A secured value copied into an unsecured column
What it is
Secured column value lands in an unsecured column.
Why it matters
A column mapping or formula copies a secured value into an unsecured column, so anyone who can read the destination reads the protected value without a grant. An active leak of data you deliberately gated.
Find it yourself
List your secured columns, then check two things for each: attribute mappings from that column to a child table, and any calculated or rollup column whose formula reads it. Where the destination is not itself secured, the protection is bypassed. This is the highest-value check in this family and the least likely to be done.
How to fix it
Secure the destination the same way or break the mapping, and clear values already copied.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L2-3.1.3 (Level 2: control the flow of CUI in line with approved authorizations), for the Dataverse system in your assessment scope. Flow control is about where protected values are permitted to travel. A copy into an unsecured column moves the value out from behind the profile that was protecting it, and no access check refuses, because none is consulted.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.