How Plex's flat, tenant-scoped, screen-oriented security model maps onto D365's bottom-up role → duty → privilege → entry-point hierarchy, Extensible Data Security and licence-linked access — and why the security design cannot be settled until the legal-entity decision is settled.
Part 1 of this domain settled the skeleton: legal entities, sites and warehouses. This chapter is about who is allowed to touch that skeleton, how you prove it, and what it costs.
Based on available evidence (secondary sources and the Postman-documented IAM API), Plex security appears to work as follows:
D365 security composes four levels above the entry points they secure. Unlike Plex's apparent top-down model (assign a role, role grants screens), D365's hierarchy is generated from the bottom up — starting from objects that already exist in the application.
The translation is not a mapping exercise. It is a rebuild from business process.
No segregation-of-duties mechanism was identified in any Plex source during the research pass. This does not mean Plex lacks one — it means the evidence is insufficient to confirm. Verify with the client's Plex administration team whether any SoD rules, conflict reports or compensating controls exist in their tenant.
D365 licence tier is not a static assignment. It is a continuous function of what a user's assigned roles can reach. The entry points a role's duties expose, at their granted access levels, determine the minimum licence tier for every user holding that role.
A Plex customer with Plex MES running on the shop floor may have hundreds of operator identities — workers who scan barcodes, report production completions, log quality inspections and consume materials. In Plex, these operators are users of the same tenant.
Regardless of whether Plex MES is retained or replaced, the organisation's identity provider should be unified. The recommended architecture:
D365 provides a dedicated workspace for security administration. The key tools relevant to a Plex translation:
A Plex tenant has a role called (hypothetically) "Purchasing Agent" that grants access to: RFQ creation, PO entry, supplier scorecard review and goods-receipt confirmation.
Plex's flat, tenant-scoped, screen-oriented security model does not project one-to-one onto D365's hierarchical, legal-entity-scoped, entry-point-gated model. The translation is a rebuild from business process, not a copy of role names.