PathixDataverse Forensics

← All 72 findings

Access & least privilege

A plugin step whose required privilege no role grants

Severity Medium

What it is

No operational role grants the required privilege.

Why it matters

A plugin step runs on a CRUD message against a table whose privilege no operational role grants, so least-privilege users hit access errors and the step does not execute. A functional-coverage gap, not over-privilege.

Find it yourself

For each plugin step, note its message and target table, then check whether any role your users actually hold grants the matching create, write or delete privilege on that table. System Administrator does not count, since it holds everything by definition and tells you nothing about the real user population.

How to fix it

Add the missing privilege to a role the users already hold, custom or out-of-the-box.

No control mapping, deliberately

This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π