web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Restrict Access to Mic...
Power Automate
Unanswered

Restrict Access to Microsoft Flow

(0) ShareShare
ReportReport
Posted on by 776

Hi Team,

 

Is there a way to restrict end user to only approve/reject flow 

 

enduser should not be able to create any new flow - just approve/reject

 

I tried removing the license for flow, for free flow and for power automate  - no luck

 

Please help

Categories:
I have the same question (0)
  • manuelstgomes Profile Picture
    6,625 on at

    Hi @AshishJaiswal 

     

    The license must be there even if one of the free ones. The user needs "permissions" to run the action so I don't think that's possible, sorry.

     

    If I have answered your question, please mark your post as Solved.
    If you like my response, please give it a Thumbs Up.

    Cheers
    Manuel

  • AshishJaiswal Profile Picture
    776 on at

    Hi,

     

    I have removed the below licenses but user is still able to access the flow, powerapps and PVA

    License Restriction Power Platform.gif

  • AshishJaiswal Profile Picture
    776 on at

    @manuelstgomes , please advise

  • LimeLeaf Profile Picture
    278 on at

    Hi @AshishJaiswal,

    migrate the power automate flow to a admin or service user and test if the enduser can trigger it. Then create a AD policy that blocks power automate.

    In detail:
    1) Run the flow on a service user or admin user. For a service user create a "normal" user with permission to the resources the flow is affecting e.g. Teams Channel or Outlook share mailbox and equip him with the appropriate license e.g. E3. Migrate the flow to this service user and make sure all connections of the flow are running on the new user. Then test if the enduser can trigger the flow.

    2) Implement an AD policy as described here from the Microsoft DEV Blog.
    https://devblogs.microsoft.com/premier-developer/control-access-to-power-apps-and-power-automate-with-azure-ad-conditional-access-policies/
    Block with this permission all users except the service user who owns the flow.


    Then the endusers should be able to particapte in an approval process but they will not be allowed to even enter power automate to create flows.

    Note:
    Some triggers will not work with such an AD policy e.g. to trigger a flow from sharepoint libary for a specific document. 

    This solution helped us to restrict who is capable of creating flows. In combination with a multiple environment strategy.
    https://docs.microsoft.com/en-us/power-platform/guidance/adoption/environment-strategy 

    Cheers

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 538 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 405 Moderator

#3
abm abm Profile Picture

abm abm 252 Most Valuable Professional

Last 30 days Overall leaderboard