Column-level security enabled with no profile granting access
What it is
Column-level security enabled but no profile grants access.
Why it matters
A column is secured but no column security profile grants access, so it is unreachable in the UI and SDK. Users hit Access Denied mid-workflow. A functional gap, mapped lightly.
Find it yourself
List columns with column security enabled, then check each against the column permissions defined on your column security profiles. A secured column appearing in no profile is unreachable by everyone, which usually surfaces first as an unexplained access error mid-process.
How to fix it
Grant the column through a profile and assign users, or turn column security off if it does not need protecting.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.