Security

Roles, duties, privileges, and the segregation-of-duties conflicts auditors check first.

2026-10-155 min read01

What Happens to Saved Views When You Redesign Security Roles

Personalizations and saved views are bound to security roles. Redesign the roles without carrying them across and people lose their screens on day one. How to keep the change invisible.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-135 min read02

Ship De-Provisioning as a Sign-Off List First, an Import File Last

Never revoke access until the replacement is proven in. Ship de-provisioning as a signed-off list first and an import file last, so a cost optimization never breaks someone's day.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-116 min read03

Your SoD conflict count is mostly an artifact of the ruleset

Swap the ruleset and a segregation-of-duties conflict count moves from 870 to 353 without any security changing. Inherited rulesets are routinely contaminated. Fix the instrument first.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-096 min read04

A Cost Optimization Can Revoke Access, Not Just Trim It, Through Restrictions You Never Looked At

Restrictions are a second, inverted permission layer. An analysis that ignores read-only denies miscounts access, and a careless redesign can revoke access users needed, not just trim cost.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-085 min read05

The Access Setting That Silently Opens Every Company in Your Group

A user-role assignment with no organization rows grants access to every legal entity. Ship one unscoped assignment in a package and you widen access across the whole company by accident.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-077 min read06

A Security Redesign Shipped Straight to Production, and the Build Never Had a UAT Pass of Its Own

A client deployed a full security-role redesign straight to production without a UAT pass of the shipped build, and the first business day was quiet. Why an additive, evidence-built cutover makes that safe, and what it does and does not prove.

CASE STUDYSECURITY
→
2026-10-079 min read07

The Data Collection Is the Real Test, Which Is Why Go-Live Can Take Days Instead of Months

How two Dynamics 365 clients went live on a new security design without a UAT pass of the shipped build, and why the weeks of data collection beforehand are the test that makes a fast, low-risk go-live possible.

CASE STUDYSECURITY
→
2026-10-066 min read08

The most powerful role is invisible to your SoD engine

The System Administrator role carries zero rows in the privilege model most analyses are built on, so the most powerful accounts score as the cleanest. A blind spot worth naming.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-046 min read09

Why Your ERP Can Prove Who Opened a Screen but Not Who Posted the Entry: The 89/22/7/0 Rule

Which D365 security grants you can observe from write-evidence is fixed by the platform: about 89% of screens, 22% of outputs, 7% of actions, 0% of in-form controls. A structural constant.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-10-025 min read10

When Batch Jobs Make the Audit Log Lie

One service account posted 44.6 million rows. When batch and integration accounts dominate an audit trail, per-user signal disappears, and a naive read of the log misleads.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-3010 min read11

You Don't Need Telemetry to Know a Role Is Wrong

Grant/deny conflicts, mixed-tier privileges, sysadmin-plus-business-role overlaps: none of it needs usage evidence to catch. Here's why the lightest check we run is worth running after every security change during remediation, not just once at the end.

HOW TOLICENSINGSECURITY
→
2026-09-305 min read12

D365 Does Not Record Who Posted

The actor behind D365's highest-stakes verbs, posting and approving, is usually not recorded. What that means for audit evidence, and why a license analysis has to account for it.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-294 min read13

Over-Provisioning That Costs Nothing Is Invisible to a Budget

A redesign can hand tens of thousands of permissions to users who do not need them, and a dollar-based budget sees none of it, because access that costs nothing is invisible to cost.

EVIDENCE-BASED ANALYSISSECURITY
→
2026-09-2611 min read14

Every Batch, Diffed Against a Target That Already Moved

A client chose to deliver their security redesign in batches, a completely reasonable call for a business that can't pause. Here's what that decision actually costs on our side, batch after batch, and why it isn't anyone's fault.

CASE STUDYLICENSINGSECURITY
→
2026-09-2210 min read15

The Client's Priorities Flipped Mid-Engagement. We Still Found 5 More Points of Savings.

Cost came first, then it came third, out of a legitimate concern about revoking access without proof of use. Remediation exists to cut a real bill, so we adapted our strategy to keep finding savings compatible with the new order.

CASE STUDYLICENSINGSECURITY
→
2026-09-189 min read16

Three Ways to Treat Access With No Usage Evidence, and Why the Generous One Isn't Free

Some organizations want the leanest defensible design. Others want to change nothing that isn't costing them money. We built a dial for it, and caught a real mistake in our own modeling before shipping it.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-1513 min read17

We Tested Every Setting in Our Role-Redesign Engine. Only One of Them Moves the Price.

Most tuning decisions turned out not to matter at all. One did, tested across two structurally different clients, and it behaves in opposite directions depending on the client's shape.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-139 min read18

Almost No Telemetry, Still a Defensible Number: A Small D365 Environment's Redesign

Our evidence model leans on telemetry and audit-log evidence together. This environment had almost no usable telemetry at all. Here's what the redesign looked like on one evidence source instead of two.

CASE STUDYLICENSINGSECURITY
→
2026-09-1110 min read19

The Client Chose Manageable Over Optimal. Here's the Number They Actually Paid For It.

Our cheapest role-mining design still produced 760 roles. The client asked for as few roles as possible, and told us upfront they'd pay more for it.

CASE STUDYLICENSINGSECURITY
→
2026-09-0810 min read20

We Built the Role-Mining Rebuild the Client Asked For. The First Draft Cost More Than Doing Nothing.

A client rejected a 100-role fix and asked us to mine roles from real usage instead. Our first attempt would have cost more per month than doing nothing.

CASE STUDYLICENSINGSECURITY
→
2026-09-049 min read21

The Posting Button Has No Camera: Extending Observability to the Privileges Audit-Blind by Design

Roughly half of all menu-item privileges can't be directly observed by any audit trail. Here's the careful, layered process for closing part of that gap.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-09-0210 min read22

From Disposition to Design: How Keep/Downgrade/Drop Verdicts Become an Actual Role Model

A disposition table says what to keep, downgrade, or drop. It doesn't say what roles to build. Here's the separate step, and the trade-off it can't avoid.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-308 min read23

106 Questions Before Anyone Touches a Role: What a Real D365 Licensing Analysis Checks First

Most reviews start with a user list and a role count, about ten questions. A properly scoped intake runs to 106. Here's what falls in the gap.

HOW TOLICENSINGSECURITY
→
2026-08-249 min read24

Inside an Evidence-Based Disposition: Why "No Usage Data" Isn't "Not Needed"

A privilege with no recorded activity isn't automatically safe to remove. Why observability has to be verified before silence can be treated as an answer.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-188 min read25

How We Decide What Stays, What Goes Read-Only, and What Goes Away

Every privilege in a D365 role lands on one of five outcomes. Here's the evidence model behind that decision, and the one rule that keeps it safe to act on.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-127 min read26

The Evidence-First Framework: Three Stages, One Defensible License Number

Every article on this site traces back to the same three-stage method. This piece is the map, linking to the articles that go deep on each stage.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-08-1111 min read27

We Gave a Client Three Numbers, Not One: $260K, $180K, or $90K a Month

The security model wasn't the biggest driver of this estate's license bill. The way one integration authenticated was.

CASE STUDYLICENSINGSECURITY
→
2026-08-0913 min read28

The Fast Path to License-Analysis Data Collection: Just-in-Time Access and One Script

Instead of two hours of manual UI exports, get just-in-time database access to a Tier 2 sandbox and run one script that pulls all 33 datasets, license, security, personalization, and audit-log evidence, unattended.

HOW TOLICENSINGSECURITY
→
2026-08-086 min read29

Four Real D365 License Analyses, Including the One Where the Client Said No

Four published engagements with real before-and-after numbers, including the one where our own recommendation got turned down, and why we publish that one too.

CASE STUDYLICENSINGSECURITY
→
2026-08-0414 min read30

What We Actually Collect for a D365 License Analysis, and Why Each Piece Matters

Ten datasets, each answering one specific question, joined together into a single defensible license number.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-07-299 min read31

The Roles Doing Too Much: Finding Your Most Expensive D365 Access Before You Touch a License

A role name rarely tells you why it's expensive. The entry points inside it do.

HOW TOLICENSINGSECURITY
→
2026-07-2410 min read32

Five Ways a “Standard” D365 Security Role Quietly Inflates Your License Bill

Clients assume Microsoft-delivered roles are untouched and safe to trust. Five real patterns show how a quietly customized role drives cost.

EVIDENCE-BASED ANALYSISLICENSINGSECURITY
→
2026-07-159 min read33

Thirty Roles. A Thousand Conflicts. One Day Before UAT.

A mentoring engagement on a greenfield D365 F&SC implementation found over a thousand segregation-of-duties conflicts in thirty roles, a day before user acceptance testing. What doing security right the first time actually looks like.

CASE STUDYSECURITY
→
2026-07-1412 min read34

We Rebuilt a Client's D365 Security Model in 90 Minutes. The Hard Part Was Everything Else.

Our first fully automated D365 F&SC security migration: an XML import replaced weeks of manual role-building. What that automation actually required, and the framework we had to build around it.

CASE STUDYLICENSING
→
2026-07-1411 min read35

We Cut a Client's D365 License Bill by 44%. They Turned It Down.

The mathematically optimal security model saved $32,000 a month. The client rejected it as unmaintainable, and was right to. Why, and how we rebuilt our methodology because of it.

CASE STUDYLICENSING
→
2026-07-1410 min read36

A 35% License Savings in a D365 Estate With Nothing Obvious to Cut

A European estate with genuinely well-built security still carried $40,000 a month in avoidable license cost. What a clean configuration hides, and how we found it anyway.

CASE STUDYLICENSING
→
2026-07-139 min read37

Avoiding Overlicensing, Part 3: Finding Exactly What's Driving a Role's Extra Licenses

A four-export, two-formula method for finding exactly which permissions drive each license on a role that requires three or more, plus a free downloadable workbook.

HOW TOLICENSING
→
2026-07-128 min read38

Avoiding Overlicensing, Part 2: Two Security Configuration Mistakes That Quietly Bump License Tiers

Contradictory Deny/Grant on the same entry point, and Correct or Invoke permissions granted without their prerequisites. Both pass an access review clean and still inflate license tiers.

HOW TOLICENSING
→
2026-07-1111 min read39

Segregation of Duties in D365 F&SC: Finding Conflicts Before Your Auditor Does

How D365 F&SC's role/duty/privilege security model works, the SoD conflict pairs that show up most often, and a walkthrough of running your own analysis.

HOW TOSECURITY
→