Microsoft Copilot security directory

Fin & Ops Apps (Dynamics 365)

Published by Microsoft

High risk

Fin & Ops Apps (Dynamics 365) connector provides access to data entities.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.

Available capabilities

This add-on exposes 8 tools or capabilities.

  • Create record
  • Delete record
  • Dynamics 365 ERP MCP
  • Execute action
  • Get a record
  • Get list of entities
  • Lists items present in table
  • Update a record

The interactive security report will load automatically.