PathixDataverse Forensics

← All 40 findings

Data protection & field security

A secured column sitting in a default view

Severity Medium

What it is

Default view exposes a field-level-security secured column.

Why it matters

A secured column sits in the default view, so its header shows to everyone and rows without a grant render blank. Dataverse still enforces access, so this is a posture and UX gap, not a leak.

Find it yourself

For each secured column, search the FetchXML of the table's default views for its logical name. Exporting the solution and grepping customizations.xml is faster than clicking through the view designer.

How to fix it

Remove the secured column from the default view; make a separate view for the audience that has the grant.

Related controls

SOC 2 CC6.1ISO 27001 A.8.3NIST AC-3 / AC-4

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in data protection & field security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.