A plugin step whose required privilege no role grants
What it is
No operational role grants the required privilege.
Why it matters
A plugin step runs on a CRUD message against a table whose privilege no operational role grants, so least-privilege users hit access errors and the step does not execute. A functional-coverage gap, not over-privilege.
Find it yourself
For each plugin step, note its message and target table, then check whether any role your users actually hold grants the matching create, write or delete privilege on that table. System Administrator does not count, since it holds everything by definition and tells you nothing about the real user population.
How to fix it
Add the missing privilege to a role the users already hold, custom or out-of-the-box.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.