Native Dynamics 365 SoD controls identify and flag certain conflicts inside the ERP environment. An access governance solution goes further by enforcing policy across roles, workflows, and reviews, often with stronger automation and oversight. In practice, the ERP control is a useful starting point, but governance tooling is better suited to sustained control management.
Native ERP segregation of duties is a control check, not a governance programme
Dynamics 365 SoD controls are designed to detect and flag conflicting duties inside the ERP application. That makes them useful for preventing obvious toxic combinations, but they are usually bounded by the roles, transactions, and conflict rules defined in that system. By design, they are narrower than an enterprise access governance layer that tracks ownership, approvals, exceptions, and review evidence over time.
The practical difference is scope and persistence. A native ERP control can tell you that a user can both create and approve a transaction, or that a role combination violates a rule, but it does not by itself run the full governance lifecycle around that access. If you need policy enforcement across role design, request workflows, recertification, and exception handling, you are already in access governance territory. That is why identity lifecycle and access review capabilities matter in a broader control model, as described in the NHI Lifecycle Management Guide and the Ultimate Guide to NHIs, Regulatory and Audit Perspectives.
Native controls also tend to be less effective when the problem is not a single toxic role pair but a pattern of access drift. Once privileges accumulate across users, service accounts, or delegated admin paths, a point-in-time ERP rule check is no longer enough to manage the exposure. That is where broader governance tooling is stronger, because it can reconcile actual access against policy, not just test one application’s internal conflict matrix. Ultimate Guide to NHIs, Key Challenges and Risks is useful here because it frames why visibility, overprivilege, and unmanaged access become operationally hard to sustain without lifecycle controls.
Access governance solutions, by contrast, are built to manage the control loop. They usually combine access request approval, policy evaluation, periodic review, evidence retention, and exception management so the organisation can prove it is not only detecting conflicts but actively governing them. In practice, that means the governance tool becomes the system of record for who approved access, why it was allowed, when it must be reviewed again, and whether the exception still exists.
That difference matters most where auditors, risk teams, and control owners need repeatable proof, not just a warning banner inside the ERP. Native SoD can support control design, but governance tooling supports control operation. If the business question is “can the ERP identify a toxic combination,” the native feature may be sufficient. If the question is “can we continuously manage segregation, exceptions, and evidence across the access lifecycle,” the answer usually requires an access governance platform.
Where the control boundary breaks down in real operations
The biggest limitation of native Dynamics 365 SoD is that it often stops at detection. It can surface a conflict, but the organisation still has to decide who investigates, who approves an exception, whether the access should be remediated, and how the evidence is retained for later review. That manual overhead becomes expensive when access changes frequently or when multiple business units interpret the same rule differently.
Access governance solutions reduce that operational ambiguity by standardising policy enforcement across roles and reviews. They are especially valuable when access spans more than one business process, when the same user holds multiple roles, or when compensating controls must be tracked alongside the conflict. In that environment, a native ERP alert without a workflow can leave too much room for exceptions to become permanent.
The difference also shows up in reporting quality. Native SoD reports often answer “what conflicts exist today,” while governance tools answer “what changed, who approved it, and what is still outstanding.” That is the distinction that matters when you need to demonstrate sustained control rather than a one-time configuration check.
For readers evaluating whether their current setup is enough, the right test is whether the organisation can evidence review, approval, and remediation over time, not whether the ERP can identify a conflict at all. If the answer depends on spreadsheets, ad hoc emails, or manual reconciliations, then the control is operationally weaker than it first appears.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Controls role and account access across an organisation, beyond a single ERP SoD check. |
| 5 — Account Management | Supports governed lifecycle handling of accounts and role changes that SoD alone does not manage. | |
| 8 — Audit Log Management | Governance tooling needs evidence of approvals, exceptions, and review actions for control assurance. | |
| Recommendation — Standardise access approvals, reviews, and revocations outside the ERP. Centralise account lifecycle oversight and recertification evidence. Retain approval and review logs that prove access decisions were enforced. | ||
| NIST CSF 2.0 | PR.AA-01 — Identities and credentials are managed for authorized devices and users | Access governance depends on managed identities and controlled access paths, not only ERP conflict flags. |
| PR.AA-05 — Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties | Directly aligns with segregation of duties and broader authorization governance. | |
| GV.RR-01 — Roles, responsibilities, and authorities to manage risk are established, communicated, and coordinated | Access governance is about ownership and accountability for access decisions over time. | |
| Recommendation — Manage identities and access paths so SoD decisions remain enforceable. Enforce least privilege and SoD together across role and review processes. Assign clear ownership for access approvals, exceptions, and reviews. | ||
Practitioner Guidance
What to verify: Check whether the native Dynamics 365 rule set only flags toxic combinations, or whether it also supports workflow, exception tracking, and recurring recertification. If those governance steps sit outside the ERP, the control is detection-led rather than lifecycle-led.
Decision rule: Use native SoD when the requirement is limited to finding obvious conflicts inside one application. Use access governance when the control objective includes sustained policy enforcement, auditability, and accountability for approvals and exceptions.
What practitioners underestimate: The hard part is rarely identifying a conflict. It is keeping access aligned after role changes, mergers, emergency grants, and exceptions, while still producing defensible evidence for audit and control owners.
Practitioner takeaway: Native ERP SoD is a useful control point, but access governance is the operating model that keeps segregation enforceable, reviewable, and auditable as access changes over time.
Related resources from NHI Mgmt Group
- What is the difference between native platform access controls and identity-centric data governance for Snowflake?
- What is the difference between SoD and sensitive access controls?
- What is the difference between centralised PAM and cloud-native privileged access governance?
- What is the difference between customer login controls and API access governance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org