D365 Audit
Use case

Dynamics 365 solution review

You are about to take over a solution someone else built, or you need to judge its condition before a decision is made. There is rarely any documentation, and access to the environment usually comes later. D365 Audit reads the solution export and shows you where the risks are right after the upload.

For consultants taking over a project, IT managers who have to make a call, partners scoping a quote and anyone assessing a solution as part of due diligence.

What is checked

Data model and deletion risks

Relationships that cascade deletes onto custom tables, and fields or tables that still carry the default prefix "new_".

ENT-009REL-003FLD-001ENT-001

Security roles

Roles with organization-wide delete rights, roles with identical privileges and roles that hold far more privileges than the rest.

SEC-001SEC-010SEC-014

Plugins

Synchronous plugin steps without filtering attributes, assemblies running outside the sandbox and plugin code that calls external services.

PLG-001PLGA-001PLG-011

JavaScript

The deprecated "Xrm.Page" API, "eval()" in the code and hard-coded GUIDs.

JS-001JS-012JS-013

Automation

Classic and real-time workflows, flows that call Dataverse inside loops, and tables whose logic is spread across three or more technologies.

WF-001WF-003FLOW-005ENT-013

Form performance

Forms with a very high control count on the first tab and a poor rating for load time.

FRM-002PERF-001

Outbound connections

Service endpoints and custom connectors without encryption, and direct HTTP calls in flows.

SEP-001CCON-002FLOW-002

Documentation

Fields, tables, plugin steps and workflows without a description, often the first hurdle in a handover.

FLD-003ENT-003PLG-002WF-005

Sample findings

This is how findings appear in the report: component, rule, severity and the note behind it.

Workflow "Opportunity - Close as lost" WF-003 High

Synchronous/real-time. Verify manually whether the logic is a performance risk.

From the sample report
Table "Lead" ENT-009 High

1 relationship(s) with CascadeDelete=Cascade on at least one custom side. Deleting a record of this entity automatically deletes related records.

From the sample report
Form "Account" FRM-002 High

56 controls in the (assumed) default tab. Performance risk, verify on the form.

From the sample report

Open the full sample report (PDF)

How it works

The export only. You upload the ZIP file Power Apps creates when you export a solution. Nothing else is needed.
No access to your environment. D365 Audit never connects to your Dataverse tenant: no app registration, no API permissions, no service account.
Raw data deleted right away. The uploaded ZIP and the extracted files are deleted immediately after the analysis. Reports are kept for a limited time only, for the download.
Rules, not AI. The analysis is deterministic code. The same solution always gives the same result, and no content is sent to an AI model.
Hosted in Frankfurt. The server is in the EU, Frankfurt region. Uploaded solutions never leave it.

Details on security and privacy

Frequently asked questions

Do I need access to the environment?

No. The check works on the solution export only, the ZIP file Power Apps creates when you export a solution. The previous maintainer or your client can create the export and send it to you.

Does it work with managed solutions?

Yes. Unmanaged exports are evaluated in full. Managed exports are checked as well, and the report points out that some governance checks carry less weight there.

What can the report not see?

Anything that is not part of the export: the data itself, usage figures and environment settings, for example whether auditing is switched on for the whole environment. The report says explicitly where something has to be checked separately.

What does the review cost?

The key figures are free after the upload. You then decide whether you want the full report; the packages are shown on the results page.