PathixDataverse Forensics

← All 72 findings

Data protection & column security

Column-level security enabled with no profile granting access

Severity Medium

What it is

Column-level security enabled but no profile grants access.

Why it matters

A column is secured but no column security profile grants access, so it is unreachable in the UI and SDK. Users hit Access Denied mid-workflow. A functional gap, mapped lightly.

Find it yourself

List columns with column security enabled, then check each against the column permissions defined on your column security profiles. A secured column appearing in no profile is unreachable by everyone, which usually surfaces first as an unexplained access error mid-process.

How to fix it

Grant the column through a profile and assign users, or turn column security off if it does not need protecting.

No control mapping, deliberately

This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in data protection & column security

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π