A sensitive column whose changes are not audited
What it is
Sensitive column changes are not being audited.
Why it matters
Auditing a secured column needs the org, table, and column switches all on. If any is off, no history is written, so who changed a sensitive value and when cannot be reconstructed.
Find it yourself
Check all three levels for each column that matters: the organization audit setting, the table's audit flag, and the column's own. Any one of them off means no history is written, and the gap is silent. Checking only the table level is the usual mistake.
How to fix it
Turn on all three switches and set retention to match your compliance requirement.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.