I am logging this idea on behalf of the customer.
The customer has data say projects or customer groups etc. which are sensitive, which means it is crucial to restrict the access to the Project or Customer groups to the major of the employees. Using the “Extensible data security policies”, we are able to create a policy which work in the system and hide the sensitive Projects or customer groups etc. for the users. However, when open the Projects or Customer groups in open excel, all Projects or Customer groups (including the sensitive projects) appear in the excel list. I do open excel with the user who has the security policy.
As per the document - https://learn.microsoft.com/en-us/dynamics365/fin-ops-core/dev-itpro/data-entities/security-data-entities
It's mentioned that, Data Entities does not work wish the Extensible Data Security Concepts.
It would be beneficial for businesses that rely heavily on this functionality if Microsoft could address and resolve this issue.
Please find the potential business impact for those customers who rely on this functionality.
Business Impact:
The bug in the "Extensible Data Security Policies" exposes sensitive projects in Excel, bypassing access restrictions and creating significant operational risks.
Key Impacts:
- Operational Risk:
- Sensitive projects can be viewed by unauthorized users. Given the nature of the customer’s operations, this poses risks not only to the organization but potentially to societal, national and international security.
- Reputation Damage:
- Unauthorized exposure of critical information undermines trust and could harm relationships with stakeholders.
- Increased Security Risk:
- The uncontrolled access to sensitive data heightens the potential for misuse or leaks, with consequences far beyond the company.
- Workflow Disruption:
- The inability to mitigate this issue with a workaround impacts secure operations and user productivity.
Urgency: Addressing this issue is essential to safeguard sensitive data, protect broader societal and international interests, and maintain operational integrity.