web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Apps
Unanswered

Security role

(0) ShareShare
ReportReport
Posted on by 1,032

Hello everyone;

 

I created a canvas app and shared it with users. I gave them as security role "basic user" and "system customizer", but the problem is that they have the possibility to view the tables in dataverse and modify and delete them.

What role should I give them so that they can't access the dataverse tables?

I have the same question (0)
  • Ami K Profile Picture
    15,689 Super User 2024 Season 1 on at

    @gikido : answered here in the duplicate post in the Power Apps Forum:

     

    https://powerusers.microsoft.com/t5/Building-Power-Apps/Security-role/m-p/2280231#M570345 

  • Drew Poggemann Profile Picture
    9,287 Most Valuable Professional on at

    Hi @gikido ,

     

    System Customizer role should only be for "Makers" of the applications and within the environment will have the ability to update / modify tables, business rules, workflows and the like, I would not assign this role.  You should only have to provide them the Basic User role (depending on the tables being used) or normally create a custom role for you specific tables that will provide the appropriate Create / Read / Update / Delete / Share / etc. privileges for your tables (these will not be on the Basic User role by default).

     

  • gikido Profile Picture
    1,032 on at

    @dpoggemann 

     

    Good morning,

     

    I think I did not explain the problem well in the first post, for what I want is to prohibit the users of the application from seeing the tables (see screenshot), and at the application level they can write, view, edit, delete their recordings.

    so what should i do to achieve this?

    Capture d’écran 2023-08-06 à 14.36.41.png
  • Ami K Profile Picture
    15,689 Super User 2024 Season 1 on at

    @gikido - why would the suggested answer I gave you in the duplicate post, not answer your question?

  • gikido Profile Picture
    1,032 on at

    @Amik

     

    Hello, sorry I did not pay attention, thank you for your answer, I will try to apply it and see if that solves the problem.

  • gikido Profile Picture
    1,032 on at

    @Amik @dpoggemann 

    Thanks it works now.

    I have a complexity to understand the difference between Organization, Parent: Child Business Unit , Business Unit, User. (For my case I chose organization for all tables).

    Can you clarify these concepts for me?

  • Drew Poggemann Profile Picture
    9,287 Most Valuable Professional on at

    Hi @gikido ,

    You can find the details on this here.

    https://learn.microsoft.com/en-us/power-platform/admin/wp-security-cds#tablerecord-ownership 

     

    Basically if you are at "Organization" level in a security role on a table it means the user has that access (i.e. Read) across all business units for that table within the environment.  The user would be able to read any record in that table no matter if within the same business unit or any other and if owned by any user.

     

    Subsequently,

    • Parent: Child Business Unit - Means at the current business unit and any child business units they have the ability to Read all the records (if that is the permission).  The difference here over the Organization is that it is at that business unit and any child vs. all.  The business unit of the role of course that is assigned to the user.
    • Business Unit - Security for all records for that table within the specific business unit of the role (does not include the child business units)
    • User - This would be basically Read (if that is the table permission) for only the records that the user owns

     

  • gikido Profile Picture
    1,032 on at

    @dpoggemann @Amik 

     

    and for flows in power automate, do they need a security role so that they are not accessible by users?

  • Drew Poggemann Profile Picture
    9,287 Most Valuable Professional on at

    Hi @gikido ,

    Please see the following article for details on flow ownership, licensing requirements and ability to share a flow with others... 

    https://learn.microsoft.com/en-us/power-automate/create-team-flows

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 345 Most Valuable Professional

#2
11manish Profile Picture

11manish 207 Super User 2026 Season 2

#3
Mohsin Ali Profile Picture

Mohsin Ali 177

Last 30 days Overall leaderboard