A Power Pages access rule whose web role is the anonymous role
What it is
Page access rule restricts the page to anonymous visitors.
Why it matters
A Restrict Read rule narrows a page to the audience its web roles describe, and one of the roles attached here is marked as an anonymous users role. The page reads as protected in the design studio and admits visitors who have not signed in.
Almost always a picker mistake rather than a decision, because the anonymous role sits in the same list as the roles a maker actually meant to choose. A site can carry more than one role flagged anonymous, so the finding names every one it found on the rule. Read the reach claim carefully: this describes the page permission layer, and what a visitor sees also depends on site visibility, which is not readable by an unattended scan. Page permissions gate what pages render and never the site's Web API, so closing this does not by itself close a data path.
Find it yourself
Power Pages design studio, open the page's access control rule and read its web roles. Compare each against the role marked as the anonymous users role on the site. Verify from a private browser window with no session by opening the page and confirming you are stopped at the sign-in wall.
How to fix it
Remove the anonymous role and attach the roles that should keep access. If the page is genuinely public, delete the rule rather than leave a restriction that admits everyone.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L1-3.1.22 (Level 1: control information posted or processed on publicly accessible systems), for the Dataverse system in your assessment scope. 3.1.22 turns on what a publicly accessible system is allowed to hold. A page carrying an access rule reads as decided rather than overlooked, which is exactly why an anonymous role on that rule is worth an assessor's attention: the restriction exists, it was configured deliberately, and it admits everyone. Pathix reads the page permission layer; site visibility is not readable by scan, so this is what the rule grants rather than confirmed public reach.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.