<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1950087345534883&amp;ev=PageView&amp;noscript=1">
Skip to content

Microsoft Dynamics & ERP Security

Dynamics 365 Penetration Testing. Microsoft Lets You Test. Most ERP Vendors Don't.

Finance & Operations, Business Central, legacy AX/NAV/GP, and the Power Platform layer quietly executing your transactions. IntegSec tests all of it, including the identity plane that outranks every role inside the ERP.

6295907141639652363-128 1

Decades on the Offense

Led by an offensive-security team whose founder holds CISSP, OSCP, and OSCE, with two decades breaking into enterprise systems at IBM X-Force Red, Trustwave SpiderLabs, and IntegSec.

10217013321529659193-128 1

Real Human Pentesters

Not a scanner reselling a dashboard. Experienced operators manually chain misconfigurations into proven attack paths a tool will never produce.

d365_solid

Microsoft Stack Depth

X++, AL, and C/AL code review, Dataverse and Power Platform security models, Entra ID conditional access, and SQL Server internals. One team covering all four layers.

Why Dynamics Needs Its Own Methodology

Dynamics is not one product with one boundary. Where the customer's responsibility starts and stops moves per product, and the same finding can be critical in one and meaningless in another.

d365_tonal

The Escape Hatch Is a Feature

Data Management Framework in F&O, Configuration Packages in Business Central, Integration Manager and SmartList in GP all move bulk data around field-level and record-level controls. They are supported functionality working as designed, so nothing fires on a scanner and nothing looks wrong in an audit.

Controls Enforced Only at the Form

A permission that blocks a field on screen frequently does nothing to the OData entity, the underlying table, or the data-import tool. We test every capability at all of those levels, because that gap is where the material findings consistently live.

Refresh Is the Reliable Data Breach

Production-to-sandbox copies carry live payroll and vendor bank data into environments with developer access and weaker authentication. From there a database export lands on a Tier-1 VM where a developer holds local administrator. Production data, offline, on a machine your developers own.

Power Platform Runs as Someone Else

A Power Automate flow executes under the credentials of whoever owns its connections, not whoever triggers it. A flow built by a finance manager and shared downward performs ERP actions as the finance manager, bypassing approval entirely and misattributing it in the audit trail.

Identity Is Entra ID

So the ERP inherits its gaps. Conditional access exclusions, service principals exempt from MFA, and app registrations holding administrative ERP roles are ERP findings that live outside the ERP. Conditional access covering the ERP but excluding Power Apps and Power Automate is routine.

Auditing Is Off Until Proven On

In F&O, Business Central, and Dataverse, per-table logging is something you must explicitly enable. We assume it is off until demonstrated otherwise, then measure what your logs and SIEM actually captured against what we did.

The Dynamics Attack Surface We Test

Real Dynamics testing spans four layers: the application, the Power Platform running beside it, the Entra ID identity plane above it, and, for on-premises and legacy estates, the SQL Server underneath it.

 Microsoft Cloud Penetration Testing Rules of Engagement   

 

Data & Bulk Export

DMF, Configuration Packages, SmartList, Excel add-in

OData & APIs

Same data, different door, weaker enforcement

Roles & Duties

Duties, privileges, entry points, XDS policies

Environment Refresh

Unmasked production data in weaker environments

Identity & Admin Planes

Entra ID, LCS, Admin Centers, service principals

Power Platform

Flows, connectors, DLP, Dataverse, Power Pages

Server-Side Code

X++, AL, C/AL, batch jobs, dev endpoints, plug-ins

SQL Server Layer

Query the database, bypass every application control

Testing You Are Actually Allowed to Do

Microsoft's cloud penetration testing rules of engagement permit customers to test their own tenants and resources without pre-approval. That is materially more permissive than several other SaaS ERP vendors, and it is why a D365 engagement can honestly be called a penetration test rather than a configuration review.

Authenticated & Insider Simulation

Starting from a realistic business role, we chain over-granted duties, bulk data tools, and API paths into demonstrated escalation, then show what that access permits against the ledger, the vendor master, and payroll.

Patch Posture Verified, Not Assumed

For on-premises and legacy estates we verify the Windows Server, IIS, SQL Server, and AD FS stack against actual patch level rather than banner version, and flag products past their Microsoft lifecycle date where remediation means migration, not patching.

Detection Assessment

We compare our action log against what your Entra ID sign-in logs, Purview audit search, Application Insights, and SIEM actually captured, including whether the vendor bank change and the posting-period override were alerted on at all.

The Paths That Carry Real Dynamics Compromise

Across engagements, most genuine compromise runs through a small number of routes. We test all of them explicitly, even when one has already succeeded.

The Sandbox Export Chain

Can a sandbox holding live payroll and vendor bank data be refreshed from production, exported as a database file, and restored to a Tier-1 VM where a developer has local administrator? This is the single most reliable data breach in a Dynamics estate, and it runs entirely through supported administrative functions

Flow Ownership Escalation

We build a flow owned by a privileged account and trigger it from a low-privileged one to demonstrate the escalation. We also hunt for HTTP-triggered flows with no authentication or a guessable URL performing ERP writes, which is an unauthenticated path into the ledger from the internet.

Service Principals Above the ERP

Service principals exempt from conditional access and MFA are usually necessary and usually the weakest link. Full-access ERP permissions and Dataverse System Administrator on a machine identity are common, as is impersonation privilege that lets one identity act as any user.

Code to OS Execution

In legacy AX, development access plus the X++ editor gives OS command execution as the AOS service account. In NAV and Business Central on-premises, C/AL shell and .NET interop do the same as the server service account. We also review X++ and AL for skipped authorization attributes, direct SQL, and code writing straight to bank account and journal tables.

GP Has No Application Server

The client talks to SQL Server directly and every GP user is a SQL Server login, so GP's security model is a convention you choose to respect rather than a boundary that is enforced. Documented stored procedures provide a SQL-level write interface straight into GP business tables. A GP test that never reaches SQL has not tested GP.

The Vendor Bank Account Chain

Can a user with the standard AP Clerk role change a vendor's bank account and generate a payment journal against it? We test that at four levels: the form, the underlying table, the OData entity, and the bulk-import tool. The stop line is written down in advance: journal generated and reviewed, never posted and never exported to file.

How IntegSec Tests Microsoft Dynamics

Offensive expertise applied to the systems that run your finance, supply chain, and payroll. We don't hand you a scanner dump, we demonstrate exploitable attack paths and how to close them.

Dynamics 365 Penetration Testing

Expert-led, manual testing of Finance & Operations and Business Central, conducted under Microsoft's published rules of engagement for customer testing.

  • OData, REST, and SOAP endpoint authorization testing
  • Role, duty, privilege, and security filter analysis
  • Data Management Framework and Configuration Package bypass paths
  • Environment refresh, export, and Tier-1 exposure chains
  • X++ and AL code review for authorization and injection flaws

What You Get: Documented attack chains with proof-of-exploit, business-impact risk ratings, and remediation routed to the team that actually owns each fix.

Power Platform & Identity Review

Roughly half the value of a D365 engagement lives outside the ERP application. This covers the parallel path into the same data and the identity plane above it.

  • Power Automate flow ownership and connection reference abuse
  • DLP policy coverage and custom connector egress paths
  • Dataverse security roles, access levels, and column security
  • Entra ID conditional access gaps, including Power Platform exclusions
  • Service principal, app registration, and partner access review

Owned Outside the ERP Team: Power Platform and identity findings routinely have an owner outside the ERP team. We route them accordingly, because sending them to the ERP team guarantees inaction.

Legacy AX, NAV & GP Testing

On-premises estates are a completely different engagement: network, Active Directory, and SQL Server are fully in scope, and modern identity controls are often absent entirely.

  • SQL Server layer testing, including direct business-table access
  • Active Directory service account, SPN, and delegation abuse
  • Development access to OS command execution paths
  • Legacy table browser read and write access
  • Microsoft lifecycle position and end-of-support exposure

Remediation Is Often Migration: Where a product is past end of support there is no patch to apply. We say so directly and frame the finding as a migration decision with a risk-based timeline.

Business Control & Fraud Path Review

The review that makes this an ERP test rather than a web application test. Run with a functional counterpart, against test data, inside written stop lines.

  • Procure-to-pay: vendor bank change through payment run
  • Approval workflow bypass via import and bulk data tools
  • Posting window and period-close override testing
  • Cross-module SoD with the affected user population per conflict
  • Licence entitlement versus granted roles as a compliance finding

Written for Two Audiences: Fraud scenario walkthroughs your finance and internal audit teams can read directly, alongside the technical detail your ERP and identity teams need.

Let’s Talk
WHY CHOOSE US

 Why Teams Choose IntegSec for Dynamics 

Featured icon (4)-2
Credentialed, Not Black Box

There is little value in a black-box test of a Microsoft-hosted tenant. We work from real business roles outward, which is the only way to find the authorization and business-control failures that actually matter.

Featured icon (5)-2
Power Platform Is In Scope

Not adjacent to the ERP, part of it. It is a second path into the same data with a different security model and usually no change control. Most vendors quote the ERP and leave it out entirely.

Featured icon (6)-2
Two Questions, Not One

Is the control enforced, and is the control sufficient? The first is a technical failure. The second is a design failure, it carries most of the material findings, and a purely technical tester will never raise it.

Featured icon (2)-2
Non-Disruptive by Design

We agree lockout thresholds up front, avoid period close and payroll windows, and stop business-process scenarios at a written line: a payment journal generated and reviewed, never posted and never exported to file.

FAQs-amico 1-3

Microsoft Dynamics Penetration Testing FAQ

Common questions from security, ERP, and audit teams evaluating a Dynamics assessment.

  • Yes. Microsoft publishes cloud penetration testing rules of engagement permitting customers to test their own tenants and resources without pre-approval. That is materially more permissive than several other SaaS ERP vendors, and it means a D365 engagement can legitimately be called a penetration test. We confirm the current rules at scoping time.

  • It should be. Power Platform is an ERP attack surface, not an adjacent one. A flow runs under the credentials of whoever owns its connections, not whoever triggers it, so a flow authored by a finance manager and shared downward performs ERP actions as that manager. It bypasses approval and misattributes the action in your audit trail.

  • Yes, and very differently. These are on-premises, so network, Active Directory, and SQL Server are fully in scope. GP in particular has no application server: every GP user is a SQL Server login and the security model is a convention rather than an enforced boundary. Where a product is past end of support, remediation is migration rather than a patch.

  • Because identity is Entra ID, so the ERP inherits its gaps. Two of the most common real compromise paths are admin-plane access through Lifecycle Services or the Business Central Admin Center, and over-granted service principals. Conditional access that covers the ERP but excludes Power Apps and Power Automate is a routine finding.

  • No. We agree lockout thresholds up front, avoid period close, payroll, and payment-run windows, and run business-process scenarios against agreed test data with a written stop line. Where production is in scope we coordinate directly with your ERP and identity teams throughout.

  • Book a 30-minute scoping call. We identify which products, environments, and tenants are in scope, agree the rules of engagement, and define the right test. We also test SAP, Oracle ERP, and Salesforce.

Explore More Security Solutions

IntegSec provides specialized offensive security testing across the platforms and industries that run your business.

Group 2085662916 (4)-3

SAP & ERP Security

Penetration testing for S/4HANA, NetWeaver, RFC, Fiori, and HANA, plus business control review.

Group 2085662916-3

Oracle ERP Security

Penetration testing for E-Business Suite, PeopleSoft, JD Edwards, and Fusion Cloud ERP.

Group 2085662916 (2)-3

Salesforce Security

Penetration testing and security reviews for Salesforce orgs, Apex, and Experience Cloud.

Group 2085662916 (6)-2

SaaS & Technology

SOC 2-ready vulnerability assessments and penetration testing for software companies.

Test the System That Runs Your Business

Microsoft already permits it. Find the exploitable paths into your Dynamics estate before an attacker does. Book a 30-minute scoping call with IntegSec's ERP security experts. No prep needed.