A Power Pages site with no default publishing state, or several
What it is
Site publishing states do not name exactly one default.
Why it matters
Publishing states decide whether a page is visible to visitors, and the default is the state new pages start in. With none flagged, new content lands in an undetermined state and authors find pages that will not appear; with several, content can go live before its author intended.
A statement about the site's publishing configuration rather than about any particular page. Existing pages keep whatever state they were already assigned; it is new and newly copied content that lands unpredictably, which is why the pages worth reviewing after fixing this are the recently created ones. The Power Pages design studio warns about both cases.
Find it yourself
Power Pages design studio, open the site's publishing states and count how many carry the default flag. Verify by creating a throwaway page, confirming it starts in the state you expect, and deleting it.
How to fix it
Flag exactly one state as the default, normally the unpublished or draft state so new content starts invisible, and clear the flag from the others.
Not a security finding
This one is environment health, so it carries a plain label and no control mapping. Presenting an operational gap as a security finding would make the real security findings harder to trust, so we keep the two apart.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.