An integration account that can grant itself privileges
What it is
Integration can rewrite the security model.
Why it matters
A service account whose role can create roles, assign roles, or provision users can bootstrap itself to full control through the API alone. No production integration needs this.
Find it yourself
Harder by hand, because the answer is inside the role rather than on it. Export the roles held by your application users and read their privilege lists for anything covering role creation, role assignment, user creation, or team write. In a large environment this is where the manual approach starts costing real time.
How to fix it
Remove the security-metadata write privileges; put any genuine user management behind human approval.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L2-3.1.5 (Level 2: employ least privilege, including for privileged accounts and security functions), for the Dataverse system in your assessment scope. An account that can grant itself privileges has no ceiling. Whatever least privilege was configured describes where that account started, not how far it can reach.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.