web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Power Platform - Condi...
Power Apps
Answered

Power Platform - Conditional Access Policy setup - What Target Resources are Required?

(0) ShareShare
ReportReport
Posted on by 724
Looking around for information online, and most of the Microsoft articles don't give specifics on resources to include.
 
I have a Conditional Access Policy being setup to Block Power Apps resources, and an exemption group setup to allow grant specific members access.
 
At the moment I have 
 
Microsoft Flow Service
PowerApps Service
Power Virtual Agents Service
Power Platform Global Discovery Service
Power Platform Environment Discovery Service
 
 
But I have since realised I will also need
 
Dataverse
Power Apps
PowerApps and Flow
 
Not sure about the below, but likely need these too?
 
Dataverse Resource Provider?
Power Apps API
Power Platform API
PowerApps-Advisor
Power Virtual Agents
Power Automate AI Flows Worker
Power Platform Data Analytics
Power Platform Governance Services
Power Apps Service Data Plane Backend
 
Is there anywhere that shows the bare minimum required?
 
Thank you
RD
I have the same question (0)
  • Verified answer
    11manish Profile Picture
    4,267 Super User 2026 Season 2 on at
    Start with:

    Power Apps Service + Microsoft Flow Service + Power Virtual Agents, depending on which Power Platform products you actually want to block.

    Then use Report-only + Entra sign-in logs to identify genuine dependencies.

    For Dataverse, use Dataverse/environment/app-access controls in addition to Conditional Access rather than trying to make CA alone the Dataverse security
     
    boundary. Microsoft explicitly provides Dataverse application access control for restricting which applications can access an environment.

    Most importantly, test the exemption group before production enforcement. A CA policy that blocks the wrong downstream resource can make Power Apps,
     
    Power Automate, Teams-integrated flows, or Dataverse applications appear to fail even though the primary Power Platform service itself is correctly configured.
  • RandomDept Profile Picture
    724 on at
    Thank you,
     
    I had a Conditional Policy in place Report Only, but there never seems to be an official, this will allow X or Y without blocking Q.
     
    I have a job logged with MS to see if they can provide.
  • Suggested answer
    Syed Aqib Raza Profile Picture
    68 on at

    The key thing here is that there isn't really a reliable concept of a single "bare minimum list of Power Platform Target Resources" for Conditional Access that applies to every scenario. The required resources depend on what exactly you are trying to block or allow—for example, Power Apps maker access, Power Automate usage, Dataverse access, Copilot Studio, APIs, or administrative operations.

     

    For a policy intended to control user access to Power Platform, I would strongly recommend avoiding selecting every resource with a name containing Power Platform, Power Apps, or Dataverse. Many of those service principals are backend services and adding them unnecessarily can cause unexpected authentication or functionality issues.

     

    A better approach is:

     

    Start with the main user-facing resources you want to protect:
     
    Microsoft Power Apps

    Microsoft Power Automate / Microsoft Flow

    Dataverse

    Power Apps and Power Automate

    Power Virtual Agents / Copilot Studio, if applicable

    • Test the policy in Report-only mode first.

    • Use the Microsoft Entra sign-in logs to identify which applications/resources are actually being accessed and which Conditional Access policy would affect them.

    • Add additional Target Resources only when testing or sign-in logs demonstrate that they are required for your particular Power Platform scenario.
     

    Resources such as Power Platform Global Discovery Service, Environment Discovery Service, Dataverse Resource Provider, Power Platform API, PowerApps-Advisor, and various backend/data-plane services should generally not be added simply because they appear related to Power Platform. Some are service/backend components rather than the primary interactive applications you are trying to govern.

     

    Also, if your objective is "block Power Platform access except for members of an exemption group," make sure the policy design is tested carefully across:

     


    • Power Apps portal


    • Power Automate portal


    • Dataverse-backed apps


    • Model-driven apps


    • Canvas apps


    • Power Platform admin functionality


    • API/integration scenarios


    •  
     

    The most practical way to determine the true minimum in your tenant is therefore Report-only mode + Entra sign-in logs, rather than relying on a static list, because Microsoft's underlying service/application architecture can change and different Power Platform workloads authenticate against different resources.

     

    In short: start with the primary user-facing Power Platform resources, don't automatically include every backend service principal, and use sign-in logs to identify anything additional that is genuinely required.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 356 Most Valuable Professional

#2
11manish Profile Picture

11manish 225 Super User 2026 Season 2

#3
Mohsin Ali Profile Picture

Mohsin Ali 211

Last 30 days Overall leaderboard