PathixDataverse Forensics

← All 40 findings

Access & least privilege

The act-on-behalf-of delegation privilege granted by a custom role

Severity High

What it is

Custom role grants act on behalf of another user.

Why it matters

The delegation privilege lets a principal act as another user, attributing their actions to someone else and operating with that user's access. Legitimate for some integrations, worth confirming for the rest.

Find it yourself

Read the privilege lists of your custom roles for the delegation privilege and note every role that grants it, then list who holds those roles. Legitimate holders are usually a small number of named integrations; anything else is worth a conversation.

How to fix it

Confirm each holder needs it, scope it to a dedicated integration identity, and remove it elsewhere.

Related controls

SOC 2 CC6.1 / CC6.3ISO 27001 A.8.2NIST AC-6 / AU-10

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.