29 July 2026

Turning F&O security findings into evidence an auditor actually accepts

Detecting a Segregation of Duties conflict in Dynamics 365 F&SCM is hard enough on its own. The native rules compare duty names rather than actual access, and a privilege assigned directly to a role bypasses them entirely. Detection takes deliberate work with tooling that looks below the duty level. 

But suppose that work is done and a real conflict surfaces. A second problem is waiting, one that gets far less attention: turning that finding into something an external auditor, or an internal controls team preparing for SOX testing, will actually accept as evidence.

“We looked into it and it's fine” is not evidence. Neither is a spreadsheet someone updated eight months ago. Auditors want to see who reviewed a finding, when, what they decided, and why, in a form they can sample and verify.

What an auditor is actually asking for

A typical SoD or ITGC test doesn't stop at “does a control exist.” It asks whether the control is operating: is someone actually reviewing the conflicts the system identifies, on a defined cadence, with a documented conclusion for each one? An organization that can show a rules page with zero unresolved violations, but no record of how conflicts were assessed or why exceptions were accepted, is showing a control that exists on paper and not in practice.

Why this is harder than it sounds inside F&SCM alone

Start with what the rules actually compare: duty combinations, not duty contents. A rule can declare that the duty for maintaining vendor bank accounts conflicts with the duty for processing payments, and it will fire correctly whenever those two names meet on a role or user. But if a third, innocently named duty quietly contains the same vendor bank permissions, nothing fires. The rule knows the names it was given, not the rights behind them, and a violation that is never logged can never be reviewed. The evidence problem starts before the logging does. 

Dynamics 365 F&SCM's native Segregation of Duties rules log a violation when one occurs, and require an administrator to allow or deny it. That decision isn't retained anywhere structured enough to hand to an auditor as a review trail: no reviewer name attached to a rationale, no timestamp history, no export an audit team can sample against a population.

A structured path from finding to evidence

Authorization Monitoring is built around exactly this problem, through a three-step workflow.

Define. Set up Critical Permissions as concrete research questions about your Security Objects (who can maintain vendor master data, who can acknowledge receipt of goods, who can process payment to a vendor), organized by process and category. Start from a standard library or define your own.

Analyze. Run the analysis against your actual Security Roles, Duties and Privileges. Conflict Detection automatically surfaces combinations of Critical Permissions that violate Segregation of Duties.

Review. Every result gets evaluated as Agreed, Disagreed or To Review, with a full audit trail: who reviewed it, when, and with what rationale. Results filter, review in bulk, and export to Excel, in a format built for audit documentation, not improvised for it.

What this changes on audit day

Instead of reconstructing, after the fact, why a particular access combination was accepted, the review history already exists. An auditor sampling ten SoD exceptions gets ten documented decisions with a reviewer and a date attached, not ten conversations that have to happen for the first time during the audit itself. 

Frequently asked questions

Does D365 F&O log segregation of duties conflicts?

Yes: conflicting assignments are logged, and an administrator must allow or deny each one. What the standard flow does not produce is a structured review trail per decision, with reviewer, rationale and timestamp history in an exportable form for audit sampling.

If your auditor asked for evidence of your last SoD review right now, could you produce it in minutes? Request a demo to see how Authorization Monitoring builds that evidence as part of the review process itself, not as a scramble before the audit.