Most Business Central security problems aren’t about misuse—they’re about access that should never have been granted. This post explains how Finance must design permission sets, enforce segregation of duties, and own the quarterly access review—not IT.
How D365 F&O’s security model is structured — roles, duties, privileges, and permissions — the segregation of duties conflicts auditors require Finance to resolve, Extensible Data Security (XDS) for financial dimension and legal entity access control, the user security review that should happen quarterly but usually doesn’t, and why Finance must own the access control…