A secured column on a form shown to users without the grant
What it is
Form layout includes a field-level-security secured column.
Why it matters
Same problem on a form: users without the grant see a blank control that reads as broken rather than protected. Enforced server-side, so posture and UX, not exfiltration.
Find it yourself
Same approach as views, against formxml instead. Grep the exported customizations.xml for each secured column's logical name and note which forms place it.
How to fix it
Remove the secured column from forms shown to audiences that lack the grant, or scope a form variant to those who have it.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.