Reviews and corrects ledger-to-subledger alignment in D365 by fixing posting configurations, inventory profiles, reconciliation logic, GL mapping, and critical reporting procedures.
Your D365 License Bill Might Be a Security-Role Problem.
Posted on: September 30, 2026 | By: Heather Zhu | Microsoft Dynamics AX/365, Microsoft Dynamics AX/365|Microsoft Dynamics Manufacturing
Access & Licensing / Finance + Supply Chain
Before you buy more licenses, find out whether yesterday’s access still belongs in today’s job.

An Illustrative Budget-Room Question
“Why does someone in the warehouse need a Finance license?”
Picture a distributor reviewing next year’s budget. A warehouse employee once covered a colleague’s tasks, received extra access, and kept it long after the handoff. Nobody designed a licensing strategy. They were trying to ship Friday’s orders.
That illustrative scenario is worth investigating, not treating as proof of overcharging. Microsoft’s commercial-cloud license validation follows staged contract renewal or anniversary timing. Check your own notices rather than assuming everyone shares a deadline.
The useful question is what the person can access. Microsoft’s reporting connects assigned security roles and their permissions to license requirements. Role names alone do not settle entitlement, and access spanning applications may require a base license plus eligible attach licenses.
The Fit Problem Is Not New
“It is very common that the default security roles do not fit every user and the tasks that they need to perform.”
Kelly Neely, Logan Consulting | November 2017
The Practical Bit
Start with one person, not a purchase order.
01
Follow one unexpected requirement.
In a supported environment, open System administration > Security > Security Governance > License usage summary. The report requires version 10.0.43 or later and the relevant features enabled. Start with the user, then inspect the roles, duties, privileges and underlying security objects driving the requirement. A menu item and its access level tell you more than a reassuring job title.
02
Test the job before trimming access.
Ask the process owner what must still work, including occasional duties. In a sandbox, test a narrower role against real tasks: receiving stock, correcting an exception, completing an approval. Record the result. Removing permission is easy. Discovering at month-end that someone still needed it is less charming.
03
Reconcile before purchasing.
The in-app report describes one environment. Power Platform admin center provides the wider view across connected environments, including sandboxes, and compares required, purchased and assigned licenses. Resolve the access question, confirm the appropriate licensing, then make assignments through Microsoft 365 admin center. The reports do not make those assignments for you.

A decision path, not a license calculator. Evaluate the user’s complete access and applicable product terms.
The evidence to keep
- Business duty
- Permission driving the requirement
- Owner
- Test result
- Next review date
Accuracy Trap
Security Governance changes typically take 2 to 8 hours to appear, and Power Platform reporting refreshes every 4 to 12 hours. Check timestamps before declaring the fix unsuccessful. Lower reported requirements do not automatically change subscription charges.
Logan POV
Do not make the license count look better by making the business work worse. Keep necessary approvals and separation of responsibilities. Use Logan’s custom-security walkthrough as background, then validate the design against today’s processes and current licensing terms. Sometimes the right answer is less access. Sometimes it is the license the person genuinely needs.
Executive Takeaway
License the work people need to do, not the permissions nobody remembered to remove.














