PathixDataverse Forensics

← All 40 findings

Access & least privilege

A plugin step whose required privilege no role grants

Severity Medium

What it is

No operational role grants the required privilege.

Why it matters

A plugin step runs on a CRUD message against a table whose privilege no operational role grants, so least-privilege users hit access errors and the step does not execute. A functional-coverage gap, not over-privilege.

Find it yourself

For each plugin step, note its message and target table, then check whether any role your users actually hold grants the matching create, write or delete privilege on that table. System Administrator does not count, since it holds everything by definition and tells you nothing about the real user population.

How to fix it

Add the missing privilege to a role the users already hold, custom or out-of-the-box.

Related controls

SOC 2 CC6.1ISO 27001 A.8.3NIST AC-3

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.