Dynamics 365 solution review
You are about to take over a solution someone else built, or you need to judge its condition before a decision is made. There is rarely any documentation, and access to the environment usually comes later. D365 Audit reads the solution export and shows you where the risks are right after the upload.
For consultants taking over a project, IT managers who have to make a call, partners scoping a quote and anyone assessing a solution as part of due diligence.
What is checked
Data model and deletion risks
Relationships that cascade deletes onto custom tables, and fields or tables that still carry the default prefix "new_".
Security roles
Roles with organization-wide delete rights, roles with identical privileges and roles that hold far more privileges than the rest.
Plugins
Synchronous plugin steps without filtering attributes, assemblies running outside the sandbox and plugin code that calls external services.
JavaScript
The deprecated "Xrm.Page" API, "eval()" in the code and hard-coded GUIDs.
Automation
Classic and real-time workflows, flows that call Dataverse inside loops, and tables whose logic is spread across three or more technologies.
Form performance
Forms with a very high control count on the first tab and a poor rating for load time.
Outbound connections
Service endpoints and custom connectors without encryption, and direct HTTP calls in flows.
Documentation
Fields, tables, plugin steps and workflows without a description, often the first hurdle in a handover.
Sample findings
This is how findings appear in the report: component, rule, severity and the note behind it.
Synchronous/real-time. Verify manually whether the logic is a performance risk.
1 relationship(s) with CascadeDelete=Cascade on at least one custom side. Deleting a record of this entity automatically deletes related records.
56 controls in the (assumed) default tab. Performance risk, verify on the form.
How it works
Frequently asked questions
Do I need access to the environment?
No. The check works on the solution export only, the ZIP file Power Apps creates when you export a solution. The previous maintainer or your client can create the export and send it to you.
Does it work with managed solutions?
Yes. Unmanaged exports are evaluated in full. Managed exports are checked as well, and the report points out that some governance checks carry less weight there.
What can the report not see?
Anything that is not part of the export: the data itself, usage figures and environment settings, for example whether auditing is switched on for the whole environment. The report says explicitly where something has to be checked separately.
What does the review cost?
The key figures are free after the upload. You then decide whether you want the full report; the packages are shown on the results page.