PathixDataverse Forensics

← All 40 findings

Access & least privilege

An integration account that can grant itself privileges

Severity Critical

What it is

Integration can rewrite the security model.

Why it matters

A service account whose role can create roles, assign roles, or provision users can bootstrap itself to full control through the API alone. No production integration needs this.

Find it yourself

Harder by hand, because the answer is inside the role rather than on it. Export the roles held by your application users and read their privilege lists for anything covering role creation, role assignment, user creation, or team write. In a large environment this is where the manual approach starts costing real time.

How to fix it

Remove the security-metadata write privileges; put any genuine user management behind human approval.

Related controls

SOC 2 CC6.3ISO 27001 A.8.2NIST AC-6(1) / AC-3

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.