dynamics 365 it audit software

Dynamics 365 IT Audit Software Consulting

Dynamics 365 IT audit software is the set of tools and native platform capabilities used to test the general IT controls (ITGCs) that support Dynamics 365 Finance & Operations as a financial reporting system — access provisioning and deprovisioning, change management, and system operations. IT audit testing of Dynamics 365 differs from process-control testing (journal entry approvals, three-way match) because it targets the platform layer itself: who can grant security roles, how configuration changes to posting profiles and tax rules move from development to production, and whether the Power Platform surface connected to the ERP is governed. Dynamics 365 has strong native logging for this — database-level change tracking plus Microsoft Purview tenant-wide audit logs — but ITGC testing requires assembling evidence from both the F&O application layer and the underlying Power Platform/Dataverse environment, which most generic IT audit checklists do not distinguish.

Access provisioning and deprovisioning as an ITGC

Access ITGC testing for Dynamics 365 covers the full lifecycle: new-user role assignment, role changes tied to job transfers, and timely deprovisioning on termination. Dynamics 365 records role assignment events, but the request-and-approval trail behind a role grant — who requested it, who approved it, and why — typically lives outside the ERP in a service-desk or identity-governance tool, which means IT audit has to reconcile two systems rather than pull a single Dynamics 365 report. A common testing approach samples a population of role changes from the F&O security log and traces each one back to an approved request ticket, flagging any grant with no corresponding approval.

Deprovisioning testing is where Dynamics 365 environments most often fail ITGC testing, particularly when user identity is federated through Microsoft Entra ID. A termination processed correctly in Entra ID disables the user's sign-in, but stale security-role assignments can persist inside F&O and inside any connected Power Platform environments, and a same-day Entra ID disablement does not guarantee a same-day review of what roles that account still held. IT audit testing typically samples recent terminations and confirms both the identity-layer disablement and the F&O role-assignment removal, since the two are governed by different processes and can drift out of sync.

Change management testing across F&O and Power Platform layers

Change management ITGC testing for Dynamics 365 evaluates whether configuration and code changes — modified posting profiles, updated approval thresholds, custom extensions built on the platform — moved through a controlled process with segregation between the person making the change and the person approving it for production. F&O's database-level change tracking captures the technical record of what changed and when, but it does not capture whether that change was authorized; IT audit has to trace sampled change-tracking entries back to a change ticket or deployment record maintained in the organization's development lifecycle tooling.

The scope gap that recurring shows up in Dynamics 365 IT audit findings is that change management testing stops at the F&O application boundary and never extends into Power Platform. A Power Automate flow or Power App that reads from or writes to Dataverse tables underlying F&O is a change to the financially relevant environment just as much as a modified posting profile, but it is built and deployed through the Power Platform admin center and Power Apps maker portal, tools most ERP change-management processes were not originally designed to cover. IT audit test plans that only sample F&O change tickets will systematically miss this category of change.

System operations: backup, monitoring, and Power Platform DLP as an ITGC

System operations testing for a cloud-hosted Dynamics 365 F&O environment looks different from testing an on-premise ERP: backup and infrastructure resilience are largely managed by Microsoft under the Dynamics 365 service, so IT audit's testing effort shifts toward tenant-level configuration controls the organization does own — Data Loss Prevention policy configuration, environment strategy (which environments can host production financial data), and Purview audit log retention settings. Testing whether these tenant-level controls are configured, rather than testing infrastructure the organization does not directly operate, is the practical adaptation IT audit programmes have to make for a SaaS-delivered ERP.

Microsoft Purview audit log retention is itself an ITGC worth testing directly: if retention is configured for a period shorter than the audit cycle requires, evidence needed for a Section 404 test can no longer exist by the time testing occurs. IT audit test plans for Dynamics 365 should include a direct check of the configured retention period against the organization's evidence-retention policy, rather than assuming default retention settings are sufficient for SOX purposes.

Selection Criteria

What actually differentiates the options

  • ·Access ITGC testing that reconciles Dynamics 365 role-assignment events against approved request tickets from the identity-governance or service-desk system, not F&O security logs alone.
  • ·Termination testing that verifies both Microsoft Entra ID sign-in disablement and F&O/Power Platform role-assignment removal, since the two processes can drift out of sync.
  • ·Change management test plans that explicitly extend into the Power Platform admin center and Power Apps maker portal, not just F&O change tickets, given how much financially relevant change now happens at the Dataverse layer.
  • ·A direct, periodic check of Microsoft Purview audit log retention settings against the organization's evidence-retention requirements, rather than an assumption that default retention covers the audit cycle.
  • ·Documented ownership of Power Platform governance (DLP policies, environment strategy) inside the ITGC control set, with a named control owner distinct from core F&O system administration.
Compliance Matrix

Requirement, control, evidence

RequirementControlEvidence
ITGC — access provisioning must be authorized and evidencedSampled Dynamics 365 role-assignment events reconciled to approved access-request tickets in the identity-governance system.Sample testing worksheet showing role-assignment log entries matched to request ticket ID, approver, and approval date, with exceptions documented.
ITGC — access must be removed timely on terminationSampled terminations verified for same-cycle Entra ID disablement and F&O/Power Platform role-assignment removal.Termination sample testing worksheet showing disablement date, role-removal date, and days elapsed, with exceptions beyond policy threshold tracked to remediation.
ITGC — configuration and code changes must follow controlled change managementSampled F&O change-tracking entries and Power Platform deployment events traced to an approved change ticket with segregation between developer and approver.Change sample testing worksheet covering both F&O configuration changes and Power Platform/Dataverse deployments, each matched to a change ticket.
ITGC — audit evidence must be retained for the required testing and lookback periodMicrosoft Purview audit log retention period configured to meet or exceed the organization's SOX evidence-retention policy.Purview audit log retention configuration export, compared directly against the documented evidence-retention requirement.
ROI Model

What this actually costs

Cost driverLowHighWhat moves it
ITGC test plan design covering F&O and Power Platform layers$30,000$90,000Scales with whether the organization already has a documented ITGC framework to extend versus building one from scratch, and number of in-scope environments.
Access and change management sample testing (per testing cycle)$25,000$100,000Driven by sample sizes, number of legal entities and Power Platform environments, and whether identity-governance reconciliation is manual or tool-assisted.
Remediation of ITGC deficiencies (deprovisioning gaps, ungoverned change paths, retention shortfalls)$20,000$150,000Highly dependent on severity — a retention policy fix is inexpensive; rebuilding deprovisioning workflows across Entra ID, F&O, and Power Platform environments is not.
Assumptions
  • · Ranges assume a single primary Dynamics 365 F&O tenant with standard Power Platform integration; environments with extensive custom extensions trend toward the high end.
  • · Figures are illustrative estimates based on typical mid-market to large-enterprise Dynamics 365 ITGC engagements, not a quote for a specific organization.
  • · Microsoft licensing, Entra ID governance tooling, and third-party IT audit software costs are excluded — this reflects advisory and testing labor only.
Worked scenario

A representative scenario

A hypothetical financial services back-office running Dynamics 365 F&O integrated with several Power Automate flows for regulatory reporting is undergoing its annual ITGC test cycle. The access-testing sample surfaces three terminated employees whose Entra ID accounts were disabled within 24 hours as required, but whose Dynamics 365 security roles remained active for between eleven and forty days, because role removal depended on a separate manual ticket that was not consistently filed at termination. Separately, the change-management sample finds that two of the regulatory-reporting Power Automate flows were modified in the prior quarter with no corresponding change ticket, because the flows were built and maintained by a business analyst outside the formal ERP change-management process. Remediation typically involves automating F&O role removal as part of the existing Entra ID termination workflow rather than relying on a second manual step, and extending the change-management ticketing requirement explicitly to Power Platform assets connected to financial reporting, with the Power Platform admin center added to the population IT audit samples from going forward. This pattern — identity-layer controls working correctly while ERP-layer and Power Platform-layer controls lag behind — is common enough in Dynamics 365 environments with heavy Power Automate use that it is presented here as illustrative, not as a specific client outcome.

FAQ

Common questions

The three standard ITGC domains apply: access controls (provisioning, role changes, deprovisioning), change management (configuration and code changes moving to production), and system operations (backup, monitoring, and — for a SaaS ERP like Dynamics 365 — tenant-level configuration such as Power Platform DLP policies and Purview audit log retention).

Next step

Book an assessment

Get a scoping call on dynamics 365 it audit software for your organisation's platform and entity structure.

Book an Assessment →