PathixDataverse Forensics

← All 53 findings

Integration & automation reliability

A Power Pages permission whose parent chain does not terminate

Severity MediumCoverage

What it is

Portal table permission has a parent chain that cannot be resolved.

Why it matters

A permission uses Parent scope but the chain cannot be followed to a root, so its real reach is undetermined: anywhere between nothing and every row.

Either the chain loops, or it names a parent that does not exist, or it declares Parent scope with no parent set. Pathix will not guess in either direction, because guessing narrow would understate exposure and guessing wide would manufacture it. It makes no claim about what the portal runtime does with a broken chain at request time, only that the configuration does not describe a reachable set.

Find it yourself

In the Portal Management app, open any Parent-scoped table permission and follow its parent link until the chain terminates. A chain that returns to a permission you have already visited, or points at one that no longer exists, is the finding. Pathix makes no claim about what the runtime does with a broken chain at request time, only that the configuration does not describe a reachable set.

How to fix it

Set a parent permission that resolves to a real scope, or move the permission off Parent scope if the relationship it depended on is gone.

Not a security finding

This one is environment health, so it carries a plain label and no control mapping. Presenting an operational gap as a security finding would make the real security findings harder to trust, so we keep the two apart.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in integration & automation reliability

← Back to all 53 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π