A non-admin role that can grant itself administrator
What it is
Human user holds a role that can rewrite the security model.
Why it matters
A non-admin whose custom role grants role or user administration can grant themselves anything through the API: a low-privilege login that can bootstrap itself to full control.
Find it yourself
Same method as the integration version, pointed at roles held by human users. Read the privilege list of every custom role for role and user administration. Built-in administrative roles are expected to hold these; a custom business role holding them is the finding.
How to fix it
Remove those privileges, reserve admin for named people, and turn on prevent-elevation-of-privilege.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
CMMC relevance
This condition produces evidence for AC.L2-3.1.5 (Level 2: employ least privilege, including for privileged accounts and security functions) and AC.L2-3.1.7 (Level 2: prevent non-privileged users from executing privileged functions, and log it when they do), for the Dataverse system in your assessment scope. 3.1.7 turns on the boundary between privileged and non-privileged function. A non-admin role that can edit role definitions crosses that boundary through a route no list of administrators will show.
Pathix is not a CMMC compliance platform. It does not assess the rest of your environment, mappings are indicative, and assessment outcomes rest with your assessor.
Pathix checks this across every environment you scan, along with 71 other conditions. Self-hosted in your own Azure, read-only, metadata-only.