If my Org is Zero Trust Security compliant and we are connecting to D365 does that make us Zero Trust Security Compliant all across?
By Org I meant my company.
Hey Ephraim.
Can you define "org"? are you referring as "your company" or "the D365 environment"? There are several things here that need to be reviewed:
- if you're using D365 FS mobile for example: Do you have administration for the mobile devices?
- Do you have a procedure in case an account is compromised? does that procedure includes removing licenses/disabling the account in AAD?
- Do you have Conditional Access policies for D365 & the user accounts?
Because Dynamics 365 relies on Azure technology (specially AzureAD), devices & accounts can be managed and they will force the device/user to be compliant. At the moment you modify the account/Device on Azure, D365 will synchronize and accounts will be disabled (for example), but being zero trust is not a Stamp that you can show, but instead having the right set of procedures in place.
Regards,
Muhammad Shahzad Sh...
51
Most Valuable Professional
Ramesh Kumar
42
David Shaw_UK
27