PathixDataverse Forensics

← All 40 findings

Access & least privilege

A security role assigned to both people and integrations

Severity High

What it is

Security role assigned to both human users and integrations.

Why it matters

One role held by both people and service accounts means every privilege you add hits both audiences at once, and a stolen integration key inherits full human access.

Find it yourself

List every application user (a systemuser row with applicationid set) alongside its roles, then group the result by role instead of by user. Any role whose holders include both a row with applicationid set and a row without it is shared. There is no built-in screen for this, which is most of why it survives.

How to fix it

Split the role in two: humans on one copy, integrations on the other.

Related controls

SOC 2 CC6.3ISO 27001 A.5.15 / A.5.18NIST AC-5 / AC-6

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.