PathixDataverse Forensics

← All 72 findings

Identity lifecycle & offboarding

A disabled user account that still holds security roles

Severity High

What it is

Disabled user account still has security role assignments.

Why it matters

Disabling a user suspends login but keeps their roles. Re-enable the account, on purpose or through a directory sync, and every role snaps back with no further action.

Find it yourself

List disabled users and link through systemuserroles. Any disabled account with rows returned is the finding. This one is genuinely quick to check and it appears in almost every environment older than a couple of years.

How to fix it

Strip roles during offboarding; re-grant on reactivation only after review.

Related controls

SOC 2 CC6.2ISO 27001 A.5.18NIST AC-2 / PS-4

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC PS.L2-3.9.2

This condition produces evidence for PS.L2-3.9.2 (Level 2: protect systems containing CUI during and after personnel actions such as termination), for the Dataverse system in your assessment scope. An assessor testing 3.9.2 asks how access is revoked when someone leaves. A disabled account still holding roles is the concrete artifact of that control failing on this system.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in identity lifecycle & offboarding

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π