Skip to main content

Integration

Fincore Connector for Dynamics 365 Finance & Operations

Least-privilege, read-only access to your F&O financial data for close and reconciliation workflows.

Read-only accessNothing installed in your environment

What the connector reads

Fincore connects to your Dynamics 365 Finance & Operations (cloud) environment to read the financial data required for close and reconciliation workflows — general ledger transactions, your chart of accounts, and supporting reference data. Access is defined by a published permission specification of 46 read-only entity grants covering:

  • Chart of accounts and ledger setup, fiscal calendars, and currencies with exchange rates.
  • Financial dimensions and account–dimension combinations.
  • Posted general ledger entries and pre-aggregated ledger balances.
  • Accounts receivable and accounts payable — invoices, transactions, settlements, and payment journals.
  • Product and employee reference data for transaction enrichment.

Nothing outside the specification is readable, and the connector holds no write, post, setup, or administrative permissions of any kind.

Security model

  • Read-only by construction. The security role contains a single read-only privilege over the specified entities — no standard business roles, no administrative permissions.
  • Service-to-service OAuth 2.0 (client credentials). No interactive user login. Fincore owns and rotates the application credential — you never hold, store, or rotate a client secret.
  • Nothing installed. Your administrator builds the security role in your own environment from Fincore's specification, so nothing authored outside your organization needs to be installed.
  • Auditable by design. All connector activity executes as a dedicated integration service user, cleanly separated from human users in your logs.
  • Scoped to the legal entities you choose. You control which companies are in scope, and Fincore verifies the connector sees exactly that set.
  • Revocable in minutes. Disable the service user, remove the application binding, or revoke admin consent in your Entra tenant — each takes effect within minutes.

How onboarding works

Your administrators complete five setup steps — once per environment — followed by a joint automated verification. Fincore's onboarding guide, shared by your Fincore team, walks through each step in detail:

  1. Grant tenant-wide admin consent to Fincore's application in Microsoft Entra ID (Global Administrator). After approval, Microsoft Entra returns your administrator to Fincore's confirmation page showing your Directory (tenant) ID.
  2. Create and publish the Fincore Data Reader security role from the published specification.
  3. Create the integration service user, assign the role, and set company scope.
  4. Bind Fincore's application to the service user.
  5. Enter connection details in the Fincore portal.
  6. Automated verification — metadata retrieval, a sample read from every specified entity, a negative check confirming non-granted entities are denied, and confirmation that visible legal entities match your declared scope.

Operational fit

  • The connector honors F&O throttling responses (HTTP 429 with Retry-After) and can schedule synchronization outside your peak processing windows on request.
  • Recommended rollout is a test/UAT environment first, then production, using the same specification.
  • If a future Fincore capability requires additional entities, Fincore publishes a versioned, delta-highlighted specification update — nothing changes without your administrator's action.

Questions

Your Fincore team shares the full onboarding and security guide — including the permission specification — during onboarding. For security documentation, the SOC 2 report, or the security packet (data processing locations, retention, sub-processors, and DPA), contact support@fincore.ai or see the Trust Center.