PathixDataverse Forensics

← All 40 findings

Secrets & transmission security

A credential stored in a plugin step's unsecure configuration

Severity High

What it is

Plugin step has a secret embedded in unsecure configuration.

Why it matters

A credential sits in a plugin step's unsecure config, readable by anyone who can read the registration and carried into solution exports and source control. Pathix reports the pattern and a redacted length, never the value.

Find it yourself

Read the unsecure configuration of every plugin step in the Plugin Registration Tool and look for credential-shaped values: keys, tokens, connection strings, passwords. Remember that unsecure configuration travels in solution exports, so it is also worth searching any exported solution you have in source control.

How to fix it

Move it to Azure Key Vault via an environment variable, and rotate the exposed credential.

Related controls

SOC 2 CC6.1ISO 27001 A.5.17 / A.8.24NIST IA-5 / SC-28

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in secrets & transmission security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.