PathixDataverse Forensics

← All 40 findings

Identity lifecycle & offboarding

A plugin step that always runs as the same named user

Severity Medium

What it is

Plugin step always runs as one fixed user account.

Why it matters

Every change the step makes is attributed to one account regardless of who triggered it, obscuring who really acted, and it breaks the day that account leaves.

Find it yourself

Same list as above, but read it for steps impersonating an active named person rather than a service account. This is the one that quietly corrupts your audit trail: every write the step makes wears that person's name.

How to fix it

Confirm the impersonation is intentional and points at a dedicated service account, not a person's login.

Related controls

SOC 2 CC6.1ISO 27001 A.8.15NIST AU-2 / AU-10

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in identity lifecycle & offboarding

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.