web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Developer User Pipelin...
Power Apps
Answered

Developer User Pipeline Deployment Fails with Permission Error

(0) ShareShare
ReportReport
Posted on by 236

The developer has Environment Maker Role assigned in the DEV and TEST environments. The Deployment Pipeline was shared out with them and they have Pipeline User role in the Orchestrator Environment. When they try and deploy a new solution that has environment variables to a new environment they get the following error.

 

Failure details
Principal with id f0772446-20a0-ee11-be37-000d3a5a8baa does not have WriteAccess right(s) for record with id 3ce10b7e-0110-4230-bdcc-aaf77125c07c of entity environmentvariabledefinition. Details: {"CallerPrincipal":{"PrincipalId":"f0772446-20a0-ee11-be37-000d3a5a8baa","Type":8,"IsUserPrincipal":true},"OwnerPrincipal":{"PrincipalId":"cf0fca4d-d19b-ee11-be37-6045bd081aaa","Type":8,"IsUserPrincipal":true},"ObjectId":"3ce10b7e-0110-4230-bdcc-aaf77125c07c","ObjectTypeCode":380,"EntityName":"environmentvariabledefinition","ObjectBusinessUnitId":"9a07ca4d-d19b-ee11-be37-6045bd081aaa","RightsToCheck":"WriteAccess","RoleAccessRights":"None","PoaAccessRights":"None","HsmAccessRights":"None","GrantedAccessRights":"None","Messages":["BasicMinimumPrivilegeDepthRequired = None","EntityUserGroupRights = None","LocalMinimumPrivilegeDepthRequiredRights = WriteAccess","SecLib::AccessCheckEx2 failed. Owner Data: User principal cf0fca4d-d19b-ee11-be37-6045bd081aaa is not loaded in UserDataCache yet; Principal Data: roleCount=1, privilegeCount=891, accessMode='0 Read-Write', AADObjectId='42c06e7a-f452-42e7-8a00-1c66cdb8ad54', MetadataCachePrivilegesCount=4705, businessUnitId=9a07ca4d-d19b-ee11-be37-6045bd081aaa"],"EntityOwnershipTypeMask":1,"CallerInfo":{"IsSystemUser":false,"IsSupportUser":false,"IsAdministrator":false,"IsCustomizer":false,"IsDisabled":false,"IsIntegrationUser":false,"Teams":null,"Roles":null},"ReadOnlyState":"UserAndOrgFullAccess","IsHsmEnabled":false,"HsmInfo":null,"AccessOrigin":null}
See less
I have the same question (0)
  • Verified answer
    AlbertoCastro Profile Picture
    1,201 Most Valuable Professional on at

    Hi,

    environment maker role doesn't allow customize dataverse, for example, work with solutions, components deployed by pipelines.
    Users needs at least System Customizer role to work with solutions and pipelines.

  • NickTT Profile Picture
    236 on at

    I just got off the call with Microsoft and came to the same conclusion. Once I gave the Dev Team System Customizer role the deployment worked fine.

     

    Just wish their documentation was a bit clearer as this one is tell me that they already have the access needed.

    https://learn.microsoft.com/en-us/power-apps/maker/data-platform/EnvironmentVariables#security

     

    What is odd too is that she was able to create environment variables for her project in Dev without any issue. However, solution also had an environment variable that I created\owned associated to the solution. So I suspect too that since she wasn't the owner of that variable, it wouldn't let her update it. If you look at the permissions for the Environment Maker role the account only has "USER" permissions to the definition table. Where System Customizer has "Organization".

     

    Thoman_0-1718397563538.png

     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 711 Most Valuable Professional

#2
Michael E. Gernaey Profile Picture

Michael E. Gernaey 319 Super User 2025 Season 2

#3
Power Platform 1919 Profile Picture

Power Platform 1919 268

Last 30 days Overall leaderboard