A credential stored in a plugin step's unsecure configuration
What it is
Plugin step has a secret embedded in unsecure configuration.
Why it matters
A credential sits in a plugin step's unsecure config, readable by anyone who can read the registration and carried into solution exports and source control. Pathix reports the pattern and a redacted length, never the value.
Find it yourself
Read the unsecure configuration of every plugin step in the Plugin Registration Tool and look for credential-shaped values: keys, tokens, connection strings, passwords. Remember that unsecure configuration travels in solution exports, so it is also worth searching any exported solution you have in source control.
How to fix it
Move it to Azure Key Vault via an environment variable, and rotate the exposed credential.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for IA.L2-3.5.10 (Level 2: store and transmit only cryptographically protected passwords), for the Dataverse system in your assessment scope. Unsecure configuration is readable by anyone who can read the step registration. The credential is sitting in cleartext in a place nothing treats as a secret store.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.