The D365 F&O Telemetry Gap — Why Role Assignments Alone Are Lying to You About License Costs
Your D365 roles tell you what users can do. Telemetry tells you what they actually do. That gap is costing you money every month. Discover how to close it using Application Insights usage data.
A department head requested elevated access during a quarterly audit crunch.
The crunch ended. The access stayed.
Six months later, nobody remembered why that user held an expensive Finance license, and nobody thought to ask because day-to-day operations ran without a hitch.
This scenario plays out in enterprise ERP environments across the GCC and the UK every single week.
Organizations invest heavily in role cleanup, yet their monthly software bills remain stubbornly high. The reason is simple: they are optimizing against what users can do, completely blind to what they actually do.
The Fundamental Problem: Rights Versus Reality
In Microsoft Dynamics 365 Finance & Operations, standard licensing models bill organizations based on assigned access security roles rather than actual system utilization.
If a user is attached to a Finance or Supply Chain Management role, Microsoft's licensing validation engine assumes they require that premium tier.
But roles describe potential, not reality.
When your access controls grant expansive permissions that go entirely untouched, that structural gap translates directly into cash leaving your organization every single month.
Your CFO sees an enterprise license fee; your operations team sees a functional safety net. Neither sees the waste sitting directly in the middle.
Assigned Versus Actual: The Cost of Inaction
Consider a standard enterprise profile: a regional logistics clerk assigned a comprehensive Finance tier role.
Telemetry reveals that this user opens the application twice a month to pull a single inventory status report.
Functionally, that isolated activity requires nothing more than a Team Member access level.
Yet because the legacy role assignment remains unadjusted, the business continues paying top-tier subscription rates.
The monthly license cost is real, but the operational justification is entirely fictitious. Across fifty bloated accounts, that single oversight drains tens of thousands of pounds or dirhams annually.
Why Entra ID Sign-In Data Will Fool You
Many internal IT teams attempt to audit utilization using basic identity provider records from Microsoft Entra ID.
This is a critical mistake.
OAuth token refreshes and background API integrations keep account activity looking completely fresh, even when a human user has not opened the D365 client interface in six months.
Relying on identity provider timestamps creates a false sense of security.
Accurate inactivity detection requires application-level telemetry. You need to see what is happening inside the ERP boundary, not just at the tenant login gate.
Object-Level Usage and Application Insights
True visibility lives in Application Insights.
Page view and event tracking capture the specific forms, workspaces, and menu items users navigate to during their daily routines.
Over a thirty-to-ninety-day window, this data builds an undeniable behavioral footprint of your user base.
You can see precisely which business processes are executed daily, and more importantly, which modules of an assigned role remain untouched.
When telemetry proves an assigned role spans Accounts Payable, Procurement, and General Ledger, but the user exclusively touches AP invoice entry forms, you have objective, data-driven proof for a license downgrade.
Accessing Telemetry for License Optimization
Extracting and analyzing this data does not require a data science degree, but it does require moving beyond standard ERP menus.
By connecting your D365 environment to Azure Application Insights, your technical architects can query Kusto Query Language (KQL) logs to map user principal names directly against menu item usage events.
These queries isolate idle accounts, identify redundant privilege clusters, and map exact software footprints.
For teams without dedicated KQL bandwidth, specialized third-party Governance, Risk, and Compliance (GRC) tools—such as Fastpath Assure—pull these telemetry metrics into purpose-built executive dashboards, surfacing optimization targets automatically.
The Triple Convergence: Cost, Audit, and AI
Ignoring the telemetry gap is no longer just an expensive line item; it is an escalating operational hazard.
Three powerful enterprise pressures are converging on ERP security:
- Financial Waste: License validation audits enforce rigid tier assignments based on raw role definitions.
- Audit Exposure: Over-provisioned accounts create toxic Segregation of Duties conflicts that fail ITGC compliance reviews.
- AI Risk: As organizations deploy intelligent agents and Microsoft Copilot across their tenants, over-provisioned service identities give AI tools expansive, unmonitored reach into sensitive financial records.
Identity without telemetry-backed constraints leaves your entire financial ledger exposed.
Best Practice: Telemetry as a Mandatory Review Input
Periodic access reviews must evolve.
Treating access reviews as a routine checkbox exercise where managers simply click "approve" on existing roles guarantees continuous financial waste.
Telemetry must become a mandatory prerequisite input for every role modification decision.
Before an IT director signs off on a role change or re-licenses an employee for another year, the underlying Application Insights usage report should dictate the tier.
Data must override assumption.
The Additional Business Case
When businesses implement a telemetry-driven license review alongside traditional role rationalization, the financial returns accelerate rapidly.
While structural role cleanup typically recovers initial spend, incorporating actual usage telemetry unlocks an additional 10 to 20 percent in hidden license cost recovery.
You stop paying for phantom operational capacity, satisfy external auditors with empirical proof of compliance, and align your software expenditure strictly with operational reality.
Ready to Close Your Telemetry Gap?
Stop guessing your license requirements based on outdated role assignments. Visit sajeedmullaji.com to discover how telemetry-driven security governance can permanently reclaim your ERP software budget.
Frequently Asked Questions
Q: Why can't we just rely on standard Entra ID sign-in logs to identify inactive D365 users?
A: Entra ID logs record background token refreshes and automated service integrations, making inactive user accounts appear active. Application Insights tracks actual user navigation inside the D365 application interface, ensuring you only pay for human users actively interacting with ERP forms.
Q: Will downgrading a user's license tier based on telemetry data disrupt their day-to-day work?
A: No, because telemetry identifies what tasks the user actually performs rather than what their bloated role allows. Downgrades are only executed after isolating those verified operational duties into a right-sized, purpose-built custom role.
Q: How frequently should IT audit teams pull Application Insights usage data for license reviews?
A: Usage data should be evaluated on a quarterly basis to capture seasonal workload shifts and employee turnover. Reviewing telemetry quarterly ensures that temporary elevated access is stripped before it converts into permanent, expensive license waste.