Before you change an inherited Dynamics environment, you'd like to know what's already wrong with it, preferably before the auditors do. In Dynamics 365, security risk hides in configuration.
A role that can rewrite other roles, a disabled account that kept its access, a Power Pages permission for anonymous visitors, a secret pasted into a plugin step, an agent that never asks anyone to sign in. Each one is a different setting to open and read.
Each check is deterministic, run against the metadata Pathix already read. In the demo environment that's ninety open security findings, ten of them critical, among them a table permission on the partner site configured to let anonymous visitors create and change rows across the whole table. And an empty list never means safe: it means no check fired.
The integration from Ep. 02 holds a Microsoft role that can rewrite the security model: Critical. Where a control applies, the finding names it too, as evidence for your review, not an audit opinion. Pathix fixes nothing: the next scan sees the condition gone, and marks it resolved.
One Pathix call returns the open findings, ranked, each with its fix. With the Dataverse MCP alone, your agent would have to write each check, and run it.
A read-only metadata scan of your environment that reads the logic inside the components: compiled plugins, flow definitions, workflow XAML and scripts.
How it works →What Solution Checker checks, and what it doesn't→All questions →
A 30-minute walkthrough on a pre-scanned demo environment. No access to your tenant, nothing to install.