A Power Pages site with the local credential store still enabled
What it is
Site still accepts local username and password logins.
Why it matters
The site still accepts local username and password logins, so it runs a credential store outside your identity provider's controls: password rules, lockout and two-factor posture are the site's, not your tenant's.
Microsoft treats the local identity store as deprecated and recommends moving portal authentication to an external provider. Credential-stuffing attempts land on the portal rather than on an identity platform built to absorb them. Sites created before external providers were configured often keep this on without anyone deciding to. Like open registration, it fires on a platform default that is enabled, so an absent setting row means local login is on and the finding is right.
Find it yourself
Portal Management, Site Settings, look for Authentication/Registration/LocalLoginEnabled. As with open registration, the platform default is enabled, so an absent setting row means local login is on rather than off. Confirm by loading the sign-in page and checking whether it still offers a username and password form.
How to fix it
Configure an external identity provider, migrate existing local accounts, then set LocalLoginEnabled to false explicitly.
No control mapping, deliberately
This is a security finding that carries no SOC 2, ISO 27001, NIST 800-53 or CMMC reference. That is a decision rather than an omission. Pathix maps a finding to a control only where the mapping is defensible to an assessor, and a stretched one would undermine every mapping that is real.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.