Dynamics 365 Contact Center - Use bullseye routing with user groups to orchestrate conversations
🚨 The Signal: Dynamics 365 Contact Center introduces 'bullseye routing' to automatically expand customer service representative pools based on wait times. This feature optimizes agent assignment but requires careful security review of user group permissions to prevent unauthorized access to sensitive customer interactions.
The Impact
Dynamics 365 administrators and security teams are affected, with a risk of misconfigured access controls leading to unauthorized personnel handling sensitive customer data.
- Dynamics 365 Admins: Must review and configure user group permissions to align with least privilege principles.
- Security Teams: Need to audit access controls for customer service representatives to prevent data exposure.
- Customer Service Managers: Must understand how routing impacts data access for their teams.
- Compliance Officers: Need to ensure routing configurations meet regulatory requirements for data handling.
The Action
- Review existing Dynamics 365 user groups and their assigned security roles.
- Define new user groups for bullseye routing tiers with the principle of least privilege.
- Map specific security roles to each user group, ensuring only authorized personnel can access sensitive customer data.
- Implement a regular audit process for Dynamics 365 user group assignments and routing configurations.
- Consult the Dynamics 365 documentation for best practices on securing bullseye routing configurations.
Domain: M365-Apps · Impact: medium · Workload: M365 Apps · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898