Cyber Security

Updated January 13, 2026

A distribution company woke up one Monday morning to find their entire network encrypted. The ransom demand? $180,000 in Bitcoin. The attackers had waltzed in through a forgotten SQL login nobody knew existed. An old integration account from three years ago that was never decommissioned.

The painful part? Their Dynamics GP security was configured perfectly. User permissions were locked down. Multi-factor authentication was enabled. Regular security audits were performed.

None of that mattered.

They paid the ransom. They didn’t have a choice. The attackers had deleted their backups first, and they couldn’t operate without access to their financial data.

Sound familiar? Or maybe it makes you a little nervous?

Look, you’ve locked down your GP user permissions. Your warehouse staff can’t access payroll. Nobody can cut unauthorized checks. Your Dynamics GP security is perfectly configured. You’re protected, right?

Not quite.

Here’s the reality most GP administrators don’t want to hear: your carefully configured application security is only protecting one piece of a much larger puzzle. SQL Server, reporting tools, integrations, and cloud services create vulnerabilities that can expose your financial data even when GP’s internal security is flawless.

This isn’t about GP security being weak. It’s about understanding that GP doesn’t operate in isolation. The systems surrounding it can quietly undermine everything you’ve set up inside the application.

SQL Server: The Foundation Everyone Forgets

Dynamics GP sits on top of SQL Server, and that database layer has its own security rules that don’t always align with what you’ve configured in GP itself.

Password Requirements Can Be Bypassed

Your company probably has strict password policies. Complexity requirements, expiration rules, minimum lengths. Here’s what catches people off guard: anyone with the right SQL Server permissions can disable those requirements for individual GP users.

That means someone could end up with “password123” without IT ever noticing.Dynamics GP User Setup

Pull SQL-level password audits monthly. Make sure everyone follows your domain security standards, not just most people.

Two Accounts Control Everything

The sa and DYNSA accounts have complete control over GP’s data. If someone gains access to either account, they effectively own your entire financial system.

Lock these accounts down with strong passwords, limited access, and close monitoring. It’s that simple and critical.

Learn more about SQL Server authentication best practices from Microsoft.

SSRS Reports: The Forgotten Access Point

SQL Server Reporting Services powers many GP reports, and access is controlled through reporting roles, not through GP’s security system.

The problem? During initial setup, administrators often grant broad “access to all reports” permissions to make configuration easier. Those temporary permissions never get removed.

Suddenly, your accounts payable clerk can run payroll reports because nobody went back to tighten things up.

Here’s the fix: Pull SSRS permission reports monthly and kill any access that doesn’t match actual job duties. Report access should match your GP security model. Period.

See more Dynamics GP security tips on our blog

Integrations: Where Convenience Meets Risk

GP connects to other systems through Web Services, eConnect, or direct SQL queries. These integrations need credentials to function. That’s where things get messy.

Stop Using Employee Accounts for Integrations

Some organizations use regular employee login credentials for integration accounts because it’s easy. The integration runs under John’s account, pulls data from GP, and everything works fine. Until John leaves the company or changes his password.

Then integrations break, orders stop processing, and everyone scrambles to figure out what happened.

More importantly, that integration inherited all of John’s permissions, including access to data it shouldn’t touch.

Create dedicated service accounts. They won’t change when staff turns over, they can use long complex passwords that never expire, and you can lock them down to exactly the permissions the integration needs. Nothing more.

Track Your SQL Logins

Some integrations and reporting tools use SQL logins instead of Windows accounts. SQL logins don’t appear in Active Directory, aren’t tied to specific employees, and become forgotten entry points into your data.

Use Windows accounts for integrations whenever possible. They’re visible, auditable, and easier to manage when someone leaves or changes roles.

Read Microsoft’s guidance on securing SQL Server

The Systems Around GP Matter Too

Several systems that aren’t technically part of GP still interact with GP data or GP users—and weaknesses in these areas can expose your financial information.

Microsoft 365 Microsoft 365: The Front Door

Your Microsoft 365 tenant often connects to multiple GP-related systems. Every user should have multi-factor authentication enabled, and service accounts supporting backend processes should have conditional access policies restricting logins by location or network.

Block access from countries where you have no staff. Restrict administrative access to your office network. These simple policies prevent most unauthorized access attempts.

Administrator roles deserve special attention. Smaller organizations sometimes make multiple users Global Administrators for convenience, but Microsoft recommends no more than six Global Admins—and many organizations can operate with fewer. Review these roles regularly to ensure only the right people have high-level access.

Backup Systems: Attackers’ New Target

Backups are your safety net during disasters. They’ve also become a prime target for attackers.

Ransomware operators increasingly focus on deleting or encrypting backups before launching their main attack. Why? It ensures you can’t recover without paying.

That distribution company from the beginning? Their attackers didn’t just encrypt their production systems. They spent two weeks quietly mapping the network, identifying backup locations, and systematically deleting every backup copy before launching the ransomware.

When the attack hit, there was nothing to restore from.

Isolate your backup systems. Implement strong authentication. Monitor access religiously. If someone can access your backups, they can hold your business hostage even if your Dynamics GP security is perfect.

Password Vaults Centralize Risk

Password managers like LastPass, KeePass, or Devolutions Password Manager centralize sensitive credentials. That makes them incredibly valuable targets.

Use non-cloud storage when possible. Restrict access to only necessary users. Some organizations hide the network location of vault files or use multiple vaults to separate highly sensitive credentials from everyday ones.

Your password vault holds the keys to your kingdom. Treat it that way.

Stop Playing Whack-a-Mole with Security

Most organizations approach Dynamics GP security reactively. Someone discovers a permission issue, they fix that specific problem, then move on until the next issue surfaces.

That’s playing whack-a-mole with your financial data.

The better approach? Understand that GP security extends far beyond the application itself. SQL Server settings, integration accounts, Microsoft 365 configuration, backup protections, and password management practices all determine whether your payroll, AP, AR, and GL data stays protected.

Your GP security is only as strong as the weakest link in this chain. In most organizations, that weak link exists somewhere outside GP itself. Just like that forgotten SQL login that cost one company $180,000 and weeks of operational chaos.

Planning your move from GP? Modern cloud platforms like Business Central and Acumatica include built-in security features that eliminate many of these infrastructure headaches.

Contact CAL

Ready to Strengthen Your Entire GP Environment?

At CAL Business Solutions, we’ve been implementing and securing Dynamics GP systems for over 40 years. We understand both the application-level security and the surrounding infrastructure that can undermine your efforts.

Whether you need help auditing your current security configuration, implementing better integration practices, or planning your eventual migration to modern cloud platforms like Business Central or Acumatica, our team can help you protect your financial data across your entire technology stack.

Contact us today to discuss how we can help strengthen your GP security, both inside the application and across the systems that surround it.

By CAL Business Solutions, Connecticut Acumatica & Microsoft Dynamics 365 BC / GP Partner, www.calszone.com