web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Suggested Answer

Architecting custom SoD rules beyond the Microsoft default ruleset

(2) ShareShare
ReportReport
Posted on by 194

We are running into a scenario where the out-of-the-box Microsoft Segregation of Duties (SoD) ruleset completely misses several critical, industry-specific risk combinations for our client.

When building custom SoD rules from scratch in D365 F&O, what is the best practice for maintaining them? Specifically, if we define SoD rules at the Duty level, how do we prevent future updates or custom privilege additions from silently breaking the rule's effectiveness? Are there tools or frameworks you use to map out these custom Duty conflicts before configuring them in the system?

Categories:
I have the same question (0)
  • Suggested answer
    SajeedMullaji Profile Picture
    798 on at

    @Huma Selot CU200816... 
    Here is the architectural approach that works:

    Building custom SoD rules at the right level:
    Always define SoD rules at the Duty level — not the Role level and not the Privilege level. Duty level is the correct abstraction because it represents a business process activity rather than a technical permission. This makes your rules readable to auditors and stable across role changes.

    Navigate to System administration > Security > Segregation of duties > Segregation of duties rules > New. Define each rule as a conflict between two specific duties — for example PurchOrderMaintain conflicts with PurchOrderApprove. The system will flag any user assigned both duties simultaneously.

    Preventing silent rule breakage from updates:
    The biggest risk is a developer adding a new privilege to an existing duty — or creating a new duty — that effectively replicates a conflicting capability without triggering your existing SoD rule. Three things to prevent this:

    Document every SoD rule with a business rationale — not just the duty names. When developers see why a rule exists they are less likely to inadvertently break it through new privilege additions.

    Run the SoD conflicts report after every platform update and security change — System administration > Security > Segregation of duties > Segregation of duties conflicts. Review the delta — new conflicts appearing or existing conflicts disappearing both indicate something changed.

    Add SoD conflict report review to your change management process — any security role or duty change must include a SoD report run before and after as part of the approval documentation.

    Frameworks for mapping custom duty conflicts before configuring:
    Build a conflict matrix in Excel before touching the system. Columns are duties, rows are duties, cells mark whether the intersection is a conflict and why. Map your business processes — AP, AR, GL, Procurement, Inventory — and identify every combination where one person controlling both activities creates fraud risk or audit failure.

    This matrix becomes your living SoD rulebook. Every new rule added to D365 F&O traces back to a cell in this matrix with a documented business justification. Auditors love this — it shows your SoD framework is intentional not accidental.

    If it helps, mark answered.

  • Suggested answer
    NikolajSorensen Profile Picture
    1,816 on at

    Hi.

    The standard SoD framework only works on the duty level, which means you have no way of securing future updates or privilege creep do not silently violate your ruleset.

    I'm not sure what out-of-the-box SoD rulesets you are referring to - as there are none defined default.

    So if you have SoD rulesets in your D365 instance, someone set them up.

     

    There are several 3rd party tools that allow you to define SoD rules at the menu item level (the relevant level), but these come at a cost.

  • NikolajSorensen Profile Picture
    1,816 on at

    @SajeedMullaji 

    Stop your AI assisted responses, they are often either completely or partially wrong. 

    At least have the courtesy of marking them as AI assisted as requested several times.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
SajeedMullaji Profile Picture

SajeedMullaji 760

#2
Martin Dráb Profile Picture

Martin Dráb 330 Most Valuable Professional

#3
CU10121822-0 Profile Picture

CU10121822-0 310

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans