PathixDataverse Forensics

← All 40 findings

Secrets & transmission security

An HTTP-triggered flow anyone with the URL can run

Severity High

What it is

HTTP-triggered flow can be run by anyone with the URL.

Why it matters

The flow's trigger accepts anyone with the URL, no identity check, so a leaked link lets anyone drive whatever the flow does in Dataverse. Power Automate now defaults new flows to tenant-restricted.

Find it yourself

Export the solution and search the flow definition JSON for request triggers, then read the authentication setting on each. Older flows predate the tenant-restricted default, so age is a good filter for where to look first.

How to fix it

Restrict the trigger to your tenant or named users, and regenerate the signature key so old URLs stop working.

Related controls

SOC 2 CC6.1ISO 27001 A.8.3NIST AC-3 / IA-2

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in secrets & transmission security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.