Dynamics 365 Finance and Operations
Connect Dynamics 365 Finance and Operations to Ploy to see which of your workers hold a Finance and Operations user account, in each environment you connect. Ploy only reads: it never changes anything in Dynamics 365.
This integration is in beta
The Dynamics 365 integration is in beta. It was built from Microsoft's documentation for the Finance and Operations data API and has not yet been checked against a live environment, so some details may need adjusting once customers connect it. Beta does not limit what the integration can do.
The first step of setup is a consent checkbox. Ticking it lets Ploy capture redacted error data when a request to Dynamics 365 fails: the error response Dynamics 365 or Microsoft Entra sends back, with personal details, tokens and other secrets removed. Ploy uses it only to fix problems with this integration. You must tick the box to continue.
What Ploy reads
Every worker in the environment who is linked to a Finance and Operations user account, across all of your legal entities, with their name, email address, user ID and employment status
The environment itself, so a production and a sandbox environment stay separate in Ploy
Workers who are not linked to a user account are skipped, because they cannot sign in. A worker whose employment has ended but who is still linked to a user account stays in Ploy as an inactive person who still has access, so you can spot it.
Ploy does not see user accounts that have no worker record, such as administrator or service accounts, and it does not see security roles. Dynamics 365 does not make either available through its data API. Ploy does not import workers as employee records.
Before you start
You need:
The address you sign in to Finance and Operations at, for example contoso.operations.dynamics.com
Permission to register an app in Microsoft Entra ID for your organization
A Finance and Operations administrator, to add the app inside Finance and Operations
Register an app in Microsoft Entra ID
In the Microsoft Entra admin center, go to App registrations and create a new registration, for example called Ploy. Leave the redirect URI empty.
Under API permissions, add a permission, search for the API called Microsoft Dynamics ERP, and add its permissions for accessing Dynamics AX data, the Dynamics AX custom service and Dynamics AX online as organization users. Grant admin consent.
Under Certificates and secrets, create a new client secret and copy its value. Entra shows it only once.
From the app's overview page, copy the Application (client) ID and the Directory (tenant) ID.
Add the app in Finance and Operations
In Finance and Operations, go to System administration, then Setup, then Microsoft Entra applications.
Add a new row with the Application (client) ID, a name such as Ploy, and a User ID.
Use a dedicated Finance and Operations user for this, not a person's own account. Ploy reads with exactly that user's access, so give it a security role that can read workers in every legal entity.
If the app is registered in Entra but not added here, Dynamics 365 refuses every request.
Connect Dynamics 365 in Ploy
In Ploy, go to Integrations and choose Dynamics 365 Finance and Operations.
Tick the beta consent checkbox.
Enter your environment address. You can paste the full address from your browser; Ploy keeps only the host.
Enter the Directory (tenant) ID, the Application (client) ID and the client secret.
Select Test connection. Ploy signs in as the app and reads one worker to check everything works.
To connect a sandbox environment as well, add the integration again with the sandbox address.
What Ploy can change
Nothing. The Finance and Operations data API has no way to create, disable or remove users or to change their security roles, so the integration is read only.
Troubleshooting
Dynamics 365 rejected that app: check the tenant ID, client ID and secret, and that the app is listed under Microsoft Entra applications in Finance and Operations.
Dynamics 365 refused to list workers: give the Finance and Operations user the app is mapped to a security role that can read workers.
Dynamics 365 did not recognise that environment: check the address. It ends in operations.dynamics.com.
Workers are missing: make sure the mapped user can read workers in every legal entity. Workers without a linked user account are not shown.
Your client secret expires: Entra client secrets have an expiry date. Create a new secret before it expires and update the connection in Ploy.