PathixDataverse Forensics

← All 40 findings

Access & least privilege

A role-holding team with both people and service accounts in it

Severity High

What it is

Team mixes human members and integrations while holding roles.

Why it matters

A role-holding team with both people and service accounts as members grants every privilege to both, the same shared-role risk arriving through team membership, where the direct check cannot see it.

Find it yourself

Query team, link through teamroles to confirm the team holds a role at all, then link through teammembership to systemuser and read applicationid on each member. Teams with a mix of null and non-null applicationid are the finding. A direct role-assignment check will not surface these.

How to fix it

Move integrations onto a dedicated team with its own least-privilege role.

Related controls

SOC 2 CC6.3ISO 27001 A.5.15 / A.5.18NIST AC-5 / AC-6

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.