PathixDataverse Forensics

← All 40 findings

Data protection & field security

A field-secured value copied into an unsecured column

Severity High

What it is

Secured column value lands in an unsecured column.

Why it matters

A field mapping or formula copies a secured value into an unsecured column, so anyone who can read the destination reads the protected value without a grant. An active leak of data you deliberately gated.

Find it yourself

List your field-secured columns, then check two things for each: attribute mappings from that column to a child table, and any calculated or rollup column whose formula reads it. Where the destination is not itself secured, the protection is bypassed. This is the highest-value check in this family and the least likely to be done.

How to fix it

Secure the destination the same way or break the mapping, and clear values already copied.

Related controls

SOC 2 CC6.1 / CC6.7ISO 27001 A.8.3 / A.5.12NIST AC-4 / SC-28

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in data protection & field security

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.