A role-holding team with both people and service accounts in it
What it is
Team mixes human members and integrations while holding roles.
Why it matters
A role-holding team with both people and service accounts as members grants every privilege to both, the same shared-role risk arriving through team membership, where the direct check cannot see it.
Find it yourself
Query team, link through teamroles to confirm the team holds a role at all, then link through teammembership to systemuser and read applicationid on each member. Teams with a mix of null and non-null applicationid are the finding. A direct role-assignment check will not surface these.
How to fix it
Move integrations onto a dedicated team with its own least-privilege role.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L2-3.1.4 (Level 2: separate duties so no individual can act without collusion), for the Dataverse system in your assessment scope. Team membership is the indirect route to a role, so an assessor tracing duty separation through direct assignments alone never sees this one.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.