Set up access is available to End users Eg Account manger/supervisor role
-
Set up access is available to End users Eg Account manger/supervisor role
Posted by nazimlalji@hotmail.com on September 2, 2018 at 4:55 pm-
Hi All
Why Set up in most of module is wide open for the end users with Manager role. Like Accounting manager or supervisor have access to GL set up and can change a complete set up and set up new accounts, journals and many more. Without a proper audit trail or approvals
Isnt it defy the purpose of SOX and internal audit, Where without ticket and approval set ups are changed
Beside role customization which is tedious and expensive way to fix each role. Is there any other way to lock access to set up for endusers
please advise
thanks and kind regards
——————————
Nazim Lalji
Dynamics AX Analyst——————————
-
Ludwig Reinhard
MemberSeptember 4, 2018 at 12:47 AM
Hi Nazim,
It is a matter of fact that the standard roles often do not fit and you are right that the setup of new company specific roles can take a long time.
However, MS cannot know the roles and security requirements of each and every company in the world and an accounting manager in my home country Germany hasĀ often very different tasks and responsibilities from an accounting manager in the US.
To accelerate the setup task you might get help from your MS partner that helps you implementing AX/D365FO.
Partners often modify the standard roles for multiple customers and regularly often have a set of customized roles that they might share.
I would thus suggest that you talk to your partner and ask whether they have some customized role templates from other project that they might be able to share with you.
Best regards,
Ludwig——————————
Ludwig Reinhard
Sycor
Goettingen
——————————
——————————————- -
Hi Nazim.
Like Ludwig says there is no easy way and maybe you can find similar role via your partner.If you have installed the ‘Security Development’ tool then you have rather good tool to record the entry points and change the access in a reasonable simple way.
Here is one link that guides you well.
Tips on AX 2012 Security Development Tool – Part 3Kaya Consulting remove preview Tips on AX 2012 Security Development Tool – Part 3 This is the third part of a blog series related to the Security Development Tool. This time I will walk through the functionalities related to recording of entry points. Also take a note if you first need to install a hotfix to be able to use the recording option. View this on Kaya Consulting > ——————————
Glenn Linaa
Tasklet Factory Mobile WMS
Aalborg, Denmark
——————————
——————————————- -
Nazim,
I actually have done (and will do) a session at Summit and other user group conferences about this exact topic. The out of box roles from Microsoft were developed from a functionality perspective, not from an SOD perspective. As such, as you have found, roles give much more access than they probably should from an SOD perspective.
However, one of the ‘security challenges’ we also discuss is trying to use either customizations or complex workflows instead of setting up and configuration security correctly. We caution against this because of the challenging maintainability and the possibility that changes that have nothing to do with security might actually change your security (if you change a customization or workflow it might have unintended security ramifications).
I do have a resource that might help you a bit, we at Fastpath have developed a security matrix to help design security. I have included both AX 2012 and D365FO versions of this.
Gofastpath remove preview AX 2012 Security Matrix Download this free Microsoft Dynamics AX 2012 Security Matrix spreadsheet. It will help with designing the security roles in AX. View this on Gofastpath > Dynamics 365 for Operations Security Matrix
Gofastpath remove preview Dynamics 365 for Operations Security Matrix Download this free Microsoft Dynamics 365 for Operations Security Matrix spreadsheet. It will help with designing the security roles in D365. View this on Gofastpath > Please feel free to reach out with any questions you might have.
——————————
Alex Meyer
Director of Dynamics AX/365 for Finance & Operations Development
Fastpath
Des Moines, IA
——————————
——————————————-
nazimlalji@hotmail.com replied 7 years ago 1 Member · 0 Replies -
-
0 Replies
Sorry, there were no replies found.
The discussion ‘Set up access is available to End users Eg Account manger/supervisor role’ is closed to new replies.