A service endpoint nothing triggers
What it is
Service endpoint or webhook with no plugin step binding.
Why it matters
An endpoint is registered but nothing triggers it. Not an active risk alone, but an over-permissioned or long-unused endpoint is worth cleaning up.
Find it yourself
Cross-reference registered service endpoints against the steps that route to them. Unreferenced endpoints often still carry a live credential in their definition, which is the reason to clean them up rather than leave them.
How to fix it
Delete it if unused and rotate any credential baked into its definition.
Not a security finding
This one is environment health, so it carries a plain label and no control mapping. Presenting an operational gap as a security finding would make the real security findings harder to trust, so we keep the two apart.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.