A disabled user account that still holds security roles
What it is
Disabled user account still has security role assignments.
Why it matters
Disabling a user suspends login but keeps their roles. Re-enable the account, on purpose or through a directory sync, and every role snaps back with no further action.
Find it yourself
List disabled users and link through systemuserroles. Any disabled account with rows returned is the finding. This one is genuinely quick to check and it appears in almost every environment older than a couple of years.
How to fix it
Strip roles during offboarding; re-grant on reactivation only after review.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.