Security Insights for D365 FO

Review Security Insights for D365 FO

Return to main page
-->

Security Insights for D365 FO

The following view is available to colate and review user access and security utilization:

Navigate to System administration > Insights for user access and security

Processing

The following steps are available to initiate or update the required fields.

1. Build license information

Synchronizes the current user roles, privileges and accessible menu items. This can only be run as batch.
Recommended to run again after Security configuration changes. Uses new model of D365 licensing tables (from 10.0.44 Security Governance) to build user licensing information.

Parameters:

Note: Microsoft automatically updates License usage summary information daily. This update rebuilds the new licensing tables, and thus loses our Security Insights recommended license field data. We’ve thus added the following parameter option to this step.

2. Initiate user security groups

Ability to automatically group similar users

Parameters:

When using User groups or Microsoft Entra ID security groups and an enabled user isn’t assigned to one of the groups, a new group Not assigned will be created for these users.

3. Fetch interaction data from application insights

Fetch user interation data from Azure Applications Insights

Parameters:

The records to include are automatically filtered to enabled users and can also be filtered to User Id(s).

The number of records fetched from Azure application Insights can be checked in the batch job history log.

Note: User accessed menu items date/time data: starts when logging usage data to AppInsights with either DXC’s Insights or Standard monitoring.

4. Calculate utilization rates

Calculate utilization rates of user roles and privileges based on accessing menu items.

The records to include are automatically filtered to enabled users and can also be filtered to User Id(s).

Review

Next step is to review the utilization.

Example actions that could be taken after review:

After modifying security configuration, rerun the following to update the values on the page:

Sections

The page is split into:

Fields

Description of a few of the key fields.

Buttons

The following buttons are available on the views:

Clicking on a Role name, will open Assign users to roles form, thus enabling reviewer to see which other users have been assigned to the selected role.

Highlight unused licenses

Security insights by user includes the ability to highlight unused licenses for a user and each role for the selected user. Unused means the applicable user didn’t access any menu items / securable object with that license type in the fetch period.

Select required highlight colour in field Background color for unused license fields on Visual tab in Insights for user access and security parameters to enable the colour highlights for unused licenses.

In below example the selected user didn’t access any Operations licenses in the fetch period
Visual

Security insights by user

Security insights by user

Assign users to role

System administration > Security > Assign users to roles

Role utilization % on form Assign users to roles assists in determining if other assigned users utilised the role in the fetched period.

Note: Only supported for roles assigned to users in F&O (not ‘Microsoft Entra ID security groups’)

© DXC Technology Company