PathixDataverse Forensics

← All 40 findings

Data protection & field security

Field-level security enabled with no profile granting access

Severity Medium

What it is

Field-level security enabled but no profile grants access.

Why it matters

A column is secured but no field-security profile grants access, so it is unreachable in the UI and SDK. Users hit Access Denied mid-workflow. A functional gap, mapped lightly.

Find it yourself

List columns with field security enabled, then check each against the field permissions defined on your field security profiles. A secured column appearing in no profile is unreachable by everyone, which usually surfaces first as an unexplained access error mid-process.

How to fix it

Grant the column through a profile and assign users, or turn field security off if it does not need protecting.

Related controls

SOC 2 CC6.1ISO 27001 A.8.3NIST AC-3

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in data protection & field security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.