You can appoint a user as a stand-in for another user for a specified period. For example, if a user has a vacation, you can appoint a stand-in during this vacation. For auditing purposes, you cannot delete stand-in records with periods in the past.


Security administrator Security administrator The security administrator (SysSecSecurityAdministrator) maintains user and security setup in D365 F&SCM, grants the ability to create and maintain security roles, duties, and privileges and the ability to assign users to roles, define role assignment rules, and maintain data security policies. Appoint stand-ins Appoint stand-ins You can appoint a user as a stand-in for another user for a specified period. For example, if a user has a vacation, you can appoint a stand-in during this vacation. For auditing purposes, you cannot delete stand-in records with periods in the past. Procedure 1. Click Security management. 2. Click the Stand-in tab. 3. Click New. 4. In the User field, enter or select a value. 5. In the Stand-in field, enter or select a value. 6. In the From date field, enter a date. 7. In the To date field, enter a date. 8. Select or clear the Copy assigned organizations check box. 9. Close the page. Validate segregation of duties for stand-in Validate segregation of duties for stand-in You can set up rules to separate tasks that must be performed by different users. This concept is named segregation of duties.If you use segregation of duties rules, you can validate if the assignment of the user roles to the stand-in user complies with the segregation of duties rules.If assigning the user roles to the stand-in violates the segregation of duties rules, a message is displayed with the name of the role and the names of the conflicting duties. The security administrator must either indicate the mitigation for the security risk or modify the conflicts so that segregation of duties rules are not violated. If no rules are violated, a message indicates that the stand-in role complies with the segregation of duties rules. Note: If enhanced segregation of duties rules are enabled, the stand-in role assignment is validated against the enhanced segregation of duties rules. Procedure 1. Click Security management. 2. Click the Stand-ins tab. 3. Click Edit. 4. In the list, find and select the desired record. 5. Click Validate SoD rules. Note: Check the resulting messages. If violations are indicated, solve these violations. 6. Close the page. Start Start Assign stand-in roles Assign stand-in roles If you have set up stand-ins, the actual assignment of the required security setup is only done for the defined period. Use the Assign stand-in roles batch job to do the actual assignment. This batch job activates and deactivates the required security setup for the stand-ins: If the current date is the From date, the security setup is activated for the stand-in. As a result, the security setup of the user who is substituted is merged with the security setup of the stand-in. If the current date is past the To date, the security setup is deactivated for the stand-in. As a result, the security setup merge is undone. Notes: The security setup of the substituted user stays unchanged. If the stand-in has already (partially) the same security setup as the substituted user, this security setup isn't changed on activation or deactivation. You are advised to run this batch job daily. Preferably, before working hours. For example, run the batch job at 00:01. Procedure 1. Go to Security and compliance > Periodic tasks > Assign stand-in roles. 2. Expand the Run in the background section. 3. Select Yes in the Batch processing field. 4. Sub-task: Set recurrence. 5. Click Recurrence. 6. In the Start date field, enter a date. 7. In the Start time field, enter '00:00:01'. 8. Select the No end date option. 9. In the Recurrence pattern field, enter 'Days'. 10. Select the Every weekday option. 11. Click OK. 12. Click OK. Do you use  segregation of duties  rules? Do you use  segregation of duties  rules? End End Yes No

Activities

Name Responsible Description

Appoint stand-ins

Security administrator

You can appoint a user as a stand-in for another user for a specified period. For example, if a user has a vacation, you can appoint a stand-in during this vacation.
For auditing purposes, you cannot delete stand-in records with periods in the past.

Validate segregation of duties for stand-in

Security administrator

You can set up rules to separate tasks that must be performed by different users. This concept is named segregation of duties.
If you use segregation of duties rules, you can validate if the assignment of the user roles to the stand-in user complies with the segregation of duties rules.
If assigning the user roles to the stand-in violates the segregation of duties rules, a message is displayed with the name of the role and the names of the conflicting duties. The security administrator must either indicate the mitigation for the security risk or modify the conflicts so that segregation of duties rules are not violated. If no rules are violated, a message indicates that the stand-in role complies with the segregation of duties rules.
Note: If enhanced segregation of duties rules are enabled, the stand-in role assignment is validated against the enhanced segregation of duties rules.

Assign stand-in roles

Security administrator

If you have set up stand-ins, the actual assignment of the required security setup is only done for the defined period. Use the Assign stand-in roles batch job to do the actual assignment. This batch job activates and deactivates the required security setup for the stand-ins:
  • If the current date is the From date, the security setup is activated for the stand-in. As a result, the security setup of the user who is substituted is merged with the security setup of the stand-in.
  • If the current date is past the To date, the security setup is deactivated for the stand-in. As a result, the security setup merge is undone.
Notes:
  • The security setup of the substituted user stays unchanged.
  • If the stand-in has already (partially) the same security setup as the substituted user, this security setup isn't changed on activation or deactivation.
You are advised to run this batch job daily. Preferably, before working hours. For example, run the batch job at 00:01.

Provide feedback