web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Risk regarding PCF ins...
Power Apps
Answered

Risk regarding PCF installation

(0) ShareShare
ReportReport
Posted on by Microsoft Employee

Hello, 

 

I am just a regular maker and administrator of PowerApps.
As it's possible to every maker to upload PCF found over the wed and use it into their apps, I would like to know if it's safe to let code "injected" in our app. Is there any leaks risk ?

 

Thx

I have the same question (0)
  • Verified answer
    Diana Birkelbach Profile Picture
    3,072 Most Valuable Professional on at

    Hi @Anonymous , 

     

    The PCF is written by a developer, and he/she is free to make requests (will run under your name), change the DOM content, so there might be a risk. That's why it's good to check the PCFs beforehand. In my opinion you always have this risk if you don't check the imported content; even if a LowCode ( CanvasComponent ) is imported, not only with the PCFs.

     

    But the PCFs cannot be free imported in the CanvasApps. First the PCF-Solution (.zip) has to be installed in your organization. For that they need the right "System Customizer", while for making Apps they need "Environment Maker". Maybe you can decide by role, who's allowed to import PCFs.

    Maybe this helps: https://docs.microsoft.com/en-us/power-platform/admin/database-security

     

    That's only my opinion. I must say that usually I just write code, and don't care about the governance. Maybe this still helps.

     

    Kind regards,

    Diana

     

  • Community Power Platform Member Profile Picture
    Microsoft Employee on at

    Thank you for your comprehensive answer.

    I will check the roles, but I fear that Environment Maker is assigned by default to all my users.

     

  • Diana Birkelbach Profile Picture
    3,072 Most Valuable Professional on at

    Hi @Anonymous , 

     

    That would be ok; so they can make Apps.

    I think that if they don't have the SystemCustomizer role, they cannot import the PCFs in your organization, so they cannot use them in the Apps. This way the SystemCustomizers can decide which PCFs are allowed to be used.

     

    Kind regards,

    Diana

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 542 Most Valuable Professional

#2
Haque Profile Picture

Haque 206

#3
Kalathiya Profile Picture

Kalathiya 201 Super User 2026 Season 1

Last 30 days Overall leaderboard