Dynamics 365 Customer Insights – Journeys - Transform customer journeys into action with record creation

🚨 The Signal: Dynamics 365 Customer Insights – Journeys can now automatically create records (e.g., tasks, leads) directly within customer journeys. This streamlines automation but expands the potential attack surface for data manipulation if not properly secured.

The Impact

Dynamics 365 admins and security teams are affected by the increased automation capabilities, which introduce new risks for unauthorized data creation and manipulation if access controls are not rigorously applied.

  • Dynamics 365 Admins: Must review and secure permissions for automated record creation to prevent misuse.
  • Security Teams: Need to assess the expanded attack surface for data integrity and unauthorized actions.
  • Compliance Officers: Must ensure automated record creation aligns with data governance and privacy policies.

The Action

  1. Review existing Dynamics 365 security roles and privileges for Customer Insights – Journeys users.
  2. Implement least privilege for users creating or modifying customer journeys that include record creation.
  3. Monitor audit logs for unusual or unauthorized record creation activities originating from customer journeys.
  4. Establish data validation rules for automatically created records to maintain data quality and integrity.

Domain: M365-Apps · Impact: medium · Workload: M365 Apps