Evidence-Based Analysis

Source-cited breakdowns, verified against official Microsoft documentation. No vendor spin.

2026-10-155 min read01

What Happens to Saved Views When You Redesign Security Roles

Personalizations and saved views are bound to security roles. Redesign the roles without carrying them across and people lose their screens on day one. How to keep the change invisible.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-135 min read02

Ship De-Provisioning as a Sign-Off List First, an Import File Last

Never revoke access until the replacement is proven in. Ship de-provisioning as a signed-off list first and an import file last, so a cost optimization never breaks someone's day.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-116 min read03

Your SoD conflict count is mostly an artifact of the ruleset

Swap the ruleset and a segregation-of-duties conflict count moves from 870 to 353 without any security changing. Inherited rulesets are routinely contaminated. Fix the instrument first.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-096 min read04

A Cost Optimization Can Revoke Access, Not Just Trim It, Through Restrictions You Never Looked At

Restrictions are a second, inverted permission layer. An analysis that ignores read-only denies miscounts access, and a careless redesign can revoke access users needed, not just trim cost.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-085 min read05

The Access Setting That Silently Opens Every Company in Your Group

A user-role assignment with no organization rows grants access to every legal entity. Ship one unscoped assignment in a package and you widen access across the whole company by accident.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-066 min read06

The most powerful role is invisible to your SoD engine

The System Administrator role carries zero rows in the privilege model most analyses are built on, so the most powerful accounts score as the cleanest. A blind spot worth naming.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-046 min read07

Why Your ERP Can Prove Who Opened a Screen but Not Who Posted the Entry: The 89/22/7/0 Rule

Which D365 security grants you can observe from write-evidence is fixed by the platform: about 89% of screens, 22% of outputs, 7% of actions, 0% of in-form controls. A structural constant.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-039 min read08

Microsoft Sets the Price. Your Security Configuration Sets How Many Licenses You Need.

The belief that nothing can be done about a D365 license bill is the most expensive one in the room. Microsoft sets the price and the rules. How many licenses you actually need is a function of your own security configuration, and that is yours to change.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-10-025 min read09

When Batch Jobs Make the Audit Log Lie

One service account posted 44.6 million rows. When batch and integration accounts dominate an audit trail, per-user signal disappears, and a naive read of the log misleads.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-305 min read10

D365 Does Not Record Who Posted

The actor behind D365's highest-stakes verbs, posting and approving, is usually not recorded. What that means for audit evidence, and why a license analysis has to account for it.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-294 min read11

Over-Provisioning That Costs Nothing Is Invisible to a Budget

A redesign can hand tens of thousands of permissions to users who do not need them, and a dollar-based budget sees none of it, because access that costs nothing is invisible to cost.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-276 min read12

How Much of Your Quoted Saving Is Actually Bankable

A modeled saving of $171,552 looked real until you asked how much hits the next invoice. The answer was near zero until revocation ships. The one question to ask of any quote.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-255 min read13

Adding the Missing Usage Data Raised the Cost, and That Was the Honest Number

Restoring missing usage data raised the modeled cost from $1.83M to $2.21M. The honest number went up, not down. Why more evidence can make a design look worse, and why that is right.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-235 min read14

A Quoted Saving Is Not Bankable Until the Package Ships What It Modeled

A saving you cannot bank until the package actually ships it. On one estate the designed cost sat 61.5% below the shipped cost, and the shipped saving was zero.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-217 min read15

"This Role Should Be Cheaper If People Worked Differently"

Modeling a client's per-role license intent and the process change behind it: find the driver, re-route to a cheaper entry point or drop it, then confirm the tier actually fell.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-198 min read16

When a Client Says "We Don't Run Commerce, Take It Off Our Bill"

'We don't run Commerce, take it off our bill' is surgery, not a toggle. The pros, the cons, the ties and service operations that trip it up, and governing intent so drift cannot undo it.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-189 min read17

Three Ways to Treat Access With No Usage Evidence, and Why the Generous One Isn't Free

Some organizations want the leanest defensible design. Others want to change nothing that isn't costing them money. We built a dial for it, and caught a real mistake in our own modeling before shipping it.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-176 min read18

The Bug Fix That Would Have Cut Off Users

Pricing a bug correctly nearly removed access hundreds of users needed. Why an evidence-based engine must credit service-operation cost without letting it condemn a privilege.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-167 min read19

The Same Project Case Costs a Full License Through One Door and Team Members Through Another

The same project case needs a premium Project Operations license through one door and only Team Members through another. The license is a property of the door, not the destination.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-1513 min read20

We Tested Every Setting in Our Role-Redesign Engine. Only One of Them Moves the Price.

Most tuning decisions turned out not to matter at all. One did, tested across two structurally different clients, and it behaves in opposite directions depending on the client's shape.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-147 min read21

The Securables Your License Tool Can't See: D365 Service Operations

D365 charges real licenses for service operations, the endpoints integrations call. Most license tooling prices them as free, so a whole category of paid access is invisible.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-125 min read22

Pricing the "Before" Seat From the Union of Every Option Invents Savings That Were Never There

Pricing the 'before' seat from the union of every license option a user could reach invents savings that were never there. Price one population, both sides, as a minimum-cost cover.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-105 min read23

There Are Two Different Savings Numbers, and Mixing Them Inflates the Headline

A vs-compliance baseline and a like-for-like baseline answer different questions and produce very different savings. Mixing them inflates the headline. Name your baseline.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-086 min read24

Five Privileges Are Your Entire D365 Bill

On one estate, five privileges pinned 110 of 127 top-tier seats. License cost is Pareto-distributed, so targeted remediation beats a boil-the-ocean role project.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-076 min read25

"Just Make It Read-Only" Saves Nothing About Three Times Out of Four

Only about a quarter of D365 menu items cost less read-only, and a handful of privileges drive most expensive seats. Why 'just make it read-only' rarely lowers the bill.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-057 min read26

More Than Half of Your D365 "Users" Do Not Need a Paid Seat

On one estate the user list held about 2,180 accounts but barely 955 were real people. Counting service and system accounts as seats inflates both the bill and the savings claim.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-049 min read27

The Posting Button Has No Camera: Extending Observability to the Privileges Audit-Blind by Design

Roughly half of all menu-item privileges can't be directly observed by any audit trail. Here's the careful, layered process for closing part of that gap.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-036 min read28

A role cannot have a license

D365 bills per user over the union of their roles, resolved as a minimum-cost set cover. Pricing per role double-counts and invents savings. The conceptual spine of license analysis.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-09-0210 min read29

From Disposition to Design: How Keep/Downgrade/Drop Verdicts Become an Actual Role Model

A disposition table says what to keep, downgrade, or drop. It doesn't say what roles to build. Here's the separate step, and the trade-off it can't avoid.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-018 min read30

How Dynamics 365 Actually Bills You: A Plain-English Primer

Microsoft bills per user, not per role, over everything their roles can do. A plain-English primer on D365 F&SC license tiers and the vocabulary every analysis assumes.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-08-249 min read31

Inside an Evidence-Based Disposition: Why "No Usage Data" Isn't "Not Needed"

A privilege with no recorded activity isn't automatically safe to remove. Why observability has to be verified before silence can be treated as an answer.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-188 min read32

How We Decide What Stays, What Goes Read-Only, and What Goes Away

Every privilege in a D365 role lands on one of five outcomes. Here's the evidence model behind that decision, and the one rule that keeps it safe to act on.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-127 min read33

The Evidence-First Framework: Three Stages, One Defensible License Number

Every article on this site traces back to the same three-stage method. This piece is the map, linking to the articles that go deep on each stage.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-049 min read34

What We Actually Collect for a D365 License Analysis, and Why Each Piece Matters

Ten datasets, each answering one specific question, joined together into a single defensible license number.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-07-2410 min read35

Five Ways a “Standard” D365 Security Role Quietly Inflates Your License Bill

Clients assume Microsoft-delivered roles are untouched and safe to trust. Five real patterns show how a quietly customized role drives cost.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-07-2010 min read36

From Privilege to User: How One Extra Access Right Triggers an Attached License

License requirements aren't decided at the role level. They're decided at the user level, across every role that user holds.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-07-184 min read37

A Discount and an Optimization Are Two Different Savings. Most Companies Only Ever Claim One.

Negotiating a Microsoft discount lowers price per license. It doesn't touch how many you actually need. Two real engagements show what the second lever is worth.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-07-169 min read38

How D365 License Requirements Roll Up From a Single Entry Point

A privilege tied to five expensive workloads doesn't need the priciest one. It needs whatever license every entry point actually shares.

EVIDENCE-BASED ANALYSISLICENSING
→
2026-07-1111 min read39

D365 F&SC Licensing 101: User Types, SLs, and Where the Money Leaks

A plain-English breakdown of Dynamics 365 Finance & Supply Chain license types (Team Members, Operations, Premium) and the five overbuying mistakes we see most often.

EVIDENCE-BASED ANALYSISLICENSING
→