ →
in
Follow the Avantiico Insights feed New licensing & security breakdowns, posted as we ship them.
Follow on LinkedIn →

▌Every licensing claim on this site is checked against

01
Dynamics 365 Licensing Guide
Microsoft Corporation · October 2026 edition
The official entitlement, pricing, and use-rights reference for every Dynamics 365 application: SL tiers, Base/Attach rules, security-role-to-license mapping.
Open source document →
02
User Security Role Reporting and Technical Validation for Dynamics 365 Finance and Operations Apps: FAQ
Microsoft Corporation · Updated March 3, 2026
Official FAQ on per-user license validation enforcement, license-exempt service account roles, and security governance reporting tools.
Open source document →
▌TWO LENSES, ONE GOAL

Pick the read that matches your problem

Licensing and security are two different disciplines that both show up on the same D365 F&SC audit. We write for both.

◆

Licensing Analysis

Understand what you're actually entitled to use, and where you're paying for seats nobody needs.

  • User license types: Team Members, Operations, Finance/SCM Premium
  • Attach licensing, device licenses, and multiplexing rules
  • Self-audit steps before Microsoft's compliance team runs theirs
TRUE-UPS SKU MAPPING
Read licensing guides
◈

Security Analysis

Find the access risk hiding in your security role design before an auditor, internal or external, finds it for you.

  • Roles, duties, and privileges: how D365's security model actually works
  • Segregation of duties (SoD) conflicts and how they creep in
  • Remediation patterns that don't break people's day-to-day work
SOD ROLE DESIGN
Read security guides
▌WHICH ONE DO YOU NEED

Licensing review vs. security audit

Different questions, different deliverables. Most clients eventually need both.

Licensing Review Security Audit
Question Are we licensed correctly for how people actually use the system? Can any single person do something they shouldn't be able to do alone?
Best for Finance & procurement, before a true-up or renewal Compliance & internal audit, before SOX or ISO review
What you get SKU-by-user mapping, overbuy/underbuy report, right-sizing plan Conflict matrix, role redesign recommendations, monitoring plan
Typical outcome 25 to 44% reduction in license spend, per our published case studies Closed audit findings, cleaner SOX sign-off
▌02 // — LATEST ARTICLES

Start here

Deep, practical breakdowns, not marketing copy.

2026-10-155 min read01

What Happens to Saved Views When You Redesign Security Roles

Personalizations and saved views are bound to security roles. Redesign the roles without carrying them across and people lose their screens on day one. How to keep the change invisible.

→
2026-10-135 min read02

Ship De-Provisioning as a Sign-Off List First, an Import File Last

Never revoke access until the replacement is proven in. Ship de-provisioning as a signed-off list first and an import file last, so a cost optimization never breaks someone's day.

→
2026-10-116 min read03

Your SoD conflict count is mostly an artifact of the ruleset

Swap the ruleset and a segregation-of-duties conflict count moves from 870 to 353 without any security changing. Inherited rulesets are routinely contaminated. Fix the instrument first.

→
2026-10-096 min read04

A Cost Optimization Can Revoke Access, Not Just Trim It, Through Restrictions You Never Looked At

Restrictions are a second, inverted permission layer. An analysis that ignores read-only denies miscounts access, and a careless redesign can revoke access users needed, not just trim cost.

→
2026-10-085 min read05

The Access Setting That Silently Opens Every Company in Your Group

A user-role assignment with no organization rows grants access to every legal entity. Ship one unscoped assignment in a package and you widen access across the whole company by accident.

→
2026-10-077 min read06

A Security Redesign Shipped Straight to Production, and the Build Never Had a UAT Pass of Its Own

A client deployed a full security-role redesign straight to production without a UAT pass of the shipped build, and the first business day was quiet. Why an additive, evidence-built cutover makes that safe, and what it does and does not prove.

→
2026-10-079 min read07

The Data Collection Is the Real Test, Which Is Why Go-Live Can Take Days Instead of Months

How two Dynamics 365 clients went live on a new security design without a UAT pass of the shipped build, and why the weeks of data collection beforehand are the test that makes a fast, low-risk go-live possible.

→
2026-10-066 min read08

The most powerful role is invisible to your SoD engine

The System Administrator role carries zero rows in the privilege model most analyses are built on, so the most powerful accounts score as the cleanest. A blind spot worth naming.

→
2026-10-046 min read09

Why Your ERP Can Prove Who Opened a Screen but Not Who Posted the Entry: The 89/22/7/0 Rule

Which D365 security grants you can observe from write-evidence is fixed by the platform: about 89% of screens, 22% of outputs, 7% of actions, 0% of in-form controls. A structural constant.

→
2026-10-039 min read10

Microsoft Sets the Price. Your Security Configuration Sets How Many Licenses You Need.

The belief that nothing can be done about a D365 license bill is the most expensive one in the room. Microsoft sets the price and the rules. How many licenses you actually need is a function of your own security configuration, and that is yours to change.

→
2026-10-025 min read11

When Batch Jobs Make the Audit Log Lie

One service account posted 44.6 million rows. When batch and integration accounts dominate an audit trail, per-user signal disappears, and a naive read of the log misleads.

→
2026-10-014 min read12

Licensing Guide Watch: Dynamics 365 Sustainability Joins the Portfolio, but Not Your F&SC Bill, September to October 2026

The October 2026 Dynamics 365 Licensing Guide adds exactly one new product, Dynamics 365 Sustainability, a standalone SaaS with its own tenant and per-user licensing. For a Finance and Supply Chain shop, nothing changes.

→
2026-09-3010 min read13

You Don't Need Telemetry to Know a Role Is Wrong

Grant/deny conflicts, mixed-tier privileges, sysadmin-plus-business-role overlaps: none of it needs usage evidence to catch. Here's why the lightest check we run is worth running after every security change during remediation, not just once at the end.

→
2026-09-305 min read14

D365 Does Not Record Who Posted

The actor behind D365's highest-stakes verbs, posting and approving, is usually not recorded. What that means for audit evidence, and why a license analysis has to account for it.

→
2026-09-294 min read15

Over-Provisioning That Costs Nothing Is Invisible to a Budget

A redesign can hand tens of thousands of permissions to users who do not need them, and a dollar-based budget sees none of it, because access that costs nothing is invisible to cost.

→
2026-09-276 min read16

How Much of Your Quoted Saving Is Actually Bankable

A modeled saving of $171,552 looked real until you asked how much hits the next invoice. The answer was near zero until revocation ships. The one question to ask of any quote.

→
2026-09-2611 min read17

Every Batch, Diffed Against a Target That Already Moved

A client chose to deliver their security redesign in batches, a completely reasonable call for a business that can't pause. Here's what that decision actually costs on our side, batch after batch, and why it isn't anyone's fault.

→
2026-09-255 min read18

Adding the Missing Usage Data Raised the Cost, and That Was the Honest Number

Restoring missing usage data raised the modeled cost from $1.83M to $2.21M. The honest number went up, not down. Why more evidence can make a design look worse, and why that is right.

→
2026-09-235 min read19

A Quoted Saving Is Not Bankable Until the Package Ships What It Modeled

A saving you cannot bank until the package actually ships it. On one estate the designed cost sat 61.5% below the shipped cost, and the shipped saving was zero.

→
2026-09-2210 min read20

The Client's Priorities Flipped Mid-Engagement. We Still Found 5 More Points of Savings.

Cost came first, then it came third, out of a legitimate concern about revoking access without proof of use. Remediation exists to cut a real bill, so we adapted our strategy to keep finding savings compatible with the new order.

→
2026-09-217 min read21

"This Role Should Be Cheaper If People Worked Differently"

Modeling a client's per-role license intent and the process change behind it: find the driver, re-route to a cheaper entry point or drop it, then confirm the tier actually fell.

→
2026-09-198 min read22

When a Client Says "We Don't Run Commerce, Take It Off Our Bill"

'We don't run Commerce, take it off our bill' is surgery, not a toggle. The pros, the cons, the ties and service operations that trip it up, and governing intent so drift cannot undo it.

→
2026-09-189 min read23

Three Ways to Treat Access With No Usage Evidence, and Why the Generous One Isn't Free

Some organizations want the leanest defensible design. Others want to change nothing that isn't costing them money. We built a dial for it, and caught a real mistake in our own modeling before shipping it.

→
2026-09-176 min read24

The Bug Fix That Would Have Cut Off Users

Pricing a bug correctly nearly removed access hundreds of users needed. Why an evidence-based engine must credit service-operation cost without letting it condemn a privilege.

→
2026-09-167 min read25

The Same Project Case Costs a Full License Through One Door and Team Members Through Another

The same project case needs a premium Project Operations license through one door and only Team Members through another. The license is a property of the door, not the destination.

→
2026-09-1513 min read26

We Tested Every Setting in Our Role-Redesign Engine. Only One of Them Moves the Price.

Most tuning decisions turned out not to matter at all. One did, tested across two structurally different clients, and it behaves in opposite directions depending on the client's shape.

→
2026-09-147 min read27

The Securables Your License Tool Can't See: D365 Service Operations

D365 charges real licenses for service operations, the endpoints integrations call. Most license tooling prices them as free, so a whole category of paid access is invisible.

→
2026-09-139 min read28

Almost No Telemetry, Still a Defensible Number: A Small D365 Environment's Redesign

Our evidence model leans on telemetry and audit-log evidence together. This environment had almost no usable telemetry at all. Here's what the redesign looked like on one evidence source instead of two.

→
2026-09-125 min read29

Pricing the "Before" Seat From the Union of Every Option Invents Savings That Were Never There

Pricing the 'before' seat from the union of every license option a user could reach invents savings that were never there. Price one population, both sides, as a minimum-cost cover.

→
2026-09-1110 min read30

The Client Chose Manageable Over Optimal. Here's the Number They Actually Paid For It.

Our cheapest role-mining design still produced 760 roles. The client asked for as few roles as possible, and told us upfront they'd pay more for it.

→
2026-09-105 min read31

There Are Two Different Savings Numbers, and Mixing Them Inflates the Headline

A vs-compliance baseline and a like-for-like baseline answer different questions and produce very different savings. Mixing them inflates the headline. Name your baseline.

→
2026-09-0810 min read32

We Built the Role-Mining Rebuild the Client Asked For. The First Draft Cost More Than Doing Nothing.

A client rejected a 100-role fix and asked us to mine roles from real usage instead. Our first attempt would have cost more per month than doing nothing.

→
2026-09-086 min read33

Five Privileges Are Your Entire D365 Bill

On one estate, five privileges pinned 110 of 127 top-tier seats. License cost is Pareto-distributed, so targeted remediation beats a boil-the-ocean role project.

→
2026-09-076 min read34

"Just Make It Read-Only" Saves Nothing About Three Times Out of Four

Only about a quarter of D365 menu items cost less read-only, and a handful of privileges drive most expensive seats. Why 'just make it read-only' rarely lowers the bill.

→
2026-09-057 min read35

More Than Half of Your D365 "Users" Do Not Need a Paid Seat

On one estate the user list held about 2,180 accounts but barely 955 were real people. Counting service and system accounts as seats inflates both the bill and the savings claim.

→
2026-09-049 min read36

The Posting Button Has No Camera: Extending Observability to the Privileges Audit-Blind by Design

Roughly half of all menu-item privileges can't be directly observed by any audit trail. Here's the careful, layered process for closing part of that gap.

→
2026-09-036 min read37

A role cannot have a license

D365 bills per user over the union of their roles, resolved as a minimum-cost set cover. Pricing per role double-counts and invents savings. The conceptual spine of license analysis.

→
2026-09-0210 min read38

From Disposition to Design: How Keep/Downgrade/Drop Verdicts Become an Actual Role Model

A disposition table says what to keep, downgrade, or drop. It doesn't say what roles to build. Here's the separate step, and the trade-off it can't avoid.

→
2026-09-015 min read39

Licensing Guide Watch: Headless Commerce Goes GA, and This Time It Touches F&SC, August to September 2026

The September 2026 guide's only new entry is Headless Commerce reaching GA. Unlike the last two editions, this one is documented to integrate directly with Finance and Supply Chain Management.

→
2026-09-018 min read40

How Dynamics 365 Actually Bills You: A Plain-English Primer

Microsoft bills per user, not per role, over everything their roles can do. A plain-English primer on D365 F&SC license tiers and the vocabulary every analysis assumes.

→
2026-08-308 min read41

106 Questions Before Anyone Touches a Role: What a Real D365 Licensing Analysis Checks First

Most reviews start with a user list and a role count, about ten questions. A properly scoped intake runs to 106. Here's what falls in the gap.

→
2026-08-249 min read42

Inside an Evidence-Based Disposition: Why "No Usage Data" Isn't "Not Needed"

A privilege with no recorded activity isn't automatically safe to remove. Why observability has to be verified before silence can be treated as an answer.

→
2026-08-188 min read43

How We Decide What Stays, What Goes Read-Only, and What Goes Away

Every privilege in a D365 role lands on one of five outcomes. Here's the evidence model behind that decision, and the one rule that keeps it safe to act on.

→
2026-08-127 min read44

The Evidence-First Framework: Three Stages, One Defensible License Number

Every article on this site traces back to the same three-stage method. This piece is the map, linking to the articles that go deep on each stage.

→
2026-08-1111 min read45

We Gave a Client Three Numbers, Not One: $260K, $180K, or $90K a Month

The security model wasn't the biggest driver of this estate's license bill. The way one integration authenticated was.

→
2026-08-0913 min read46

The Fast Path to License-Analysis Data Collection: Just-in-Time Access and One Script

Instead of two hours of manual UI exports, get just-in-time database access to a Tier 2 sandbox and run one script that pulls all 33 datasets, license, security, personalization, and audit-log evidence, unattended.

→
2026-08-086 min read47

Four Real D365 License Analyses, Including the One Where the Client Said No

Four published engagements with real before-and-after numbers, including the one where our own recommendation got turned down, and why we publish that one too.

→
2026-08-0414 min read48

What We Actually Collect for a D365 License Analysis, and Why Each Piece Matters

Ten datasets, each answering one specific question, joined together into a single defensible license number.

→
2026-08-034 min read49

Licensing Guide Watch: Two New Agents, Both Customer Insights, July to August 2026

The August 2026 Dynamics 365 Licensing Guide grew from 89 to 90 pages. Two new Change Log entries, both Customer Insights agents, neither touches Finance or Supply Chain Management.

→
2026-08-024 min read50

Quick Reference: The D365 F&SC Roles That Never Require a License

A working list of the device, integration, and background-operation roles that carry no license requirement on their own.

→
2026-08-018 min read51

What Telemetry Can and Can't Tell You About D365 License Optimization

Telemetry is one of the strongest inputs in a license review, and also one of the easiest to misuse.

→
2026-07-305 min read52

If Your D365 Renewal Is in the Next 90 Days, Your License Analysis Should Already Be Underway

Microsoft's per-user validation is tied to each tenant's own renewal date. What actually needs to happen before that date, not after the notice arrives.

→
2026-07-299 min read53

The Roles Doing Too Much: Finding Your Most Expensive D365 Access Before You Touch a License

A role name rarely tells you why it's expensive. The entry points inside it do.

→
2026-07-278 min read54

The First Hour of a Real D365 Licensing Review Isn't About Roles

Most licensing reviews start with a user export and a few disabled accounts. That feels productive and rarely gives you a trustworthy number.

→
2026-07-2410 min read55

Five Ways a “Standard” D365 Security Role Quietly Inflates Your License Bill

Clients assume Microsoft-delivered roles are untouched and safe to trust. Five real patterns show how a quietly customized role drives cost.

→
2026-07-2010 min read56

From Privilege to User: How One Extra Access Right Triggers an Attached License

License requirements aren't decided at the role level. They're decided at the user level, across every role that user holds.

→
2026-07-184 min read57

A Discount and an Optimization Are Two Different Savings. Most Companies Only Ever Claim One.

Negotiating a Microsoft discount lowers price per license. It doesn't touch how many you actually need. Two real engagements show what the second lever is worth.

→
2026-07-169 min read58

How D365 License Requirements Roll Up From a Single Entry Point

A privilege tied to five expensive workloads doesn't need the priciest one. It needs whatever license every entry point actually shares.

→
2026-07-159 min read59

Thirty Roles. A Thousand Conflicts. One Day Before UAT.

A mentoring engagement on a greenfield D365 F&SC implementation found over a thousand segregation-of-duties conflicts in thirty roles, a day before user acceptance testing. What doing security right the first time actually looks like.

→
2026-07-1412 min read60

We Rebuilt a Client's D365 Security Model in 90 Minutes. The Hard Part Was Everything Else.

Our first fully automated D365 F&SC security migration: an XML import replaced weeks of manual role-building. What that automation actually required, and the framework we had to build around it.

→
2026-07-1411 min read61

We Cut a Client's D365 License Bill by 44%. They Turned It Down.

The mathematically optimal security model saved $32,000 a month. The client rejected it as unmaintainable, and was right to. Why, and how we rebuilt our methodology because of it.

→
2026-07-1410 min read62

A 35% License Savings in a D365 Estate With Nothing Obvious to Cut

A European estate with genuinely well-built security still carried $40,000 a month in avoidable license cost. What a clean configuration hides, and how we found it anyway.

→
2026-07-139 min read63

Avoiding Overlicensing, Part 3: Finding Exactly What's Driving a Role's Extra Licenses

A four-export, two-formula method for finding exactly which permissions drive each license on a role that requires three or more, plus a free downloadable workbook.

→
2026-07-1210 min read64

D365 F&SC Telemetry Setup: 15 Minutes to Configure, Likely Free to Run

The exact Azure and F&SC configuration steps, what it costs against the free tier, and the two KQL scripts that turn telemetry into a license and user-activity report.

→
2026-07-127 min read65

Avoiding Overlicensing, Part 1: Why "Inactive User" Isn't as Simple as Last Login

Identifying inactive users saves the most of any overlicensing strategy, but the built-in report alone misreads integration users. The two-source method and two exceptions that keep it accurate.

→
2026-07-128 min read66

Avoiding Overlicensing, Part 2: Two Security Configuration Mistakes That Quietly Bump License Tiers

Contradictory Deny/Grant on the same entry point, and Correct or Invoke permissions granted without their prerequisites. Both pass an access review clean and still inflate license tiers.

→
2026-07-1111 min read67

D365 F&SC Licensing 101: User Types, SLs, and Where the Money Leaks

Team Members, Operations, Finance/SCM, and Premium: what each SL actually entitles you to, official pricing, and the five overbuying mistakes we see in almost every tenant.

→
2026-07-1111 min read68

Segregation of Duties in D365 F&SC: Finding Conflicts Before Your Auditor Does

How roles, duties, and privileges actually stack up, the conflict pairs that show up most often, and a walkthrough of running your own SoD analysis.

→
2026-07-118 min read69

Microsoft's Mandatory Per-User License Validation: What Changes and How to Prepare

Starting on each tenant's contract anniversary or renewal date, unlicensed users lose access. The T-90/T-30/T+15 timeline and the four-step prep checklist.

→
Coming soonIN PROGRESS

Does Copilot Change Your D365 Licensing? A Practical Breakdown

Where embedded Copilot features are included in existing SLs, and where they quietly require add-on licensing.

▌03 // — HOW WE WORK

Five stages, two phases

We loop back on gaps in the data and on findings that change the picture, before anything ships to production.

Planning
Set the strategy
→
Analysis
Collect & assess
→
Design
Reports & sign-off
→
Remediation
Build the new model
→
Implementation
UAT, go-live & support
Read the full breakdown →
▌GUIDE WATCH — RUNNING SERIES

We diff the Licensing Guide every month, so you don't have to

Microsoft revises the Dynamics 365 Licensing Guide monthly and logs changes in its own Appendix K. We started tracking it edition to edition from May 2026. Here's the trail so far.

2026-10-014 min read01

September → October 2026: Dynamics 365 Sustainability Joins the Portfolio, Not Your F&SC Bill

The guide grew from 90 to 95 pages. One new entry: Dynamics 365 Sustainability, a standalone SaaS with its own tenant license and per-user USL. It names no Finance or Supply Chain integration, so nothing about an F&SC estate changes.

→
2026-09-015 min read02

August → September 2026: Headless Commerce Goes GA, and This Time It Touches F&SC

The guide's only new entry is Headless Commerce reaching General Availability, and unlike the last two editions, this one is documented to integrate directly with Finance and Supply Chain Management.

→
2026-08-034 min read03

July → August 2026: Two New Agents, Both Customer Insights

The guide grew from 89 to 90 pages. Two new Change Log entries, both Customer Insights agents in Paid Public Preview, neither touching Finance or Supply Chain Management.

→
2026-07-034 min read04

June → July 2026: A Quiet Month

Zero new Change Log entries. The one real change: Copilot Credits documentation consolidated into its own standalone guide. Everything else is copyediting.

→
2026-06-036 min read05

May → June 2026: Microsoft Adds Official Pricing Tables to the Guide

72 pages became 89. Every major application section gained a real Entitlements table with list pricing, plus three new agents across Sales, Business Central, and Contact Center.

→
2026-05-065 min read06

April → May 2026: Procurement Agent Replaces Supplier Communications Agent

One new agent, a Contact Center metering change from flat messages to Copilot Credits, and a cleanup of the "how to buy" language. 72 pages, unchanged.

→
▌04 // — PLAYBOOKS & CHEAT SHEETS

Bookmark-worthy references

Shorter, scannable companions to the full articles.

▌05 // — WHO THIS IS FOR

Written for the people who own the risk

If one of these is your job title, this blog is for you.

📊

IT Asset Managers

Own the license spend and need to defend it at renewal.

🛡️

SOX & Compliance Teams

Need a clean SoD story before the audit committee meets.

⚙️

D365 System Admins

Design security roles and get blamed when they're wrong.

💼

Finance & IT Leaders

Sign the Microsoft contract and want fewer surprises.

▌06 // — QUESTIONS FIRST

Frequently asked

Straight answers, no "it depends" unless it genuinely depends.

Is a licensing self-audit legally binding?

No. A self-audit is a planning exercise. It doesn't replace Microsoft's own True-Up or Software Asset Management review, but it tells you what that review is likely to find, while you still have time to fix it.

How often should we run a SoD review?

At minimum annually, and after any significant role redesign, acquisition, or org restructuring. Conflicts creep back in quietly as people change teams and roles get copied.

What's the difference between attach and subscription licensing?

Attach licensing lets you add F&SC at a discounted rate on top of an existing qualifying Dynamics subscription. Standalone subscription licensing has no such prerequisite, but costs more per seat. Which one applies changes your effective cost per user significantly.

Can I mix Team Members and Operations licenses in the same tenant?

Yes, and most tenants should. Mixing is exactly how you avoid overbuying. The mistake is assigning Operations-tier licenses to users who only need Team Member-level access.

Do Copilot / AI features change my licensing?

Some Copilot capabilities are included in existing F&SC SLs; others are metered add-ons. We cover the current breakdown in an upcoming article. The split has shifted more than once, so treat any answer as a snapshot in time.

How do I prepare for a Microsoft compliance audit?

Reconcile your assigned licenses against actual usage before Microsoft does, document your reasoning for edge cases, and fix the obvious overassignments early. Walking in with your own numbers changes the conversation.

▌07 // — ABOUT

Who's behind this

Avantiico is a Microsoft Solutions Partner and consulting firm focused on Dynamics 365, with over 80 years of combined ERP experience across the team and 400,000+ hours specifically in D365 Finance & Supply Chain Management. This site is written by the people who actually run these licensing and security engagements, not a marketing team summarizing them secondhand.

ML

Morten Logstrup

D365 Licensing & Database Expert

Morten works alongside Avantiico's licensing team on D365 Finance & Supply Chain engagements, drawing on years of Microsoft partner and customer-engagement experience to keep technical findings tied to real business outcomes.

SA

Sebastian Andersen

Licensing & Database Associate

Sebastian supports Avantiico's licensing and database practice, helping turn raw D365 data exports into the analysis this site's articles are built from.

TS

Tatiana Subbotin

D365 Licensing & Database Technical Lead

Tatiana works with D365 Finance & Supply Chain customers on licensing optimization and security role design, turning audit findings into fixes that don't disrupt day-to-day operations. Everything published here comes from real client engagements, generalized and anonymized.

Not sure where your license risk is hiding?

A short conversation usually tells us whether it's a licensing problem, a security problem, or both. Let's find out before your auditor does.