PathixDataverse Forensics

← All 53 findings

Public exposure & portal security

A Power Pages table permission granting anonymous read

Severity up to High

What it is

Anonymous portal visitors can read this table.

Why it matters

A table permission grants Read to the site's anonymous users role. It governs the portal Web API, not only what a page renders, so at Global scope a visitor who never sees a list page can still query every row.

This is a statement about the table permission layer, not a verdict that the data is public. Pathix reads five of the six configuration layers that decide portal reach; site visibility, whether the site is public or behind a sign-in wall, is not readable by an unattended scan, and a private site neutralises this entirely. Nor is it automatically wrong: reference data a public form needs, such as a list of states or service types, is legitimately readable by anyone, and Global scope is the correct way to configure it. Pathix cannot tell a lookup table from a business table by metadata alone. Severity follows the declared reach: High at Global, or where the scope is unrecognised or its parent chain cannot be resolved, because an unknown reach is not a small one; Medium for Contact, Account and Self scopes, which key off a signed-in contact an anonymous visitor does not have.

Find it yourself

Portal Management, Table Permissions, filtered to those attached to the role marked as the anonymous users role. Read the roles from that form, not the advertised relationship, which reads back empty on the enhanced data model however many times you attach it. Then read the scope: Global puts every row of the table in range, while Contact, Account and Self key off a signed-in contact an anonymous visitor does not have, so those reach almost nothing and usually mean a misconfiguration rather than an exposure. Verify by loading the page in a private browser window with no session.

How to fix it

Confirm the anonymous role belongs on the permission. If the table holds anything not meant for the public, detach the role or narrow the scope.

Related controls

SOC 2 CC6.1ISO 27001 A.5.15 / A.8.3NIST AC-3 / AC-22

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC AC.L2-3.1.22 (L1)

This condition produces evidence for AC.L2-3.1.22 (Level 1: control information posted or processed on publicly accessible systems), for the Dataverse system in your assessment scope. 3.1.22 is about what a publicly accessible system is allowed to hold. The permission governs the portal Web API, not only what a page renders, so at Global scope a visitor who never sees a list page can still query every row. Pathix reads five of the six layers that decide portal reach; site visibility is not readable by scan, so this reports what the configuration grants rather than confirming the data is public.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in public exposure & portal security

← Back to all 53 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π