Integration
Fincore Connector for Dynamics 365 Finance & Operations
Least-privilege, read-only access to your F&O financial data for close and reconciliation workflows.
What the connector reads
Fincore connects to your Dynamics 365 Finance & Operations (cloud) environment to read the financial data required for close and reconciliation workflows — general ledger transactions, your chart of accounts, and supporting reference data. Access is defined by a published permission specification of 46 read-only entity grants covering:
- Chart of accounts and ledger setup, fiscal calendars, and currencies with exchange rates.
- Financial dimensions and account–dimension combinations.
- Posted general ledger entries and pre-aggregated ledger balances.
- Accounts receivable and accounts payable — invoices, transactions, settlements, and payment journals.
- Product and employee reference data for transaction enrichment.
Nothing outside the specification is readable, and the connector holds no write, post, setup, or administrative permissions of any kind.
Security model
- Read-only by construction. The security role contains a single read-only privilege over the specified entities — no standard business roles, no administrative permissions.
- Service-to-service OAuth 2.0 (client credentials). No interactive user login. Fincore owns and rotates the application credential — you never hold, store, or rotate a client secret.
- Nothing installed. Your administrator builds the security role in your own environment from Fincore's specification, so nothing authored outside your organization needs to be installed.
- Auditable by design. All connector activity executes as a dedicated integration service user, cleanly separated from human users in your logs.
- Scoped to the legal entities you choose. You control which companies are in scope, and Fincore verifies the connector sees exactly that set.
- Revocable in minutes. Disable the service user, remove the application binding, or revoke admin consent in your Entra tenant — each takes effect within minutes.
How onboarding works
Your administrators complete five setup steps — once per environment — followed by a joint automated verification. Fincore's onboarding guide, shared by your Fincore team, walks through each step in detail:
- Grant tenant-wide admin consent to Fincore's application in Microsoft Entra ID (Global Administrator). After approval, Microsoft Entra returns your administrator to Fincore's confirmation page showing your Directory (tenant) ID.
- Create and publish the Fincore Data Reader security role from the published specification.
- Create the integration service user, assign the role, and set company scope.
- Bind Fincore's application to the service user.
- Enter connection details in the Fincore portal.
- Automated verification — metadata retrieval, a sample read from every specified entity, a negative check confirming non-granted entities are denied, and confirmation that visible legal entities match your declared scope.
Operational fit
- The connector honors F&O throttling responses (HTTP 429 with Retry-After) and can schedule synchronization outside your peak processing windows on request.
- Recommended rollout is a test/UAT environment first, then production, using the same specification.
- If a future Fincore capability requires additional entities, Fincore publishes a versioned, delta-highlighted specification update — nothing changes without your administrator's action.
Questions
Your Fincore team shares the full onboarding and security guide — including the permission specification — during onboarding. For security documentation, the SOC 2 report, or the security packet (data processing locations, retention, sub-processors, and DPA), contact support@fincore.ai or see the Trust Center.