An activated dialog in an environment where dialogs are retired
What it is
Dialog is still activated, and dialogs no longer run.
Why it matters
Microsoft deprecated dialogs and removed the legacy web client that ran them in December 2020, so nobody can start this one and it does nothing. It still reads as an active process wherever processes are listed and still travels inside any solution it belongs to, so an inventory of what automation runs here will count it.
Reported at Low because it is not an exposure and the dialog cannot be doing anything harmful. The two readings are that a business process was quietly lost when the runtime went away, or that this is leftover configuration from an environment that has been upgraded past it. A dialog that arrived in a managed solution cannot be deleted locally; the publisher has to remove it.
Find it yourself
List processes of category Dialog and read their state. Anything still activated is the finding. The classic-settings process list still shows them, which is part of why they survive: they look like live automation to anyone taking stock of the environment.
How to fix it
Work out whether the process it described is still needed and rebuild it as a business process flow, a canvas app or a cloud flow, then deactivate and delete the dialog.
Not a security finding
This one is environment health, so it carries a plain label and no control mapping. Presenting an operational gap as a security finding would make the real security findings harder to trust, so we keep the two apart.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.