Join our Newsletter — 33% off our NHI Course

What happens when Microsoft Dynamics access reviews are not automated across connected systems?

When reviews stay manual, organisations struggle to see who truly has access across Microsoft Dynamics and linked ERP, CRM, and finance systems. The result is delayed revocation, inconsistent approvals, and a growing attack surface. Sensitive business and customer data becomes easier to expose, while compliance teams lose the evidence needed to demonstrate controlled access over time.

Why manual Dynamics access reviews create hidden control debt

When reviews stay manual, the biggest problem is not just effort, it is drift. Access granted in Microsoft Dynamics often propagates through linked ERP, CRM, and finance systems, so reviewers end up checking fragments instead of the full entitlement picture. That makes it easy for stale, excessive, or duplicated access to survive multiple review cycles without being challenged.

Manual review processes also tend to rely on snapshots, spreadsheets, and inbox approvals. Those artefacts are useful for a one-off attestation, but they rarely keep pace with role changes, shared accounts, system integrations, or delegated admin paths. The result is that access can look approved on paper while actual business reach remains broader than intended.

Where the environment includes multiple business systems, lifecycle coordination matters more than the individual review event. If one platform is cleaned up while another remains untouched, the organisation still carries the same exposure. The relevant control question is whether review findings trigger consistent change across every connected system that can use the same user or service access path.

  • Automated review coverage reduces the chance that inherited access from a source system is missed in a downstream application.
  • Consistent evidence is easier to retain when review outcomes, approvers, and remediation timestamps are captured in a repeatable workflow.
  • Cross-system visibility matters most when finance or customer data can be reached through more than one entitlement layer.

How access review gaps expand exposure across ERP, CRM, and finance

The practical failure mode is cumulative privilege. A user may no longer need access in one business function, yet still retain it in another connected system because the revocation workflow is delayed or never reconciled. Over time, this raises the chance of unauthorized viewing, improper transaction activity, and silent overexposure of sensitive records.

Manual review also weakens governance because it makes exceptions easier to normalise. Once reviewers see the same names and the same approved access patterns month after month, stale entitlements can start to feel routine. That is especially risky in systems that carry payroll, billing, customer, or revenue data, where even a small access mismatch can have outsized impact.

For practitioner context, NHIMG’s Ultimate Guide to NHIs is useful here because the same lifecycle and visibility discipline applies to business access paths that must be discovered, reviewed, and removed reliably over time. The point is not the label of the identity, it is whether access is continuously governed instead of intermittently attested.

  • Delayed revocation is the usual operational weak point, because approval and removal often live in different queues.
  • Overprivilege becomes harder to spot once access is spread across several systems with inconsistent role models.
  • Audit defensibility drops when the organisation cannot show what changed after the review, not just who clicked approve.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Management Connected-system reviews must remove stale access paths and credentials.
NHI-02 — Lifecycle and Offboarding Manual reviews fail when access is not removed consistently across system lifecycles.
NHI-03 — Visibility and Discovery Cross-platform access review depends on knowing where access actually exists.
Recommendation — Automate recertification and revoke stale credentials and entitlements across integrated systems. Tie access review outcomes to automated offboarding and deprovisioning workflows. Inventory all access-bearing systems and continuously discover hidden or inherited entitlements.
CIS Controls v8 6.3 — Access Control Management Automated review supports consistent removal of unnecessary access.
6.4 — Account Management Manual processes often miss account changes across connected systems.
Recommendation — Enforce periodic access reviews and promptly remove unneeded accounts and privileges. Synchronize account lifecycle changes and deprovision access in all connected applications.
NIST CSF 2.0 PR.AC-4 — Access Permissions Management The issue is excessive or stale permissions across business systems.
GV.RM-03 — Risk Management Strategy Cross-system review gaps create governance and exposure risk.
RS.MA-1 — Incident Management Process Delayed revocation increases the time exposure remains active after detection.
Recommendation — Review permissions regularly and remove access that is no longer required. Define and enforce a repeatable access-review process for all connected platforms. Use automated workflows so remediation follows review findings without unnecessary delay.
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Controlled access decisions rely on reliable identity evidence and lifecycle checks.
AAL2 — Authenticator Assurance Level 2 Persistent access should be paired with stronger authentication where business risk is high.
Recommendation — Require strong identity evidence before granting or retaining sensitive access. Use stronger authenticators for high-value systems and review their continued necessity.

Practitioner Guidance

What to prioritise: Treat connected-system review as one control problem, not separate reviews for each application. The first operational objective is to make sure the review output can drive revocation everywhere the access is effective, including downstream ERP, CRM, and finance permissions.

What to verify: Confirm that review evidence includes the entitlement owner, the approver, the date of decision, and the remediation status for each system touched by the access path. If your evidence cannot prove removal, it only proves acknowledgement.

Common mistake: Relying on manual certification to compensate for poor integration. Manual review can supplement governance, but it should not be the mechanism that discovers every stale entitlement in a connected environment.

Practitioner takeaway: If access reviews are not automated across linked systems, the organisation is usually measuring approval activity rather than true access reduction, which leaves the real attack surface intact.