Dynamics 365 Business Central: Development - Page Scripting enters General Availability

🚨 The Signal: Dynamics 365 Business Central now includes a General Availability page scripting tool. This enables recording and replaying user actions for testing, potentially introducing new vectors for malicious script injection or unauthorized data access if not properly governed.

The Impact

Admins and security teams are affected by the potential for script misuse, increasing risk of unauthorized actions or data manipulation.

  • Admins: Increased risk of unauthorized script execution if not properly managed.
  • Security Teams: New attack surface for malicious script injection and data exfiltration.
  • Auditors: Requires new audit considerations for automated process integrity.
  • Business Users: Potential for accidental or malicious automation of sensitive tasks.

The Action

  1. Review and update existing security policies for Dynamics 365 Business Central to include guidelines for page scripting.
  2. Implement strict access controls for who can create, modify, and execute page scripts.
  3. Establish a formal review and approval process for all new page scripts before deployment to production environments.
  4. Monitor audit logs for unusual page script activity or unauthorized script modifications.
  5. Educate users and administrators on the secure use of page scripting and the risks associated with unapproved scripts.

Domain: Other · Impact: high · Workload: Other · Essential Eight: Application Control, Restrict Administrative Privileges · ISM: ISM-0445, ISM-0843, ISM-1175, ISM-1380, ISM-1490, ISM-1507, ISM-1508, ISM-1509, ISM-1544, ISM-1582, ISM-1647, ISM-1648, ISM-1650, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1686, ISM-1688, ISM-1689, ISM-1870, ISM-1871, ISM-1883, ISM-1897, ISM-1898