PathixDataverse Forensics

← All 72 findings

Identity lifecycle & offboarding

A plugin step that always runs as the same named user

Severity Medium

What it is

Plugin step always runs as one fixed user account.

Why it matters

Every change the step makes is attributed to one account regardless of who triggered it, obscuring who really acted, and it breaks the day that account leaves.

Find it yourself

Same list as above, but read it for steps impersonating an active named person rather than a service account. This is the one that quietly corrupts your audit trail: every write the step makes wears that person's name.

How to fix it

Confirm the impersonation is intentional and points at a dedicated service account, not a person's login.

Related controls

SOC 2 CC6.1ISO 27001 A.8.15NIST AU-2 / AU-10

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC AU.L2-3.3.2

This condition produces evidence for AU.L2-3.3.2 (Level 2: ensure the actions of individual users can be uniquely traced to them), for the Dataverse system in your assessment scope. Every write the step makes is attributed to one named person who did not make it. The audit trail is not merely incomplete here, it is confidently wrong about who acted.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in identity lifecycle & offboarding

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π