A plugin step whose required privilege no role grants
What it is
No operational role grants the required privilege.
Why it matters
A plugin step runs on a CRUD message against a table whose privilege no operational role grants, so least-privilege users hit access errors and the step does not execute. A functional-coverage gap, not over-privilege.
Find it yourself
For each plugin step, note its message and target table, then check whether any role your users actually hold grants the matching create, write or delete privilege on that table. System Administrator does not count, since it holds everything by definition and tells you nothing about the real user population.
How to fix it
Add the missing privilege to a role the users already hold, custom or out-of-the-box.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.