Dynamics 365 security audit: who can see, edit, and export what
Most Dynamics 365 security models weren't designed — they accumulated. A role copied here, a share granted there, a departed employee's account left active because nobody was sure what it touched. DesertCRM provides direct senior Dynamics 365 CE expertise to map, question, and redesign who has access to what, and why. Phoenix, AZ · remote US-wide.
What it is: a configuration-level review of your Dynamics 365 security model — roles, business units, teams, field-level security, sharing, and integration-user privileges. It is a configuration and access review, not a penetration test or a compliance certification. Who it's for: organizations that suspect their security model has sprawled past what anyone can explain, or that need a defensible access picture before an audit, acquisition, or new integration. How it starts: a Health Check — fixed scope, 5 business days, $1,500 — focused specifically on security. What you get: a role matrix, a privilege review, a least-privilege redesign proposal, and a remediation sequence ranked by risk.
Signs your security model has sprawled
None of these are unusual — they're the predictable result of a security model that's been patched incrementally for years instead of periodically reviewed.
System Administrator as the catch-all role
Users who need one elevated permission were handed full System Administrator instead of a narrow custom role.
Roles copied and never pruned
A new role was cloned from an old one to save time, inheriting privileges nobody meant to grant and nobody's since removed.
Business units flattened or overbuilt
Either everything sits in one business unit regardless of org structure, or the hierarchy was overbuilt and now fights the security model it was meant to support.
No field-level security on sensitive columns
Compensation data, personal identifiers, or financial fields are visible to any user with basic record access.
Sharing used instead of roles
Individual records get manually shared so often that nobody can answer "who has access to this?" without querying the sharing table directly.
Guest or external users with broad access
External or guest accounts hold access levels well beyond what the collaboration they were created for actually requires.
Inconsistent app-level access via Dataverse teams
Model-driven app access granted through Dataverse teams is inconsistent — some users can open apps their role shouldn't expose.
Integration users over-licensed and over-privileged
Service accounts running integrations hold full interactive licenses and admin-level roles instead of scoped application-user permissions.
Audit logging off, export privileges everywhere
Auditing isn't enabled on the entities that matter, and export-to-Excel and bulk-delete privileges are granted broadly by default.
What the review produces
Written, specific, and ranked by business impact — not a generic checklist.
- Role matrix — who has which role, what that role actually grants, and why it was assigned
- Privilege review — a described (not invented-statistic) picture of where access is broadest relative to actual need, by role and by entity
- Least-privilege redesign proposal — a role structure rebuilt around what people actually need to do their jobs
- Separation of service accounts — integration and automation accounts moved off interactive licenses and admin roles onto scoped application users
- Audit-log recommendations — which entities and events should have auditing enabled, and why
- License-alignment findings — right-sizing licenses against actual assigned roles, including the Dynamics 365 license optimization angle
- Remediation sequence — a prioritized order for implementing changes without disrupting active users mid-workday
Health Check → Stabilization Sprint → Fractional Administration
The same funnel as every DesertCRM engagement, scoped to security and access.
Health Check, focused on security
Fixed scope, 5 business days, $1,500. The audit weights roles, teams, sharing, field-level security, and license alignment rather than spreading evenly across every CE module.
Stabilization Sprint
Scoped after assessment. Implementation of the least-privilege redesign — role rebuilding, service-account separation, field-level security — as a fixed-price project confirmed in writing before work starts.
Fractional Administration
Ongoing senior ownership of user and security management — onboarding, offboarding, and role maintenance as the org changes. See Fractional Administration.
What this review is — and isn't
| This review | Covers | Does not cover |
|---|---|---|
| Access & roles | Security roles, business units, teams, sharing patterns | Network-layer or tenant-wide IAM policy |
| Field-level security | Field security profiles on sensitive columns | Data classification for legal/compliance sign-off |
| Integration users | Licensing and privilege level of service/application accounts | Third-party system security outside Dataverse |
| Audit & logging | Which entities/events should have auditing enabled | Formal SOC 2 / compliance certification |
| Penetration testing | — | Not part of this engagement |
For Microsoft partners: bring DesertCRM in white-label for a security review your team doesn't have the bench for. See Partner Staff Augmentation.
Discuss Partner CapacitySecurity audit questions, answered straight
The full 8-area environment audit, of which the security review is one part.
How DesertCRM itself accesses and secures data during any engagement.
Service-account and connection-reference issues, closely tied to integration-user security findings.
Data-quality issues that often surface alongside sharing sprawl and access problems.
How a fixed-price implementation project is scoped after the Health Check.
Ongoing user and security management once the role structure is rebuilt.
Ready to know exactly who has access to what?
A security-focused Health Check: 5 business days, $1,500, fixed. Fee credited toward Fractional Administration started within 30 days.
Direct senior Dynamics 365 CE expertise