A security role granted to a business unit default team
What it is
Business unit default team holds a security role.
Why it matters
Every user in a business unit is an unremovable member of its default team, so a role there grants to the whole unit and widens automatically as people are added. Easy to do by accident.
Find it yourself
List teams that hold roles and check the team type. Default teams are created automatically per business unit and their membership is not something you control, so any role on one grants to everyone in that unit both now and as it grows.
How to fix it
Move the role onto an owner team or an explicit assignment naming only the users who need it.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L1-3.1.1 (Level 1: limit system access to authorized users, processes and devices), for the Dataverse system in your assessment scope. A role on a business unit default team is held by every user in that business unit, including everyone added later. The set of authorized users grows without anyone choosing to grant access.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.