User Security Risks When Creating in Power Platform

Are you worried your users won’t create securely in the Power Platform? Find out what you should and shouldn’t be concerned about in this video!

Watch my 80+ courses on Pluralsight (opens in a new tab)

Video Summary

  • Empowering Users vs. Security Concerns: Allowing business users to create apps can pose security risks if not properly managed. It’s crucial to balance user empowerment with security measures.
  • Potential Risks: Without proper configuration, users can create flows that expose sensitive data, such as copying documents to external services or posting internal messages publicly.
  • Governance and Policies: Microsoft provides tools to secure the Power Platform, but it’s up to organizations to implement data policies, block certain connectors, and ensure proper governance.
  • Training and Monitoring: Educating users on security practices, integrating monitoring, and creating audit trails are essential to prevent misuse and shadow IT.
  • Access Control: Proper governance starts with managing permissions in Microsoft Entra ID, ensuring users have the right access and removing unnecessary permissions as roles change.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

What is the impact of having each one of your business users be able to create an application? Because we go from this very controlled IT-only DevOps scenario where everything is so controlled to now enabling 99% of the users in the organization to start creating apps. Can this be a security concern for enterprises?

I think I’m just thinking out loud here from the perspective of someone who works with cloud infrastructure management. I believe it can definitely affect security if it’s not configured properly. But as far as I know, at the organizational level, all the services we have under Microsoft are integrated with Microsoft Intra ID. So as long as there’s policy and control over that, it should be okay, in my perspective, unless it’s overlooked or missed by the admins of the organization or tenants. Anything to add, Shag, on this?

I’ll go ahead this time and say, as always, our goal as IT admins is to empower the user but still sleep at night. That’s how I define my job: how do I make users productive but not afraid of opening my phone in the morning?

If you don’t configure anything, can people do bad things with the Power Platform? Absolutely. Somebody can set up a flow that whenever a document gets added in SharePoint, it copies it to their Dropbox. Whenever a message is added to the SharePoint intranet, it gets posted on Twitter and things like that. So can users do bad things if you let it wide open? Absolutely. It’s no secret, but that’s the case with anything from external sharing in SharePoint to having people do an Azure function in Azure that’s open or a web app that is not properly secured.

Now, Microsoft gives you the tools to secure it. You have data policies, for example, where you can block connectors. Maybe you have an environment for all your financial stuff in the Power Platform and you say, you know what, in this environment, the Facebook, MailChimp, Blue Sky, whatever connectors are blocked. So you can absolutely secure it, but you will have to do the job to secure it. Microsoft gives us the tools to empower business users while still having a really good governance model, but it’s up to you to go and configure them.

Now, I wish I could point you to a Power Platform admin certification or credential. There is none right now. I keep pushing to have something more admin-focused in the Power Platform, and I think it would be awesome to do it, but there is nothing there yet. But if ever you’re looking at things to study, things like that as a Power Platform admin, feel free to DM me directly and it’ll be a pleasure for me to tell you what you need to learn.

Yeah, I think I kind of agree with what Vlad was saying. The big things are data exposure and the lack of access control. That’s the big deal here, so basically not having governance at all. Because look, if you don’t do that, you’re also probably not doing that for a bunch of other stuff. So probably you’re not doing that for some SharePoint files that you have, for OneDrive, and all of that. So the risk is already there. It’s not because you developed this app that the risk now shows up out of nowhere. So there’s a lot that we need to do to mitigate those risks, but there are always risks.

What Vlad was saying was, look, no admin wants to make the users’ life hell. Literally no one. They just want to make sure that everyone can access stuff, and do their work, but the company also does it in a secure and policed policy way. So mitigating risks is always important. Implementing governance policies, enforcing things like DLP, and access controls with a lot of training to educate the users on how to use security and how to secure the apps, and also integrating monitoring in all this and making sure that those who build those apps are creating some audit trails, some monitoring on this, and we are not doing shadow IT. Because I think that’s also important. We are not using Power Apps and Power Automate and all that to basically work out ways to do things without IT knowing. That’s not the purpose of this.

I think those are the main pointers that I can give you where governance is king, to be honest. Look, if you don’t do good governance, this even starts way before this. It starts with Intra ID with access packages and a bunch of that stuff so that you can give the right permissions to the right people and ensure they always have the right permissions. It’s not because they change from one position to another in the company like they have a different job role now. Usually what happens in most companies is they gain more permissions but they never lose any. But it’s important to make sure that they lose some because they don’t need that permission anymore to do their old job.

For example, I was working in a company for a few years and I switched floors many times because we were doing renovations. I changed floors multiple times and I was able to print to all the printers in the company in the end when I left, literally all of them because I was changing floors so they gave me permission to print to that floor because we had a printer on each floor. In the end, I had permissions to all printers. This is just to show you an example of how bad this organization was in governance. They just added stuff and never removed any kind of permission. This is really wrong.

It’s also wrong when you start adding things like Copilot into this and that, but we’re not here to talk about that today. That’s another nightmare that a lot of organizations have now because they want to implement AI and Copilot and then realize they never did governance in their data. Now Copilot is exposing your data. It’s not exposing anything; the data is already exposed. It’s just an easier way to access the data. That’s just that because the data is already exposed. But we’re not going to talk about AI today.