A security role assigned to both people and integrations
What it is
Security role assigned to both human users and integrations.
Why it matters
One role held by both people and service accounts means every privilege you add hits both audiences at once, and a stolen integration key inherits full human access.
Find it yourself
List every application user (a systemuser row with applicationid set) alongside its roles, then group the result by role instead of by user. Any role whose holders include both a row with applicationid set and a row without it is shared. There is no built-in screen for this, which is most of why it survives.
How to fix it
Split the role in two: humans on one copy, integrations on the other.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L1-3.1.1 (Level 1: limit system access to authorized users, processes and devices) and AC.L2-3.1.4 (Level 2: separate duties so no individual can act without collusion), for the Dataverse system in your assessment scope. An assessor testing separation of duties asks which principals hold a given role. When one role is held by both a person and a service account, the access record cannot tell the two apart, so the question has no answer on this system.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.