We have identified a security issue in Dynamics CRM where users accessing the system via the OData API can retrieve all data. This behavior violates expected security boundaries and could lead to unauthorized data exposure.
Please investigate and provide a resolution or guidance on how to limit data exposure based on user roles for OData API access.