Marva,
The sys admin role is a tricky one. From a system access perspective, it is not granting all security, it is a complete lack of security. So things like group membership, segregation of duties and most other AX security features are simply ignored. There are a few things that can be done to help alleviate these concerns.
The main reason a user needs sysadmin in 2012 is to get to the development environment. Most would argue this should not be allowed in a production system and I agree, to a degree. Sometimes troubleshooting in prod is the only way to see how a specific issue is occurring. This should be a rare occurrence. For all other access (like user admin, database maintenance, etc.) a security group could be built to limit access to just the features a sysadmin needs. Once there is an actual role (and not sysadmin) then all the security features kick in and you should be good. This may take some time to create, but it is the most reliable solution.
If users need get into the dev environment, have a process for requesting and logging the grant, making sure to revoke when done.
If a dedicated role wont work and sysadmin has to stay in place, consider turning on database logging for the processes that cause concern. Send a manager an alert every time a new vendor is created, etc. You need to be careful with this one so you don't turn on logging for everything as it can cause system issues, but in limited scope in can work very well. Keep in mind a sysadmin can disable database logging in AX, so an external log (at the SQL level perhaps) may be needed here.
------------------------------
Scott Morley
------------------------------
Original Message:
Sent: 08-23-2018 01:10 PM
From: Robin Finnell
Subject: System Admins' Access Concerns
Hi Marva-
There was a discussion post a few days ago titled AX2012 R3 - Segregation of Duties regarding segregation of duties in AX/D365. Below is a link to the post.
Unified Operations & Dynamics AX Forum - Dynamics AX User Group
There were some very good responses that I think will address the question you have posed in this post. Hope this helps!
------------------------------
Robin Finnell
Continuous Improvement Coordinator
Operations Lead - D365FO/MES Implementation
Tillamook County Creamery Association
Tillamook
Original Message:
Sent: 08-23-2018 12:57 PM
From: Marva Dockery
Subject: System Admins' Access Concerns
Hi Everyone,
We are looking to address the concerns of our Accounting Team, regarding the IT System Admins' security role unfettered access, that could allow nefarious activities. One concern is the ability to create vendors then generate payments to themselves (via the vendors they created) without it being immediate recognized.
Can anyone share their process and controls, they have established, to mitigate this risk?
------------------------------
Marva Dockery
Ultimate Software
------------------------------