A plugin step set to run as a disabled user
What it is
Plugin step impersonates a disabled user account.
Why it matters
A step set to always run as a disabled user fails every time it fires, because Dataverse cannot build a run-as context for a disabled principal.
Find it yourself
In the Plugin Registration Tool, check the run-as user on every step. Steps with an impersonating user set are worth listing, then cross-reference those users against disabled accounts. This one fails loudly at runtime, so it is often already a known problem without anyone having identified the cause.
How to fix it
Repoint the impersonation to an active service account, or remove it so the step runs as the caller.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for PS.L2-3.9.2 (Level 2: protect systems containing CUI during and after personnel actions such as termination), for the Dataverse system in your assessment scope. The step runs as a user the organization has already offboarded, so a personnel action completed in the directory was never completed in this system.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.