10 August 2026

Four layers of F&SCM security, one complete picture

Ask an F&SCM administrator what a particular security role grants, and the honest answer is usually: roughly this. Roles are built from duties, duties from privileges, and privileges from permissions on individual menu items, tables and fields. Four layers, each one a level of detail deeper than the last. Most day-to-day tooling, and most reviews, work with the top one or two.

That is not a criticism of the model. It is a well-designed hierarchy: duties group related privileges into business tasks, roles group duties into jobs, and the layering makes reuse and maintenance manageable. The challenge is visibility. Names live at the top of the hierarchy; actual access lives at the bottom.

What a complete picture means in practice

Authorization Monitoring reads all four layers together. For every role it shows not just which duties it carries, but which privileges those duties contain, which permissions those privileges grant, and which users hold the role, whether assigned directly or inherited. A role stops being a label and becomes a transparent container: you see what is actually inside.

On top of that structure sit Critical Permissions: research questions you define about your Security Objects. Who can maintain vendor master data? Who can acknowledge the receipt of goods? Who can process payment to a vendor? The analysis answers each question across every layer and every assignment path at once, so the answer is complete rather than approximate.

What changes when you can see everything

Role reviews become reviews of contents, not names. Whether a role called Accounts Payable Coordinator is actually limited to accounts payable stops being a matter of trust.

Auditor questions get answered in minutes. Who can approve payments? is a query result with a documented basis, not a research project across role definitions.

Conflicts surface automatically. Combinations of Critical Permissions that violate Segregation of Duties are detected across the whole structure, classified by impact, and queued for review.

Decisions leave a trail. Every finding is evaluated as Agreed, Disagreed or To Review, with reviewer, timestamp and rationale retained, and results exportable to Excel.

Why the full picture matters

Reviews and controls that only reason about the top layers inherit the top layers' blind spots. What that looks like in practice, and how access can exist that duty-level checks never evaluate, is a story of its own. 

The constructive version of that story is simpler: when all four layers are visible in one analysis, the question is no longer what you might be missing, but what you want to check next.

Frequently asked questions

What are security roles in Dynamics 365 Finance and Operations?

A security role is the top layer of the F&SCM security model. Users are only granted access through roles: a user without a role has no privileges. Roles contain duties, duties contain privileges, and privileges contain permissions on individual objects such as menu items, tables and fields.

How many standard security roles does Dynamics 365 F&O include?

About 100 standard security roles ship with the application, and all functionality is associated with at least one of them. Microsoft recommends duplicating these standard roles and modifying the copies, rather than editing the originals.

What is the Dynamics 365 security model?

A four-layer hierarchy: roles are assigned to users, roles contain duties, duties contain privileges, and privileges contain permissions to securable objects. Authorization is enforced at the entry point at run time.

Curious what the complete picture of your own environment looks like? Request a demo and bring your most complicated role.