PathixDataverse Forensics

← All 72 findings

Identity lifecycle & offboarding

A Copilot Studio agent owned by a disabled user

Severity Medium

What it is

Copilot Studio agent is owned by a disabled user account.

Why it matters

Disabling an account does not reassign what it owns, so the agent keeps pointing at someone who is gone: nobody is accountable for it, and the review and cleanup paths run through the owner. Agents built during a proof of concept and left behind are the common case.

This reports the ownership gap and does not claim the agent is broken. Whether it still works depends on how each of its tools connects, and Pathix reads that much, recording each tool's connection reference and whether it runs on its maker's credentials or the caller's; whether the credential behind a connection still works is not read.

Find it yourself

List bot rows with their owner and join the owner to systemuser, filtering to disabled accounts. Exclude the platform's built-in SYSTEM and INTEGRATION accounts, which are stored disabled by design.

How to fix it

Reassign the agent to an active owner, preferably a service account or a team, or delete it if it is no longer wanted; add agent reassignment to offboarding alongside flows and apps.

No control mapping, deliberately

This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in identity lifecycle & offboarding

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π