web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Restrict Access to Mic...
Power Automate
Unanswered

Restrict Access to Microsoft Flow

(0) ShareShare
ReportReport
Posted on by 776

Hi Team,

 

Is there a way to restrict end user to only approve/reject flow 

 

enduser should not be able to create any new flow - just approve/reject

 

I tried removing the license for flow, for free flow and for power automate  - no luck

 

Please help

Categories:
I have the same question (0)
  • manuelstgomes Profile Picture
    6,625 on at

    Hi @AshishJaiswal 

     

    The license must be there even if one of the free ones. The user needs "permissions" to run the action so I don't think that's possible, sorry.

     

    If I have answered your question, please mark your post as Solved.
    If you like my response, please give it a Thumbs Up.

    Cheers
    Manuel

  • AshishJaiswal Profile Picture
    776 on at

    Hi,

     

    I have removed the below licenses but user is still able to access the flow, powerapps and PVA

    License Restriction Power Platform.gif

  • AshishJaiswal Profile Picture
    776 on at

    @manuelstgomes , please advise

  • LimeLeaf Profile Picture
    278 on at

    Hi @AshishJaiswal,

    migrate the power automate flow to a admin or service user and test if the enduser can trigger it. Then create a AD policy that blocks power automate.

    In detail:
    1) Run the flow on a service user or admin user. For a service user create a "normal" user with permission to the resources the flow is affecting e.g. Teams Channel or Outlook share mailbox and equip him with the appropriate license e.g. E3. Migrate the flow to this service user and make sure all connections of the flow are running on the new user. Then test if the enduser can trigger the flow.

    2) Implement an AD policy as described here from the Microsoft DEV Blog.
    https://devblogs.microsoft.com/premier-developer/control-access-to-power-apps-and-power-automate-with-azure-ad-conditional-access-policies/
    Block with this permission all users except the service user who owns the flow.


    Then the endusers should be able to particapte in an approval process but they will not be allowed to even enter power automate to create flows.

    Note:
    Some triggers will not work with such an AD policy e.g. to trigger a flow from sharepoint libary for a specific document. 

    This solution helped us to restrict who is capable of creating flows. In combination with a multiple environment strategy.
    https://docs.microsoft.com/en-us/power-platform/guidance/adoption/environment-strategy 

    Cheers

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Congratulations to the March Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Automate

#1
Haque Profile Picture

Haque 594

#2
Valantis Profile Picture

Valantis 328

#3
David_MA Profile Picture

David_MA 281 Super User 2026 Season 1

Last 30 days Overall leaderboard