PathixDataverse Forensics

← All 72 findings

Auditability & observability

A sensitive column whose changes are not audited

Severity High / Medium

What it is

Sensitive column changes are not being audited.

Why it matters

Auditing a secured column needs the org, table, and column switches all on. If any is off, no history is written, so who changed a sensitive value and when cannot be reconstructed.

Find it yourself

Check all three levels for each column that matters: the organization audit setting, the table's audit flag, and the column's own. Any one of them off means no history is written, and the gap is silent. Checking only the table level is the usual mistake.

How to fix it

Turn on all three switches and set retention to match your compliance requirement.

Related controls

SOC 2 CC7.2ISO 27001 A.8.15NIST AU-2 / AU-12

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC AU.L2-3.3.1

This condition produces evidence for AU.L2-3.3.1 (Level 2: create and retain audit records sufficient to investigate unauthorized activity), for the Dataverse system in your assessment scope. 3.3.1 is about possessing the record you would investigate with. A column marked sensitive but excluded from auditing produces no record at all, so the investigation ends before it starts.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in auditability & observability

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π