Global Power Platform
Bootcamp, Bulgaria 2021
Crack the insecurity with Power Platform Security
- Dipti Chhatrapati, Modern Workplace Architect, AIS.
Global Power platform Bootcamp Bulgaria 2021
Thanks to our Sponsors
With the support of:
Global Power platform Bootcamp Bulgaria 2021
Agenda
Tenant Level
Access Control
Environment
Isolation
Resource-level
security
Connection
security and
DLP
Dataverse
Access Levels
Balance the
privileges
Separate
illusion from
the reality
Make a
promise to
be secured
Set the
relationships
& boundaries
Organize
realistic
routine
1
2
3
4
5
Global Power platform Bootcamp Bulgaria 2021
Security is built into every layer of the stack.
Resource permissions
Microsoft Dataverse security
Dev
Test
Environment
Prod
Tenant access & isolation
1
3
4
5
2 Environment access & strategy
Connector access and data loss policies
Global Power platform Bootcamp Bulgaria 2021
Tenant Level Access Control
Power Apps Power Automate
Internal user cannot establish
a connection using external
tenant credentials
External user cannot
establish a connection
using internal tenant
credentials
INTERNAL TENANT
EXTERNAL TENANT
Power Apps Power Automate
1
AAD Conditional policies by
Device/Location/User/Group
Global Power platform Bootcamp Bulgaria 2021
Environment Isolation
Restrict environment creation to Power Platform/Dynamic 365 Admins only
Provision personal apps in Default and non-personal apps in Sandbox/Production env.
•Dev/Test/Production environments for specific business groups or application
Configure DLP policies for all environments to restrict connectors
Non-default and non-developer environments with Dataverse can be restricted with
specific AAD security group.
2
Global Power platform Bootcamp Bulgaria 2021
Resource Level Security
Share via
Security
Role
Co-
Ownership
to Share
Co-
Ownership
to Edit
Co-
Ownership
to Use
Canvas App Canvas App
• To edit, update and
delete this flow.
• access the run
history and add or
remove other
owners.
Cloud Flow Model Driven App
• Environment Admin
• Environment Maker
• Basic User
• System Admin
• System Customizer
3
Global Power platform Bootcamp Bulgaria 2021
Connectors and Data Loss Prevention Policies
Data
Connectors
Connection
Power Platform Resources
4
Global Power platform Bootcamp Bulgaria 2021
Connectors and Data Loss Prevention Policies
Connectors Grouping –
Business/Non-Business/Blocked
Tenant Level and
Environment Level
DLP policies
Set policies using
connectors/Admin
center/PowerShell
4
Most restrictive DLP –
Default/new environment (Tenant, all env. except )
Org Productivity DLP –
LOB environments ( Tenant , Include env.)
Org IT management DLP -
Central IT environment ( Tenant , Include env.)
Special Env DLP –
Special Application Environment ( Environment, Single Env.)
Global Power platform Bootcamp Bulgaria 2021
Microsoft Dataverse Security
Field
Level Security
Record level security
Business Units and Teams
Security Roles and Privileges ( Users/Teams)
Read-Create-Update
Create-Read-Write-Delete-Append-Append To-Assign-Share
Security boundary for the users data / work with security role’s scope
Environment Admin - Environment Maker - Common Data Service User - System Admin - System Customizer
5
Global Power platform Bootcamp Bulgaria 2021
Default BU
BU 1
BU 1.1
BU 1.1.1
BU 1.2
BU 2
BU 2.1 BU 2.2
BU 2.2.2
Tamra Jeramy
Lucas Ren Gavin Ross Tobias
Weston
Tom
Dipti
Record
Scope
Who can access?
Create-Read-Write-Delete-Append-
Append To-Assign-Share
Global Anyone in the organization
Deep Any user from assigned business unit and
it’s child business unit
Local Any user from assigned business unit
Basic User who owns
Record Level Security
Epic Manager Security Role
Create Read Write Delete
 Anyone can create record
 Tamra can only read all records from BU 1/1.2/1.1/1.1.1
User experience with Epic Manager Security Role
 Lucas can only write records from BU 1.1
 Ross can only delete record created by him in BU 2.1
Global Power platform Bootcamp Bulgaria 2021
DEMO
How user connects to
external tenant which
should be restricted?
How environments can
be restricted?
How are resources
shared with
users/Security groups?
How are connectors
grouped with DLP?
How records can be
secured via security
roles/scopes?
Global Power platform Bootcamp Bulgaria 2021
Thank you for joining!
With the support of:
Join Dynamic 365 Trial Tenant:
https://docs.microsoft.com/en-
us/dynamics365/marketing/trial-signup
Administering Power Platform :
https://docs.microsoft.com/en-us/power-
platform/admin/admin-documentation
Power Platform Best Practices:
https://docs.microsoft.com/en-us/power-
platform/guidance/adoption/methodology
Global Power platform Bootcamp Bulgaria 2021

More Related Content

PPTX
F17_Unified Governance for Power Automate, Power Apps, Power BI
PPTX
Power Platform Governance Center of Excellence
PPTX
Administering power platform deployment planning
PPTX
Power Platform Governance Webinar
PDF
Ideas & Inspiration: Getting Started & Driving Success With Power Platform At...
PPTX
PL-100 Microsoft Power Platform App Maker
PPTX
Team Nation 2022 - How to choose between Dataverse, SQL Azure, SharePoint lis...
PPTX
Dataverse meets Teams: low code app opportunities for everyone
F17_Unified Governance for Power Automate, Power Apps, Power BI
Power Platform Governance Center of Excellence
Administering power platform deployment planning
Power Platform Governance Webinar
Ideas & Inspiration: Getting Started & Driving Success With Power Platform At...
PL-100 Microsoft Power Platform App Maker
Team Nation 2022 - How to choose between Dataverse, SQL Azure, SharePoint lis...
Dataverse meets Teams: low code app opportunities for everyone

What's hot (20)

PDF
Getting Started & Driving Success With Power Platform At Scale
PPTX
Introduction to Power Platform
PDF
IIBA® Sydney Unlocking the Power of Low Code No Code: Why BAs Hold the Key
PPTX
Explore Microsoft Power Platform Center of Excellence
PPTX
Power Apps - Data governance, compliance and security
PPTX
Microsoft power platform
PPTX
Power Platform Governance
PPTX
Microsoft power platform
PPTX
Introduction to power apps
PPTX
Intro to power apps
PPTX
Power BI overview.pptx
PPTX
Introduction to Microsoft Power Platform (PowerApps, Flow)
PDF
Exploring the PowerApps advantage
PDF
Innovation morning power platform
PPTX
PL-900 Microsoft Power Platform Fundamentals
PPTX
Power BI Overview, Deployment and Governance
PPTX
Introduction to PowerApps and Flow
PPTX
An introduction to microsoft power apps
PDF
Powerapps & Flow
PDF
Power BI Charts Tutorial | Counter Strike Data Analysis using Power BI | Powe...
Getting Started & Driving Success With Power Platform At Scale
Introduction to Power Platform
IIBA® Sydney Unlocking the Power of Low Code No Code: Why BAs Hold the Key
Explore Microsoft Power Platform Center of Excellence
Power Apps - Data governance, compliance and security
Microsoft power platform
Power Platform Governance
Microsoft power platform
Introduction to power apps
Intro to power apps
Power BI overview.pptx
Introduction to Microsoft Power Platform (PowerApps, Flow)
Exploring the PowerApps advantage
Innovation morning power platform
PL-900 Microsoft Power Platform Fundamentals
Power BI Overview, Deployment and Governance
Introduction to PowerApps and Flow
An introduction to microsoft power apps
Powerapps & Flow
Power BI Charts Tutorial | Counter Strike Data Analysis using Power BI | Powe...
Ad

Similar to Power platform Bootcamp Bulgaria 2021 - Power Platform Security (20)

PDF
Rumos-MDD-Step Into Power Platform Presentation
PDF
PPT-Deck-Power-Platform-Virtual-Training-Day-Fundamentals.pdf
PDF
Microsoft power platform
PPTX
Securing the Power Platform - What are my options
PPTX
Dataverse Permissions Demystified - PowerAddicts BE 11-2022.pptx
PPTX
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
PPTX
Enterprise apps using Microsoft Power Platform
PDF
Whitepaper-Power-Platform-ENG.pdf
PDF
Land your data safely and accurately with Power Platform and Azure.pdf
PDF
Empower Your Organization with Microsoft Power Platform
PDF
The Future of Project Management from Microsoft
PDF
Patron Power Platfom Community September 2021 Webinar
PPTX
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
PDF
Application Lifecycle Management (ALM).pdf
PDF
O365Con18 - Deep Dive into Microsoft 365 - Jussi Roine
PPTX
Webinar Mastering Microsoft Security von Baggenstos
PPT
Data power use cases
PPT
20220205 Getting started with power bi
PPTX
Microsoft Intune y Gestión de Identidad Corporativa
PPTX
PL-400T00A-ENU-PowerPoint_03.pptx - Power Platform
Rumos-MDD-Step Into Power Platform Presentation
PPT-Deck-Power-Platform-Virtual-Training-Day-Fundamentals.pdf
Microsoft power platform
Securing the Power Platform - What are my options
Dataverse Permissions Demystified - PowerAddicts BE 11-2022.pptx
2018 11-29 - Future Of SharePoint - SharePoint Keynote and Security
Enterprise apps using Microsoft Power Platform
Whitepaper-Power-Platform-ENG.pdf
Land your data safely and accurately with Power Platform and Azure.pdf
Empower Your Organization with Microsoft Power Platform
The Future of Project Management from Microsoft
Patron Power Platfom Community September 2021 Webinar
Microsoft DirectAccess Remote Access (VPN) with Windows 10 and Server 2012
Application Lifecycle Management (ALM).pdf
O365Con18 - Deep Dive into Microsoft 365 - Jussi Roine
Webinar Mastering Microsoft Security von Baggenstos
Data power use cases
20220205 Getting started with power bi
Microsoft Intune y Gestión de Identidad Corporativa
PL-400T00A-ENU-PowerPoint_03.pptx - Power Platform
Ad

More from Dipti Chhatrapati (18)

PPTX
Entrepreneurship & Innovation – a new DNA to Success
PPTX
Prepare For The Next Decade With Microsoft 365 Hybrid Work at ALI Conference
PPTX
Teams Calling Teams at Aseans MS Women Meetup
PPTX
Grow your SharePoint development platform with SharePoint Framework
PPTX
Microsoft365 developer opportunity welcome keynote
PPTX
Building share point framework solutions
PPTX
Developing business applications via power platform build2019
PPTX
Introduction to graph services
PPTX
Grow your SharePoint development platform with SPFx
PPTX
SPS Bangalore 2018 Opening
PPTX
SPS Bangalore 2018 - SharePoint Hybrid
PPTX
Being INSIGHTFUL is the only way to get on SharePoint Hybrid !
PPTX
Microsoft Business Platform for real time applications
PPTX
Share point 2016 end user training module 1 - introduction
PPTX
Share point 2016 end user training overview
PPTX
Custom Connectors for Microsoft Flow - Your Service Is My Command
PPTX
Automating your tasks with microsoft flow
PPTX
Microsoft Graph API - A Single Stop For Your Cloud Solution
Entrepreneurship & Innovation – a new DNA to Success
Prepare For The Next Decade With Microsoft 365 Hybrid Work at ALI Conference
Teams Calling Teams at Aseans MS Women Meetup
Grow your SharePoint development platform with SharePoint Framework
Microsoft365 developer opportunity welcome keynote
Building share point framework solutions
Developing business applications via power platform build2019
Introduction to graph services
Grow your SharePoint development platform with SPFx
SPS Bangalore 2018 Opening
SPS Bangalore 2018 - SharePoint Hybrid
Being INSIGHTFUL is the only way to get on SharePoint Hybrid !
Microsoft Business Platform for real time applications
Share point 2016 end user training module 1 - introduction
Share point 2016 end user training overview
Custom Connectors for Microsoft Flow - Your Service Is My Command
Automating your tasks with microsoft flow
Microsoft Graph API - A Single Stop For Your Cloud Solution

Recently uploaded (20)

PDF
Pink Cute Simple Group Project Presentation.pdf
PDF
Chembond Chemicals Limited Presentation 2025
PPTX
Market and Demand Analysis.pptx for Management students
PPTX
Enterprises are Classified into Two Categories
PPTX
PwC consulting Powerpoint Graphics 2014 templates
PDF
757557697-CERTIKIT-ISO22301-Implementation-Guide-v6.pdf
PDF
Investment in CUBA. Basic information for United States businessmen (1957)
PDF
From Legacy to Velocity: how we rebuilt everything in 8 months.
PPTX
Capital Investment in IS Infrastracture and Innovation (SDG9)
PDF
El futuro empresarial 2024 una vista gen
DOCX
ola and uber project work (Recovered).docx
PPTX
UNIT 3 INTERNATIONAL BUSINESS [Autosaved].pptx
PDF
Handouts for Housekeeping.pdfhsjsnvvbdjsnwb
PDF
Nante Industrial Plug Socket Connector Sustainability Insights
PDF
the role of manager in strategic alliances
PPTX
Business Research Methods- Secondary Data
PPT
BCG内部幻灯片撰写. slide template BCG.slide template
DOCX
Center Enamel Enabling Precision and Sustainability in the Netherlands' Advan...
PPTX
Side hustles: 14 powerful tips to embrace the future of work
PDF
The Impact of Immigration on National Identity (www.kiu.ac.ug)
Pink Cute Simple Group Project Presentation.pdf
Chembond Chemicals Limited Presentation 2025
Market and Demand Analysis.pptx for Management students
Enterprises are Classified into Two Categories
PwC consulting Powerpoint Graphics 2014 templates
757557697-CERTIKIT-ISO22301-Implementation-Guide-v6.pdf
Investment in CUBA. Basic information for United States businessmen (1957)
From Legacy to Velocity: how we rebuilt everything in 8 months.
Capital Investment in IS Infrastracture and Innovation (SDG9)
El futuro empresarial 2024 una vista gen
ola and uber project work (Recovered).docx
UNIT 3 INTERNATIONAL BUSINESS [Autosaved].pptx
Handouts for Housekeeping.pdfhsjsnvvbdjsnwb
Nante Industrial Plug Socket Connector Sustainability Insights
the role of manager in strategic alliances
Business Research Methods- Secondary Data
BCG内部幻灯片撰写. slide template BCG.slide template
Center Enamel Enabling Precision and Sustainability in the Netherlands' Advan...
Side hustles: 14 powerful tips to embrace the future of work
The Impact of Immigration on National Identity (www.kiu.ac.ug)

Power platform Bootcamp Bulgaria 2021 - Power Platform Security

  • 1. Global Power Platform Bootcamp, Bulgaria 2021 Crack the insecurity with Power Platform Security - Dipti Chhatrapati, Modern Workplace Architect, AIS. Global Power platform Bootcamp Bulgaria 2021
  • 2. Thanks to our Sponsors With the support of: Global Power platform Bootcamp Bulgaria 2021
  • 3. Agenda Tenant Level Access Control Environment Isolation Resource-level security Connection security and DLP Dataverse Access Levels Balance the privileges Separate illusion from the reality Make a promise to be secured Set the relationships & boundaries Organize realistic routine 1 2 3 4 5 Global Power platform Bootcamp Bulgaria 2021
  • 4. Security is built into every layer of the stack. Resource permissions Microsoft Dataverse security Dev Test Environment Prod Tenant access & isolation 1 3 4 5 2 Environment access & strategy Connector access and data loss policies Global Power platform Bootcamp Bulgaria 2021
  • 5. Tenant Level Access Control Power Apps Power Automate Internal user cannot establish a connection using external tenant credentials External user cannot establish a connection using internal tenant credentials INTERNAL TENANT EXTERNAL TENANT Power Apps Power Automate 1 AAD Conditional policies by Device/Location/User/Group Global Power platform Bootcamp Bulgaria 2021
  • 6. Environment Isolation Restrict environment creation to Power Platform/Dynamic 365 Admins only Provision personal apps in Default and non-personal apps in Sandbox/Production env. •Dev/Test/Production environments for specific business groups or application Configure DLP policies for all environments to restrict connectors Non-default and non-developer environments with Dataverse can be restricted with specific AAD security group. 2 Global Power platform Bootcamp Bulgaria 2021
  • 7. Resource Level Security Share via Security Role Co- Ownership to Share Co- Ownership to Edit Co- Ownership to Use Canvas App Canvas App • To edit, update and delete this flow. • access the run history and add or remove other owners. Cloud Flow Model Driven App • Environment Admin • Environment Maker • Basic User • System Admin • System Customizer 3 Global Power platform Bootcamp Bulgaria 2021
  • 8. Connectors and Data Loss Prevention Policies Data Connectors Connection Power Platform Resources 4 Global Power platform Bootcamp Bulgaria 2021
  • 9. Connectors and Data Loss Prevention Policies Connectors Grouping – Business/Non-Business/Blocked Tenant Level and Environment Level DLP policies Set policies using connectors/Admin center/PowerShell 4 Most restrictive DLP – Default/new environment (Tenant, all env. except ) Org Productivity DLP – LOB environments ( Tenant , Include env.) Org IT management DLP - Central IT environment ( Tenant , Include env.) Special Env DLP – Special Application Environment ( Environment, Single Env.) Global Power platform Bootcamp Bulgaria 2021
  • 10. Microsoft Dataverse Security Field Level Security Record level security Business Units and Teams Security Roles and Privileges ( Users/Teams) Read-Create-Update Create-Read-Write-Delete-Append-Append To-Assign-Share Security boundary for the users data / work with security role’s scope Environment Admin - Environment Maker - Common Data Service User - System Admin - System Customizer 5 Global Power platform Bootcamp Bulgaria 2021
  • 11. Default BU BU 1 BU 1.1 BU 1.1.1 BU 1.2 BU 2 BU 2.1 BU 2.2 BU 2.2.2 Tamra Jeramy Lucas Ren Gavin Ross Tobias Weston Tom Dipti Record Scope Who can access? Create-Read-Write-Delete-Append- Append To-Assign-Share Global Anyone in the organization Deep Any user from assigned business unit and it’s child business unit Local Any user from assigned business unit Basic User who owns Record Level Security Epic Manager Security Role Create Read Write Delete  Anyone can create record  Tamra can only read all records from BU 1/1.2/1.1/1.1.1 User experience with Epic Manager Security Role  Lucas can only write records from BU 1.1  Ross can only delete record created by him in BU 2.1 Global Power platform Bootcamp Bulgaria 2021
  • 12. DEMO How user connects to external tenant which should be restricted? How environments can be restricted? How are resources shared with users/Security groups? How are connectors grouped with DLP? How records can be secured via security roles/scopes? Global Power platform Bootcamp Bulgaria 2021
  • 13. Thank you for joining! With the support of: Join Dynamic 365 Trial Tenant: https://docs.microsoft.com/en- us/dynamics365/marketing/trial-signup Administering Power Platform : https://docs.microsoft.com/en-us/power- platform/admin/admin-documentation Power Platform Best Practices: https://docs.microsoft.com/en-us/power- platform/guidance/adoption/methodology Global Power platform Bootcamp Bulgaria 2021