Review a third-party Dynamics 365 solution
A vendor ships a managed solution, a partner brings a ready-made module. What is inside is hard to see in the maker portal: which plugins run with which permissions, and where data goes. The solution export contains both, before the solution is ever imported into your environment.
For IT managers and architects before sign-off, consultants doing the integration, partners running their own modules next to someone else's, and procurement when choosing a vendor.
What is checked
Plugin assemblies
Code running outside the sandbox, assemblies without a strong name, direct SQL access and calls to external services.
Plugin registrations
Synchronous steps without filtering attributes, plugins that run every time a list is opened, and images that load every column.
Security roles that ship with it
Organization-wide rights to delete, share or assign records, and roles with an unusually large number of privileges.
Outbound data flows
Service endpoints without encryption or sending the user's identity, custom connectors without authentication and flows that pass data to an AI model.
Changes to standard tables
Cascading deletes from standard tables onto the solution's tables, rights inherited through relationships and items removed from the standard navigation.
Code in the browser
Libraries loaded from external CDNs, "eval()" and PCF controls with access to camera, location or the network.
Dependencies
The deployment check lists which solutions must be installed first. On top of that come buttons and navigation items that point to scripts outside the solution.
Sample findings
This is how findings appear in the report: component, rule, severity and the note behind it.
Plugin assembly does NOT run in the sandbox (IsolationMode=1). The code has unrestricted access (file system, network, any library). Full trust is no longer allowed in Dataverse online: a migration blocker and a security risk.
Grants organization-wide (Global) delete rights on 12 table(s). Large blast radius if misconfigured. Check whether it needs to be this broad.
Prerequisites: 3564 references to 58 other solutions must exist in the target environment.
How it works
Frequently asked questions
Can I check a solution before it is imported?
Yes. All you need is the ZIP file the vendor gives you. Managed solutions are checked, and the report points out that some governance checks carry less weight there.
Does D365 Audit see the plugin code?
If the assemblies are included in the export, D365 Audit checks the compiled code as well as the registration: SQL access, network calls, file access and the .NET version. An export does not contain source code.
Does the report show the layering in my environment?
No. Which solution layers sit on top of each other can only be seen in the environment itself, in the solution layers view. The report shows what the solution itself brings and requires.
What does the check cost?
The key figures are free after the upload. You then decide whether you want the full report; the packages are shown on the results page.