11 August 2026

A user access review that takes three weeks and one spreadsheet

The quarterly access review starts the way it always does. Someone exports users and their roles from Dynamics 365 F&SCM into Excel, splits the tabs by department, and emails managers with a deadline. Then the chasing begins. Two reminders later, the last approvals trickle in, the spreadsheet is filed for the auditor, and everyone agrees, again, that there must be a better way.

Three weeks of effort. And the uncomfortable question is what it actually proved.

Why the spreadsheet version fails quietly

Managers were asked to certify role names: AP Clerk vNew2, Warehouse Extended, Finance Base Copy. Nobody reviewing that list can see what those roles grant, so the review becomes a plausibility check on job titles. Access that looks reasonable gets approved, indefinitely, without anyone ever examining its contents.

The data is also stale before the review ends. Roles change during those three weeks; the export doesn't. Exceptions get resolved in email threads that never make it into the file. And the rationale behind each approval, the one thing an auditor will eventually ask about, isn't captured anywhere at all.

One category deserves special attention here. Microsoft's own documentation on role assignment is explicit: users who are manually assigned to a security role must also be manually removed, because automatic role assignment rules never clean them up. Every manual grant in your environment is therefore a standing review item, sitting there until someone deliberately takes it away.

What reviewers actually need

A review is only as good as what the reviewer can see. That means actual granted access per user, both directly assigned and inherited through roles. It means the risky part surfaced first: which users hold Critical Permissions, and where combinations conflict with Segregation of Duties, so attention lands where it matters instead of being spread evenly across hundreds of harmless rows. And it means a way to record each decision that survives longer than an inbox.

The same review, structured

With Authorization Monitoring, the review starts from analysis instead of an export. Critical Permissions are defined once, as research questions about your Security Objects. The analysis shows who holds what, findings are classified by impact, and reviewers work through them as Agreed, Disagreed or To Review, individually or in bulk where that is justified. Reviewer, timestamp and rationale are retained per decision, and the whole result exports to Excel in a form an audit team can sample.

The three weeks collapse into focused sessions, and the output changes character: from a filed spreadsheet that proves a process happened, to documented decisions that prove access was actually reviewed.

Frequently asked questions

How do you assign users to security roles in Dynamics 365 F&SCM?

Under System administration > Security > Assign users to roles. Assignment can be manual, or automatic based on membership rules that query business data. Users can also be explicitly excluded from automatic assignment.

Why do manually assigned roles matter for access reviews?

Because Microsoft's documentation is explicit: users who are manually assigned to a role must also be manually removed. Automatic role assignment rules never clean them up, so every manual assignment is a standing item for your periodic access review.

If your next access review starts with an Excel export, we should talk. Request a demo and see the same review run on a realistic F&SCM environment.