PathixDataverse Forensics

← All 72 findings

Access & least privilege

A role-holding team with both people and service accounts in it

Severity High

What it is

Team mixes human members and integrations while holding roles.

Why it matters

A role-holding team with both people and service accounts as members grants every privilege to both, the same shared-role risk arriving through team membership, where the direct check cannot see it.

Find it yourself

Query team, link through teamroles to confirm the team holds a role at all, then link through teammembership to systemuser and read applicationid on each member. Teams with a mix of null and non-null applicationid are the finding. A direct role-assignment check will not surface these.

How to fix it

Move integrations onto a dedicated team with its own least-privilege role.

Related controls

SOC 2 CC6.3ISO 27001 A.5.15 / A.5.18NIST AC-5 / AC-6

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

CMMC relevance

CMMC AC.L2-3.1.4

This condition produces evidence for AC.L2-3.1.4 (Level 2: separate duties so no individual can act without collusion), for the Dataverse system in your assessment scope. Team membership is the indirect route to a role, so an assessor tracing duty separation through direct assignments alone never sees this one.

Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.

Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 72 findings

© 2026 Pathix L.L.C. · self-hosted · metadata-only
Not affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.π