Skip to content

πŸ” Modernizing D365FO Security: Secrets, Certificates & Key Vault

After exploring encryption fundamentals in -part 1 & symmetric vs. asymmetric encryption in Part 2 ,the next topic explores how to securely manage secrets and certificates using Azure Key Vault, helping modernize security practices in D365FO solutions and integrations.

Azure Key Vault is a cloud-based service from Microsoft Azure that helps securely store and manage sensitive information such as:

  • Passwords
  • API keys
  • Connection strings
  • Certificates
  • Encryption keys

Why use Azure Key Vault in D365FO?

Without Key Vault:

  • Secrets may be hardcoded in X++ code.
  • Passwords may be stored in tables or configuration records.
  • Credential rotation becomes difficult.
  • Security and compliance risks increase.

With Key Vault:

βœ… Centralized secret management
βœ… Improved security and compliance
βœ… Secret rotation without code changes
βœ… Managed identity authentication support
βœ… Reduced exposure of credentials

Common D365FO Use Cases

1. External API Authentication

When D365FO integrates with external systems:

  • REST APIs
  • Third-party logistics providers
  • Banking systems
  • E-commerce platforms

API keys and client secrets can be stored securely in Key Vault.

2. Custom Integrations

Instead of storing:

str clientSecret = "MySecret123";

Store the secret in Key Vault and retrieve it dynamically.

3. Data Encryption Scenarios

Encryption keys can be managed through Key Vault for custom encryption/decryption implementations.

How D365FO Accesses Key Vault

D365FO generally uses:

  • Azure Active Directory (Microsoft Entra ID)
  • Application Registration
  • Managed Identity (where applicable)
  • Service Principal authentication

The D365FO environment is granted permission to access specific secrets in Azure Key Vault.

High-Level Configuration Steps

  1. Create an Azure Key Vault.
  2. Create or identify an Entra ID App Registration.
  3. Add secrets/certificates to Key Vault.
  4. Grant required permissions to the application.
  5. Configure Key Vault parameters in D365FO.
  6. Retrieve secrets using X++ or integration frameworks.

Actual Implementation:

  1. Create an App registration in Azure Portal. You can refer my detailed post on creating an App registration here
  2. Note the Client ID and Secret.

3. Search for ‘Key Vaults’ in the Azure Search bar. Create a new Key Vault

4. Add the App registration to the Key vault Access policies

Select the Permissions needed for the above App registration to access the KV. In my case, the Client ID should have access to read the KV and Secret.

Click Next.

Enter your client ID or the name .

Select the Principal and click Assign. The access policy is created for the Client id.

Creating Secret:

I am storing an API key in the secret, which one of my integrations custom logic will use.

Create a new secret and name it. Then enter the API key value

Click Create .

Now we have done necessary set ups in Azure.

How to connect the Key vault in D365FO

Go to System Administration -> Set up -> Key Vault Parameters

Click New

Enter the name of the Key vault and description

For the Key Vault URI, fetch from the below path in Azure

Enter the client ID and secret which is associated with Key vault (Used in the access policies)

Now comes the important part

The secret created in the key vault is referred in the ‘Secret’ grid

Note the format – I`ve selected as ‘manual’ and entered the secret vault:///<<KVSecretName>>

There are other types of Secrets – Certificate/Key –

Click the Validate button the Secrets grid. If the permissions are correct, the validation will be successful.

You can use the above KV set up directly in your code or by referring them in a custom parameters like this

Benefits for Architects and Developers

Benefit Description
Security No hardcoded credentials
Maintainability Secrets can be updated without redeployment
Compliance Meets security and audit requirements
Centralization Single location for secret management
Scalability Easy to reuse across multiple integrations

The best secret about integrations? They shouldn’t contain any secrets at all. Let Azure Key Vault handle them securely.

As D365FO solutions become increasingly connected, secure secret management is essential. Azure Key Vault is not just a security feature, it’s a key architectural component for enterprise-grade integrations. πŸ”πŸš€

Anitha Santosh originally posted this article on 5 October 2026 at 9:44 PM.

Leave a Reply