The act-on-behalf-of delegation privilege granted by a custom role
What it is
Custom role grants act on behalf of another user.
Why it matters
The delegation privilege lets a principal act as another user, attributing their actions to someone else and operating with that user's access. Legitimate for some integrations, worth confirming for the rest.
Find it yourself
Read the privilege lists of your custom roles for the delegation privilege and note every role that grants it, then list who holds those roles. Legitimate holders are usually a small number of named integrations; anything else is worth a conversation.
How to fix it
Confirm each holder needs it, scope it to a dedicated integration identity, and remove it elsewhere.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.