Veriland ConsultingVeriland Consulting
  • Water Utilities (MaxWater) →

    • Water Utilities OverviewSpecialist modular platform for UK water utilities — meter-to-cash, asset lifecycle, SCADA, Ofwat compliance.
    • MaxWater Platform & ModulesSix independent modules — pick what you need, own everything we build.
    • Day in the LifeSix interactive stories showing how MaxWater transforms daily work across every department of a water utility.
    • Day in the Life: OperationsSee how MaxWater detects a failing pump at 2 AM and gets it fixed before anyone notices.
    • Day in the Life: ProcurementFrom emergency parts order to delivery — automated procurement across the supply chain.
    • Day in the Life: ComplianceOfwat reporting, DWI sampling, and audit preparation — all automated, all audit-ready.
    • Day in the Life: FinanceCapital project budgeting, AMP funding, cost allocation, and invoice matching.
    • Day in the Life: Project ManagementAMP obligation tracking, earned value, regulatory packages, and programme board reporting.
    • Day in the Life: CustomerMeter reading, billing, customer complaints, and leak detection — the customer-facing story.
  • Fixed‑Price Accelerator Packages →

    • Business Central AcceleratorA rapid, fixed‑price implementation of Business Central for mid-market businesses looking to modernise finance, invoicing, stock and reporting — without complexity.
    • CRM AcceleratorA fast, simple CRM setup built on Dynamics 365 Sales or Customer Service — helping mid-market teams get better pipeline visibility and consistent customer follow‑up.
    • F&O AcceleratorA streamlined version of Dynamics 365 Finance & Operations for mid-market organisations needing stronger financial control, supply chain visibility, and structured operations.
    • AI Agent AcceleratorDeploy 1–2 AI agents that automate repetitive tasks (like reconciliations, order processing, or support responses) with a fixed, predictable cost.
    • Power Platform AcceleratorReplace spreadsheets and manual approvals with automated workflows, low‑code apps, and digital forms built on Power Platform.
    • Migration Packs (ERP / CRM)Move from legacy systems (Sage, Xero, QuickBooks, Access, Salesforce, etc.) to modern Microsoft platforms with a predictable, fixed‑scope migration.
  • Finance, Stock & Operations →

    • Business Central (SMB ERP)A modern, all‑in‑one cloud ERP for mid-market organisations. Manage finance, sales, stock, projects, and operations in one simple system that grows with you.
    • Dynamics 365 Finance & Operations (F&O)Enterprise‑grade finance, supply chain, and operations for mid‑market organisations that need deeper control and automation across their business.
  • Products

    • MaxWAM – Work Asset Management (Mobile, Offline, AI)A mobile‑first, offline‑capable asset maintenance solution with work orders, inspections, compliance checks, and AI‑assisted technician workflows.
    • MaxBudget – AI‑Backed Budget Management for ProcurementGives finance teams real‑time budget visibility for all purchase requests — including committed spend that hasn't been paid yet — reducing overspending and surprises.
    • MaxPortal – Ready‑to‑Use Portal for D365 BC / F&OA configurable customer/vendor/employee portal for Business Central or F&O, enabling self‑service access to orders, invoices, tickets, documents, and status updates.
    • MaxWater – Modular Platform for Water UtilitiesSix independent modules for water utility operations: meter‑to‑cash, asset lifecycle, SCADA integration, field service, Ofwat reporting, and capital project governance.
  • Insights

    • BlogInsights, tips, and thought leadership on Dynamics 365, Azure, and AI for UK businesses.
    • Case StudiesSee how we've helped other businesses transform with Dynamics 365 and AI.
    • Guides & TutorialsFree video tutorials and step-by-step walkthroughs for Dynamics 365, Power Platform, and Azure.
    • Tools & DownloadsFree tools and downloads, including FinOpsWorkbench for managing your Dynamics 365 and Power Platform environments.
  • Veriland Difference

    • How We WorkDiscover our agile, transparent approach to delivering successful projects.
    • Why Choose VerilandLearn what sets our expertise and partner-driven approach apart.
    • Delivery ExcellenceOur commitment to quality, on-time delivery, and continuous improvement.
    • Security & TrustHow we protect your data and ensure enterprise-grade security.
    • Our Microsoft PartnershipLeveraging our status as a trusted Microsoft Partner for your success.
  • Book discovery call
  • Contact sales
  • Contact support
Veriland Consulting

What We Do

  • Microsoft D365 F&O
  • Microsoft D365 CE
  • Microsoft D365 BC
  • Azure Ecosystem
  • Copilot for Business
  • AI Agents
  • Power Platform

Products

  • MaxWAM
  • MaxBudget
  • MaxPortal

Services

  • D365 as a Service
  • Team as a Service
  • Pay-As-You-Go Support

Insights

  • Case Studies

Company

  • About Us
  • Contact

Connect

  • Charter House, Charter Way
  • Macclesfield, SK10 2NG
  • 01625 569 777
  • enquiries@veriland.co.uk
Microsoft Cloud Partner Program
Privacy PolicyCookie PolicyTerms & ConditionsCustomer ComplaintsModern Slavery Statement
Company Reg: 08209902© 2026 Veriland Consulting. All rights reserved.
  1. Insights
  2. Tools
  3. FinOps Workbench

FinOps Workbench — User Guide

  • What it does
  • System requirements
  • Installing the app
  • Getting started
  • The Environments view
  • Lifecycle operations
  • Requesting just-in-time SQL access
  • The SQL workspace
  • Downloading assets
  • The MCP server
  • Settings & appearance
  • Keyboard shortcuts
  • Where your data lives
  • Troubleshooting
  • FAQ
D365 F&OUser Guide23 July 2026 12 min read

What it does

FinOps Workbench talks to the Power Platform admin APIs and, optionally, Lifecycle Services on your behalf. It recognises three kinds of environment, and most actions are enabled or disabled depending on which kind you've selected:

KindWhat it is
UDEA unified developer environment — an F&O environment with a linked Dataverse org that supports the modern admin APIs (SQL JIT, DB Sync, dev-tools downloads).
LCSAn LCS-managed F&O environment. Managed through Lifecycle Services rather than the Power Platform admin API; some actions redirect you to the LCS portal.
DataverseA plain Dataverse environment with no F&O database.

Everything runs against your own signed-in identity — there is no service account, tenant id, client id or secret to configure. You must be an administrator on the environments you want to manage.

The FinOps Workbench Environments page showing several environments in a grid with kind, state, SKU, location and capacity columns.The Environments page — every environment you can administer, in one grid.

System requirements

  • Windows 10 or 11 (x64, ARM64, or 32-bit / ia32), or macOS (Apple Silicon or Intel).
  • A Microsoft Entra ID (work/school) account with administrator rights on the Power Platform / F&O environments you intend to manage.
  • Internet access to Microsoft endpoints (login.microsoftonline.com, the Power Platform admin APIs, your Dataverse org URLs, and — for LCS features — lcs.dynamics.com / lcsapi.lcs.dynamics.com).
  • No SQL client or ODBC driver needs to be installed — the SQL workspace and the MCP SQL tools use a built-in TDS client.

The Windows installers are not code-signed, so SmartScreen may warn on first launch. The macOS builds are signed & notarized and open without warnings.

Installing the app

Download the latest installer from the download page and pick the build for your machine:

InstallerFor
FinOpsWorkbench-<version>-x64-setup.exe64-bit Windows (most PCs)
FinOpsWorkbench-<version>-arm64-setup.exeWindows on ARM
FinOpsWorkbench-<version>-ia32-setup.exe32-bit Windows
FinOpsWorkbench-<version>-setup.exeWindows — combined (auto-selects your architecture)
FinOpsWorkbench-<version>-arm64.dmgmacOS — Apple Silicon
FinOpsWorkbench-<version>-x64.dmgmacOS — Intel

On Windows, run the installer — because it isn't code-signed, SmartScreen may show "Windows protected your PC"; click More info → Run anyway. It installs per-user and doesn't require administrator rights. On macOS, open the .dmg and drag the app to Applications.

Updates — new versions are published to the same download page. Install the newer build over your existing one; your settings and cached session are preserved.

Getting started

  1. On the Environments page, click Sign in (Authentication group of the ribbon). A Microsoft sign-in window opens inside the app — sign in with your Entra ID account and complete any multi-factor prompts.
  2. Once signed in, your name and account appear in the bottom-left corner and the environment list loads automatically.
  3. The status bar (bottom) shows Signed in as <your UPN> and a count of visible / total environments.

Behind the scenes the app also tries to set up two extra sessions from the same sign-in, silently where it can: a developer-tools session (used later when you download assets) and an LCS session (so LCS SQL access and asset downloads don't need a separate sign-in). If either can't be captured silently, the app sets it up the first time you need it.

Your session is remembered securely between launches (encrypted at rest), so you normally only sign in once. On startup the app restores your previous session; if it has expired you'll be prompted to sign in again. Sign out clears all tokens, the LCS session, browser cookies and cached SQL grants.

The Environments view

The home page lists every environment you can administer, with live status, capacity, versions and lifecycle state.

  • Left rail — switch between the four areas (Environments, SQL Workspace, Assets, MCP Server). Your signed-in account sits at the bottom; the rail collapses to icons via the hamburger button.
  • Ribbon — grouped actions (Authentication, Lifecycle, Data ops, View). Buttons enable or disable based on the selected environment's kind and state.
  • Grid — one row per environment, organised into Environment, Dataverse and F&O column bands.
  • Details tab (right edge) and Activity log (bottom edge) — both tuck away by default; click the tab to expand.

The grid

  • The Kind column shows whether a row is a UDE, LCS, or Dataverse environment.
  • Coloured State, Operation status and F&O state pills give status at a glance — green = healthy/ready, amber = busy (provisioning, copying, syncing…), red = failed/unavailable, blue = admin/maintenance, grey = neutral.
  • The SQL access column shows a key icon when a valid SQL JIT grant is currently held for that row. The key disappears automatically when the grant expires.
  • Double-click any row to open its full JSON (a curated Details tab plus the Raw JSON).
  • Type to search, drag column headers to reorder, and click a column's filter button to filter.

Columns, units and filters

From the View group you can apply the F&O preset (default), the Dataverse preset or Show all columns; switch storage columns between GB / MB; and filter to All, UDE / F&O only or Dataverse only.

Details and Activity log

The Details panel (right edge) shows a full, curated breakdown of the selected environment — general info, status, capacity, Dataverse and F&O metadata, links and more. The Activity log (bottom edge) records everything the app does, colour-coded by severity with timestamps. Right-click to Copy row or Copy all messages. When something doesn't work as expected, this is the first place to look.

Lifecycle operations

These live in the Lifecycle and Data ops ribbon groups. Actions that change or provision environments always confirm first, and most are submitted asynchronously — click Refresh to track progress in the Operation status pill.

ActionKindWhat it does
New environmentanyProvision a new environment — display name, SKU (Sandbox / Production / Trial), Azure region, template, and whether to enable dev tools, demo data and a database.
CopyUDE / F&OOverwrite a target environment with a copy of the selected one. Type-to-confirm; this replaces the target and cannot be undone.
DeleteUDE / DataversePermanently delete an environment. You must type the environment's display name exactly to confirm.
Refresh—Reload the list and fetch F&O details, LCS enrichment, and (if enabled) LCS-only environments in the background.
HistoryUDE / DataverseShow the lifecycle-operation history, with a per-operation stage breakdown.
DB SyncUDETrigger a full database synchronisation and follow it live in the Operation status pill.
Save JSON—Save the selected environment's raw definition to a .json file.
Discover actionsUDE / DataverseProbe the Dataverse $metadata for available actions.
F&O detailsUDERead the F&O application/platform version, deployment type and state.
LCS-managed environments don't support Copy, Delete, History or DB Sync through the app — the Power Platform admin APIs don't manage them. When you try, the app points you to the LCS portal instead (for example, JIT database access is granted from the environment's Maintain menu in LCS).

Requesting just-in-time SQL access

Select an environment and click Request SQL access (enabled for UDE and LCS environments). Choose a reason and an access level:

  • Pick a standard reason and the app sets the role automatically (Reader or Writer) — you can still change it, or type your own reason.
  • The app finds your public IP (or you can enter it), opens the SQL firewall for that IP, and requests time-limited credentials.
  • For UDE environments this goes through the supported Dataverse action. For LCS environments it signs you in to Lifecycle Services once (if needed) and completes the request there.

Credentials are valid for about 12 hours and only from the allowed IP. You must be a system administrator on the environment.

The SQL JIT credentials viewer showing server, database, user, masked password, role and expiry, plus a ready-to-use connection string.The SQL JIT credentials viewer — copy the connection string straight into SSMS or your app.

The Credentials tab shows the server, database, user name, password (masked, with a Show toggle), role and expiry, plus a ready-to-use connection string. Copy connection string puts the .NET/SSMS-ready string on the clipboard; Re-request obtains a fresh grant — for example to upgrade a read grant to read/write.

The granted credentials are cached for the session (the environment's SQL access column shows a key), so opening the SQL Workspace on that environment connects straight away.

The SQL workspace

An SSMS-style workspace for browsing and querying environment databases.

The SQL Workspace with an object browser tree on the left, a SQL editor with a sample query, and a results grid.The SQL Workspace — object browser, query editor and results grid, with T-SQL auto-complete.
  • Object browser (left) — lists all your environments, each with its kind icon. Select one and connect it; connected environments expand to their database → schemas → Tables / Views → columns. Very large F&O schemas group objects into alphabetical folders. Both the F&O and Dataverse endpoints of the same environment can be connected at once.
  • Query tabs (right) — each tab has a SQL editor and a results grid, and runs against the environment named on the tab. Press F5 (or Execute) to run; Ctrl+Space opens auto-complete (T-SQL keywords plus the environment's tables and columns).
  • Double-click a table to open a new tab pre-filled with SELECT TOP (1000) * FROM [schema].[table] and run it automatically.

Connecting — select an environment in the object browser and use the ribbon (or right-click → Connect):

  • Connect F&O — connects the finance & operations database using a SQL JIT grant. For a UDE environment it requests the grant for you; for an LCS environment it reuses a held grant or runs the LCS request.
  • Connect Dataverse — connects the org's read-only TDS endpoint using your signed-in identity, no separate credentials needed. Writes are rejected by the server.
First connect can take a minute. When you connect F&O on a just-granted JIT credential, Microsoft may still be provisioning the SQL login and firewall rule — the workspace shows a "Waiting for Microsoft to provision JIT SQL access…" overlay and retries automatically for up to four minutes.

Downloading assets

Select an environment and click Download assets to open the picker (enabled for UDE and LCS environments). It lists everything available for that environment:

  • Downloadable VHD versions and developer tools (Packages local directory, the F&O Visual Studio extension, Trace Parser, cross-reference database) — for any environment with a Dataverse org.
  • For LCS-managed environments, also the project's asset library (software deployable packages, data packages, models, GER configurations, NuGet packages) and database backups (bacpacs).

Tick what you want and click Download… to save to a folder. Downloads run in the background with per-item progress; you can minimise the window and start several batches at once.

The Assets page listing downloaded developer artefacts with status, environment, category, file, size and location columns.The Assets page — your download library, with quick actions to open or remove files.

The Assets page is your download library — it shows what you've already downloaded, whether each file is still on disk, and quick actions to Open file, Open folder, Download more… or Delete (sends the file to the Recycle Bin / Trash).

The MCP server

FinOps Workbench can expose your signed-in session to AI tooling (Claude Desktop or Claude Code) through a built-in Model Context Protocol server. An assistant can then list and inspect environments, read F&O details and operation status, and run SQL on your behalf.

The MCP Server page with Start/Stop, Use HTTPS, Allow write ops, Copy config, and Add to Claude Code / Claude Desktop buttons.The MCP Server page — start the server and register it with Claude in one click.
  1. Set the Host / Port (defaults localhost / 8899 are fine for local use).
  2. Leave Use HTTPS on — most MCP clients, including Claude, require HTTPS. The app ships a self-signed localhost certificate; you can point at your own PFX if you prefer.
  3. Click Start. The log shows "MCP server listening on https://localhost:8899".
  4. Register the server with your client:
    • Add to Claude Code — runs claude mcp add for you (user scope). In Claude Code, run /mcp to confirm.
    • Add to Claude Desktop — writes the connection into Claude Desktop's config via the mcp-remote bridge. Fully quit and reopen Claude Desktop afterwards.
    • Copy config — copies the connection snippet to paste into any client manually.

Tools exposed: auth_status, sign_in, list_environments, get_environment_details, get_environment_history, get_finops_details, get_operation_status, run_sql, and request_sql_jit (guidance only). SQL runs against a held JIT grant for F&O/UDE environments, or the read-only Dataverse TDS endpoint for plain Dataverse orgs.

Write operations (create_environment, copy_environment, delete_environment, dbsync_to_finops) are off by default. Turn on Allow write ops only if you want the assistant to make changes; the toggle takes effect immediately.

Security: the endpoint is localhost-only and unauthenticated — it exposes your own signed-in session to any local MCP client. Don't expose it beyond your machine, and leave write ops off unless you need them.

Settings & appearance

Open Settings from the ribbon (View group).

The Settings dialog with theme, Load LCS environments, LCS region and SQL object browser options.Settings — theme, LCS options and SQL object-browser behaviour.
  • Theme — Follow operating system (default), or pin Light / Dark. The whole app re-themes instantly and tracks your OS light/dark switch live.
  • Load LCS environments — also crawl Lifecycle Services for F&O environments that aren't in the Power Platform admin list. Turn off if you only work with Power Platform environments.
  • LCS region — pick the regional LCS REST API endpoint used for asset downloads (leave on Global unless your LCS tenant is in a specific geo).
  • SQL object browser — group large table/view lists into alphabetical folders (and the threshold at which grouping kicks in). This keeps the SQL workspace tree responsive on huge schemas — an F&O database has ~25,000 tables.

The app follows your light/dark preference automatically:

The Environments page rendered in dark mode, following the operating system theme.Dark mode — the app re-themes the whole UI to match your OS.

Keyboard shortcuts

ShortcutWhereAction
F5SQL editorRun the active query tab
Ctrl+SpaceSQL editorOpen auto-complete
TabSQL editorIndent (does not change focus)
Type to searchEnvironments grid / object treeIncremental find
Double-clickEnvironments rowOpen the environment JSON viewer
Double-clickSQL object tree table/viewOpen & run SELECT TOP (1000)
Ctrl / Shift + clickEnvironments gridMulti-select rows

Where your data lives

FinOps Workbench stores everything under your user profile — nothing is sent anywhere except the Microsoft services you're administering.

DataLocation (Windows)
Settings (theme, LCS options)%LOCALAPPDATA%\FinOpsWorkbench\settings.json
Download history (Assets page)%LOCALAPPDATA%\FinOpsWorkbench\downloads.json
Tokens, LCS session, cached SQL grantsEncrypted store
Sign-in browser profiles%LOCALAPPDATA%\FinOpsWorkbench\

Secrets are never logged. Tokens, passwords, cookies, connection strings and download SAS URLs are kept out of the Activity log and diagnostics.

Troubleshooting

SmartScreen warns when I run the installer (Windows). The installer isn't code-signed. Click More info → Run anyway. This is expected for a release from the official download page.

Sign-in window is blank or won't load. The app uses an embedded Microsoft sign-in browser. If it can't start (common on some virtual machines), the app falls back to your default browser to finish sign-in — watch the Activity log. Ensure the machine can reach login.microsoftonline.com.

"Request SQL access" is disabled. It's only available for UDE and LCS environments. Plain Dataverse environments have no F&O database to grant access to — query them via SQL Workspace → Dataverse tables instead.

The SQL workspace sits on "Waiting for Microsoft to provision JIT SQL access…". Microsoft provisions the SQL login and firewall rule on demand; this can take a minute or two on a fresh grant, and the app retries for up to four minutes. A changed public IP is a common cause — re-request access to refresh the firewall rule.

Claude can't connect to the MCP server. Make sure the server is Started, Use HTTPS is on, and you've registered it with Add to Claude Code / Desktop. For Claude Desktop, fully quit and reopen it after adding, then ask the assistant to call auth_status.

FAQ

Do I need to configure a tenant, client id or secret? No. The app signs you in interactively with your own account and uses your identity for everything.

Is my session shared with anyone? No. Tokens are stored encrypted on your machine and used only to call Microsoft services. The MCP server, if you start it, is localhost-only.

Can I manage LCS environments fully from the app? Partly. You can list them, enrich their details, request SQL access, and download LCS assets. Copy, Delete, History and DB Sync for LCS environments must be done in the LCS portal.

Does querying Dataverse cost or change anything? The Dataverse SQL endpoint is read-only — only SELECT works, and it needs no separate credentials beyond your sign-in.

Is the app free? Yes. FinOps Workbench is built and maintained by Veriland Consulting for the Dynamics 365 community — free to use and share, provided "as is" without warranties.

FinOps WorkbenchDynamics 365 F&OPower PlatformUDESQLMCP

Ready to try FinOps Workbench?

Download the free app for Windows or macOS, or talk to the Veriland team about your Dynamics 365 and Power Platform delivery.

Download FinOps WorkbenchBook a discovery call
Or call us directly: 01625 569 777