Tenant-scoped IAM translated into the role, duty, privilege and entry-point model

How Plex's flat, tenant-scoped, screen-oriented security model maps onto D365's bottom-up role → duty → privilege → entry-point hierarchy, Extensible Data Security and licence-linked access — and why the security design cannot be settled until the legal-entity decision is settled.

What you will be able to do

Introduction

Part 1 of this domain settled the skeleton: legal entities, sites and warehouses. This chapter is about who is allowed to touch that skeleton, how you prove it, and what it costs.

Plex's security model: what we know and what we do not

Based on available evidence (secondary sources and the Postman-documented IAM API), Plex security appears to work as follows:

D365's security model: the bottom-up hierarchy

D365 security composes four levels above the entry points they secure. Unlike Plex's apparent top-down model (assign a role, role grants screens), D365's hierarchy is generated from the bottom up — starting from objects that already exist in the application.

The translation: Plex roles to D365 roles

The translation is not a mapping exercise. It is a rebuild from business process.

Segregation of duties

No segregation-of-duties mechanism was identified in any Plex source during the research pass. This does not mean Plex lacks one — it means the evidence is insufficient to confirm. Verify with the client's Plex administration team whether any SoD rules, conflict reports or compensating controls exist in their tenant.

Licence types and the cost of role design

D365 licence tier is not a static assignment. It is a continuous function of what a user's assigned roles can reach. The entry points a role's duties expose, at their granted access levels, determine the minimum licence tier for every user holding that role.

The identity-estate question: MES and QMS operators

A Plex customer with Plex MES running on the shop floor may have hundreds of operator identities — workers who scan barcodes, report production completions, log quality inspections and consume materials. In Plex, these operators are users of the same tenant.

Identity federation and SSO

Regardless of whether Plex MES is retained or replaced, the organisation's identity provider should be unified. The recommended architecture:

The Security Configuration workspace

D365 provides a dedicated workspace for security administration. The key tools relevant to a Plex translation:

Worked translation example

A Plex tenant has a role called (hypothetically) "Purchasing Agent" that grants access to: RFQ creation, PO entry, supplier scorecard review and goods-receipt confirmation.

Knowledge check

Summary

Plex's flat, tenant-scoped, screen-oriented security model does not project one-to-one onto D365's hierarchical, legal-entity-scoped, entry-point-gated model. The translation is a rebuild from business process, not a copy of role names.