This session is a case study for designing and building an application security framework that supports the needs of a large manufacturing company, and also drives least-privilege access and business ownership of security roles and risks during a D365FO implementation. We will start with an overview of how U.S. Venture, Inc., designed its security roles by building a segregation of duties rule set, and creating compliant task-based roles as the foundation for ensuring appropriate access and proper control throughout the D365 environment. This presentation does not require detailed knowledge of D365 security.The content of this session is geared toward an audience with beginner-level knowledge of the subject area.