A Power Pages table permission letting anonymous visitors write
What it is
Anonymous portal visitors can change data in this table.
Why it matters
A table permission grants Write, Create, or Delete to the site's anonymous users role, so visitors who have not signed in can change stored data.
Reported separately from anonymous read for a reason worth knowing: the tenant setting administrators reach for first, which disables anonymous access, blocks anonymous reads and does not revoke anonymous write. Someone who flipped that switch and considered it closed has shut the read path and left this one open. It does not depend on a form existing, because a table permission governs the portal Web API. Severity follows the privileges: Create alone is the normal shape of a public submission form and reports at High, while Write or Delete reach records that already exist and report at Critical. Pathix reads five of the six layers deciding portal reach and cannot read site visibility, so this is what the configuration grants rather than confirmed exposure.
Find it yourself
Portal Management, Table Permissions, filtered to those whose web roles include the role marked as the anonymous users role, then read the privileges on each. Read the roles from that form rather than the advertised relationship, which on the enhanced model saves and then reads back empty. Create alone is the normal shape of a public submission form; Write or Delete reach records that already exist, which no submission form needs.
How to fix it
Detach the anonymous role, or split the permission so anonymous visitors keep only Create, which is all a public submission form needs.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L2-3.1.22 (Level 1: control information posted or processed on publicly accessible systems) and AC.L2-3.1.2 (Level 1: limit access to the transactions and functions authorized users may execute), for the Dataverse system in your assessment scope. The tenant switch that disables anonymous access blocks anonymous reads and does not revoke anonymous write, so an administrator who flipped it and moved on has closed one path and left this one open. Pathix reads five of the six layers deciding portal reach and cannot read site visibility, so this is what the configuration grants, not confirmed public exposure.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.