SECURITY & ACCESS CONFIGURATION REVIEW

Dynamics 365 security audit: who can see, edit, and export what

Most Dynamics 365 security models weren't designed — they accumulated. A role copied here, a share granted there, a departed employee's account left active because nobody was sure what it touched. DesertCRM provides direct senior Dynamics 365 CE expertise to map, question, and redesign who has access to what, and why. Phoenix, AZ · remote US-wide.

What it is: a configuration-level review of your Dynamics 365 security model — roles, business units, teams, field-level security, sharing, and integration-user privileges. It is a configuration and access review, not a penetration test or a compliance certification. Who it's for: organizations that suspect their security model has sprawled past what anyone can explain, or that need a defensible access picture before an audit, acquisition, or new integration. How it starts: a Health Check — fixed scope, 5 business days, $1,500 — focused specifically on security. What you get: a role matrix, a privilege review, a least-privilege redesign proposal, and a remediation sequence ranked by risk.

Health Check scoped to Security & Access · $1,500, fixed · 5 business days

Signs your security model has sprawled

None of these are unusual — they're the predictable result of a security model that's been patched incrementally for years instead of periodically reviewed.

System Administrator as the catch-all role

Users who need one elevated permission were handed full System Administrator instead of a narrow custom role.

Roles copied and never pruned

A new role was cloned from an old one to save time, inheriting privileges nobody meant to grant and nobody's since removed.

Business units flattened or overbuilt

Either everything sits in one business unit regardless of org structure, or the hierarchy was overbuilt and now fights the security model it was meant to support.

No field-level security on sensitive columns

Compensation data, personal identifiers, or financial fields are visible to any user with basic record access.

Sharing used instead of roles

Individual records get manually shared so often that nobody can answer "who has access to this?" without querying the sharing table directly.

Guest or external users with broad access

External or guest accounts hold access levels well beyond what the collaboration they were created for actually requires.

Inconsistent app-level access via Dataverse teams

Model-driven app access granted through Dataverse teams is inconsistent — some users can open apps their role shouldn't expose.

Integration users over-licensed and over-privileged

Service accounts running integrations hold full interactive licenses and admin-level roles instead of scoped application-user permissions.

Audit logging off, export privileges everywhere

Auditing isn't enabled on the entities that matter, and export-to-Excel and bulk-delete privileges are granted broadly by default.

What the review produces

Written, specific, and ranked by business impact — not a generic checklist.

  • Role matrix — who has which role, what that role actually grants, and why it was assigned
  • Privilege review — a described (not invented-statistic) picture of where access is broadest relative to actual need, by role and by entity
  • Least-privilege redesign proposal — a role structure rebuilt around what people actually need to do their jobs
  • Separation of service accounts — integration and automation accounts moved off interactive licenses and admin roles onto scoped application users
  • Audit-log recommendations — which entities and events should have auditing enabled, and why
  • License-alignment findings — right-sizing licenses against actual assigned roles, including the Dynamics 365 license optimization angle
  • Remediation sequence — a prioritized order for implementing changes without disrupting active users mid-workday

Health Check → Stabilization Sprint → Fractional Administration

The same funnel as every DesertCRM engagement, scoped to security and access.

1

Health Check, focused on security

Fixed scope, 5 business days, $1,500. The audit weights roles, teams, sharing, field-level security, and license alignment rather than spreading evenly across every CE module.

2

Stabilization Sprint

Scoped after assessment. Implementation of the least-privilege redesign — role rebuilding, service-account separation, field-level security — as a fixed-price project confirmed in writing before work starts.

3

Fractional Administration

Ongoing senior ownership of user and security management — onboarding, offboarding, and role maintenance as the org changes. See Fractional Administration.

What this review is — and isn't

This review Covers Does not cover
Access & roles Security roles, business units, teams, sharing patterns Network-layer or tenant-wide IAM policy
Field-level security Field security profiles on sensitive columns Data classification for legal/compliance sign-off
Integration users Licensing and privilege level of service/application accounts Third-party system security outside Dataverse
Audit & logging Which entities/events should have auditing enabled Formal SOC 2 / compliance certification
Penetration testing Not part of this engagement

For Microsoft partners: bring DesertCRM in white-label for a security review your team doesn't have the bench for. See Partner Staff Augmentation.

Discuss Partner Capacity

Security audit questions, answered straight

Is this a penetration test? +
No. This is a configuration and access review of your Dynamics 365 security model — roles, teams, field-level security, and sharing patterns — not a penetration test and not a formal compliance certification. If you need a pen test or a specific compliance attestation, that's a separate, specialized engagement outside this scope.
What does "System Administrator used as a catch-all" actually mean? +
It means users who need one or two elevated permissions — say, the ability to reassign records or edit a business rule — were given the full System Administrator role instead of a narrower custom role. It's the single most common finding in a Dynamics 365 security review, and it's usually fixable without disrupting anyone's day-to-day work.
Do you review field-level security? +
Yes. The audit checks whether sensitive fields — compensation data, personal identifiers, financial figures — have field-level security applied at all, and whether the field security profiles actually match who should see them.
We use record sharing a lot instead of roles. Is that a problem? +
Often, yes. Sharing individual records instead of designing roles and business units correctly tends to sprawl over time — nobody can answer who has access to what without querying the sharing table directly. The audit maps current sharing patterns and proposes a role-based redesign that reduces reliance on ad hoc sharing.
Does the audit include license optimization? +
Yes. License-to-role alignment is part of the deliverable — for example, integration or service accounts holding interactive user licenses and admin roles they don't need, or users with Enterprise licenses whose assigned role only requires a fraction of that access.
How is this different from the general D365 Health Check? +
The general Health Check covers security as one of several review areas. This page describes the same engagement structure — Health Check, Stabilization Sprint, Fractional Administration — scoped and weighted specifically toward roles, teams, field-level security, and access control.

Ready to know exactly who has access to what?

A security-focused Health Check: 5 business days, $1,500, fixed. Fee credited toward Fractional Administration started within 30 days.

Direct senior Dynamics 365 CE expertise