A disabled user account that still holds security roles
What it is
Disabled user account still has security role assignments.
Why it matters
Disabling a user suspends login but keeps their roles. Re-enable the account, on purpose or through a directory sync, and every role snaps back with no further action.
Find it yourself
List disabled users and link through systemuserroles. Any disabled account with rows returned is the finding. This one is genuinely quick to check and it appears in almost every environment older than a couple of years.
How to fix it
Strip roles during offboarding; re-grant on reactivation only after review.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for PS.L2-3.9.2 (Level 2: protect systems containing CUI during and after personnel actions such as termination), for the Dataverse system in your assessment scope. An assessor testing 3.9.2 asks how access is revoked when someone leaves. A disabled account still holding roles is the concrete artifact of that control failing on this system.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.