Hi Community,
We are a small IT team of 2 managing our Dynamics 365 Business Central environment. Currently, both of us have SUPER access, but we want to implement Segregation of Duties (SoD) to reduce risk.
Specifically, we want to ensure:
No single IT staff member can make critical system changes alone (e.g., creating users and assigning full admin permissions).
Administrative duties are split in a way that both can manage the system safely.
Change logs and approvals can be leveraged to maintain accountability.
We would like guidance on:
Best practices for splitting IT responsibilities in BC.
How to use permission sets instead of full SUPER access for day-to-day tasks.
Recommended approval or review processes for system changes.
Any tips on using sandbox environments for testing changes safely.
Thank you in advance for your insights!