A Copilot Studio agent owned by a disabled user
What it is
Copilot Studio agent is owned by a disabled user account.
Why it matters
Disabling an account does not reassign what it owns, so the agent keeps pointing at someone who is gone: nobody is accountable for it, and the review and cleanup paths run through the owner. Agents built during a proof of concept and left behind are the common case.
This reports the ownership gap and does not claim the agent is broken. Whether it still works depends on how each of its tools connects, and Pathix reads that much, recording each tool's connection reference and whether it runs on its maker's credentials or the caller's; whether the credential behind a connection still works is not read.
Find it yourself
List bot rows with their owner and join the owner to systemuser, filtering to disabled accounts. Exclude the platform's built-in SYSTEM and INTEGRATION accounts, which are stored disabled by design.
How to fix it
Reassign the agent to an active owner, preferably a service account or a team, or delete it if it is no longer wanted; add agent reassignment to offboarding alongside flows and apps.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.