PathixDataverse Forensics

← All 72 findings

Access & least privilege

A security role granted to a business unit default team

Severity High

What it is

Business unit default team holds a security role.

Why it matters

Every user in a business unit is an unremovable member of its default team, so a role there grants to the whole unit and widens automatically as people are added. Easy to do by accident.

Find it yourself

List teams that hold roles and check the team type. Default teams are created automatically per business unit and their membership is not something you control, so any role on one grants to everyone in that unit both now and as it grows.

How to fix it

Move the role onto an owner team or an explicit assignment naming only the users who need it.

Related controls

SOC 2 CC6.1ISO 27001 A.5.15 / A.8.2NIST AC-6 / AC-2

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC AC.L1-3.1.1

This condition produces evidence for AC.L1-3.1.1 (Level 1: limit system access to authorized users, processes and devices), for the Dataverse system in your assessment scope. A role on a business unit default team is held by every user in that business unit, including everyone added later. The set of authorized users grows without anyone choosing to grant access.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π