PathixDataverse Forensics

← All 40 findings

Access & least privilege

A non-admin role that can grant itself administrator

Severity High

What it is

Human user holds a role that can rewrite the security model.

Why it matters

A non-admin whose custom role grants role or user administration can grant themselves anything through the API: a low-privilege login that can bootstrap itself to full control.

Find it yourself

Same method as the integration version, pointed at roles held by human users. Read the privilege list of every custom role for role and user administration. Built-in administrative roles are expected to hold these; a custom business role holding them is the finding.

How to fix it

Remove those privileges, reserve admin for named people, and turn on prevent-elevation-of-privilege.

Related controls

SOC 2 CC6.3ISO 27001 A.8.2NIST AC-6(1) / AC-6(10)

These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.

Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.

More in access & least privilege

← Back to all 40 findings

Pathix

Forensics for Dynamics 365 and the Dataverse.

See it on sample data →
USE CASES
CAPABILITIES
  • What we check
  • Dataverse MCPsoon
  • Dependency analysissoon
  • Migration impactsoon
PRODUCT
COMPANY
© 2026 Pathix · self-hosted · metadata-onlyNot affiliated with Microsoft. Dynamics 365, Dataverse, and Power Platform are trademarks of Microsoft Corporation.