A role-holding team with both people and service accounts in it
What it is
Team mixes human members and integrations while holding roles.
Why it matters
A role-holding team with both people and service accounts as members grants every privilege to both, the same shared-role risk arriving through team membership, where the direct check cannot see it.
Find it yourself
Query team, link through teamroles to confirm the team holds a role at all, then link through teammembership to systemuser and read applicationid on each member. Teams with a mix of null and non-null applicationid are the finding. A direct role-assignment check will not surface these.
How to fix it
Move integrations onto a dedicated team with its own least-privilege role.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.