A Copilot Studio agent tool running on its maker's connection
What it is
Agent tool is set up to run with its maker's credentials.
Why it matters
A tool set to run with the credentials of the person who built it acts with that person's access for every caller, so the agent effectively reaches whatever its author can reach.
Read from the tool's configuration: the credential mode alone is the trigger, and the worst parts of the shape are named where present, a target left for the model to choose at run time and a target in another environment. High when the owning agent is active and authenticates nobody, Medium otherwise. Pathix does not read conversations or run history, so this says the tool is set up to act this way and never that it has. Draft tools fire too.
Find it yourself
Export the agent's botcomponent rows and read each tool's connection setting inside its definition: a mode of Maker means the author's connection. In Copilot Studio, open each tool and check whether its connection runs as the maker or as the user. While you are in the definition, note tools whose table is left for the model to choose and tools aimed at another environment; the same rows carry both.
How to fix it
In Copilot Studio, switch the tool's connection to run as the person using the agent, or give a tool that must act as a service a dedicated account with only the access it needs; pin the table and action as fixed values and keep the environment explicit.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.