Microsoft Dynamics GP System Administrator: Should You Separate Accounting Controls and Duties?
[Ed. - this story has been updated to reflect Microsoft's guidance on security and administration for Microsoft Dynamics GP]
Over the years, we've had questions from larger clients about the Microsoft SQL "SA" (System Administrator) user. The SA users, or other users attributed with system administration capabilities, are POWERUSERS inside SQL Enterprise, even to the point of enabling the editing of tables. As Microsoft's security planning guide for Dynamics GP (last updated in 2007) explains, "any user who is assigned to the POWERUSER security role will have access to everything in Microsoft Dynamics GP, with the exception of private lists."1 That means POWERUSERS, usually SA barring other changes to user security, have access or can grant themselves access to all tables and operations in Dynamics GP. Certain operations can only be performed by POWERUSERS, per the listing below.
DYNSA is created by Dynamics Utilities and assigned to the POWERUSER security role during the initial installation of Dynamics GP and set as the "db_owner" of the Dynamics and company databases. If that ownership is changed prior to or during upgrades, the upgrades will fail. As Microsoft's security documentation explains, "[i]f different owners are assigned, complications can arise when deleting user accounts and granting access to companies."2
Auditors point out that the broad access privileges of administrators like an SA user must be carefully managed and tracked. One all-powerful user with no accountability to auditors is unacceptable in view of accounting controls and separation of duties. With Dynamics GP, the accounting department must take charge of the system and invoke the typical auditing of the ERP software: balancing, testing, reconciling, and verification with outside sources.
Microsoft Dynamics GP's module Audit Trails ...
FREE Membership Required to View Full Content:
Joining MSDynamicsWorld.com gives you free, unlimited access to news, analysis, white papers, case studies, product brochures, and more. You can also receive periodic email newsletters with the latest relevant articles and content updates.
Learn more about us here