A Power Pages access rule with no web role attached
What it is
Page access rule has no web role, so it restricts nothing.
Why it matters
A Restrict Read rule narrows a page to the audience its attached roles describe, so a rule with no roles narrows nothing. The page stays as reachable as it was before anyone created the rule, while the design studio still shows an active restriction on it.
The shape of a half-finished change: someone created the rule and navigated away before picking a role, or removed the last role from a rule that used to work. Read it as a statement about what Pathix read rather than a verdict on the platform. Role attachments on the enhanced data model are stored where the obvious query does not report them, so Pathix reads them the way that does report them, and an empty result here means no attachment was found in that read. The page may also be protected by a different rule further up its inheritance chain.
Find it yourself
Power Pages design studio, open the rule and check the web roles on it. Confirm in the studio before treating the page as unprotected, then verify from a private browser window with no session by opening the page and confirming you either reach it or are stopped, whichever you intended.
How to fix it
Attach the roles that should keep access, or delete the rule so the configuration stops advertising a protection the page does not have.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.