Segregation of Duties in the New Microsoft Dynamics AX

Posted on: October 18, 2016 | By: Jarrod Kraemer | Microsoft Dynamics AX/365

Authored by: Michael Row

Employees in many companies these days are asked to do many jobs. Dynamics AX administrators are tasked with assigning roles to the employees giving a user different duties and privileges within AX to be able to perform every day work. The use of the segregation of duties rules can aid in showing where a conflict exists when assigning a user to different roles.

In this example, I will add a rule to the segregation of duties rules in Dynamics AX that I know will cause a conflict. The rule will be maintaining vendor masters and maintaining purchase orders which the security risk is the employee could create a phony vendor and purchase from that vendor. The roles “Purchasing agent” and “Purchasing agent – Public Sector” both have the duties to maintain vendor master and Maintain purchase orders.

Navigate to the Segregation of duties rules.

One way to navigate in Dynamics AX is to type a keyword in the search bar. Click the link of the correct path.

Click new and create the criteria for the rule. In this example, the first duty is Maintain vendor master. The second duty is Maintain purchase orders. The security risk is Create a phony vendor and purchase from vendor.

Click on Validate duties and roles to see where the rule has a conflict.

When assigning the role to a user a warning will be shown.

The segregation of duty conflict can now be resolved by clicking yes or put in a queue of unresolved conflicts by clicking no. I will click yes to resolve now.

Click on Allow assignment and give a reason for the override.

The user now has the role Purchasing agent.

The segregation of duties rules can come in handy around audit time to check where conflicts exist or where a conflict has been resolved with a reason.

Another way to comply with the rule is to create a custom role that has many of the duties of the purchasing agent, but make the vendor master view only. The maintaining of the vendor master could be the duty of another department to ensure the security risk in avoided.

All the best! 
Logan Consulting 
www.loganconsulting.com