Skip to main content

Microsoft Dynamics GP System Administrator: Should You Separate Accounting Controls and Duties?

by Gloria Braunschweig
President, Dorian Enterprises, Computeration, Inc.

[Ed. - this story has been updated to reflect Microsoft's guidance on security and administration for Microsoft Dynamics GP]

Over the years, we've had questions from larger clients about the Microsoft SQL "SA" (System Administrator) user.  The SA users, or other users attributed with system administration capabilities, are POWERUSERS inside SQL Enterprise, even to the point of enabling the editing of tables. As Microsoft's security planning guide for Dynamics GP (last updated in 2007) explains, "any user who is assigned to the POWERUSER security role will have access to everything in Microsoft Dynamics GP, with the exception of private lists."1  That means POWERUSERS, usually SA barring other changes to user security, have access or can grant themselves access to all tables and operations in Dynamics GP.  Certain operations can only be performed by POWERUSERS, per the listing below.

DYNSA is created by Dynamics Utilities and assigned to the POWERUSER security role during the initial installation of Dynamics GP and set as the "db_owner" of the Dynamics and company databases.  If that ownership is changed prior to or during upgrades, the upgrades will fail.  As Microsoft's security documentation explains, "[i]f different owners are assigned, complications can arise when deleting user accounts and granting access to companies."2

Auditors point out that the broad access privileges of administrators like an SA user must be carefully managed and tracked. One all-powerful user with no accountability to auditors is unacceptable in view of accounting controls and separation of duties. With Dynamics GP, the accounting department must take charge of the system and invoke the typical auditing of the ERP software: balancing, testing, reconciling, and verification with outside sources.

Microsoft Dynamics GP's module Audit Trails sets up a separate SQL ...

FREE Membership Required to View Full Content:

Joining MSDynamicsWorld.com gives you free, unlimited access to news, analysis, white papers, case studies, product brochures, and more. You can also receive periodic email newsletters with the latest relevant articles and content updates.
Learn more about us here

About Gloria Braunschweig

Gloria has experience across the full spectrum of business operations and management. Decades of experience are documented in the book Rapid Implementation, establishing Gloria as a specialists using Microsoft SQL tools for implementation, integration, and business intelligence related to Microsoft Dynamics GP.

Gloria writes and presents on lean implementation concepts and business management systems for small and mid-size businesses.