web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Pages / Restrict Table Permission
Power Pages
Answered

Restrict Table Permission

(0) ShareShare
ReportReport
Posted on by 74

Hi,

 

As far I understand it, if I give read access to a table (Table Permission), I can use that read access to list records for that table in Portals, for example.

 

My questions is: Is it possible for a user to access that table data beyond the list I provided and if so, how?

 

I ask this because the WebAPI can be accessed via "/_api/contacts?$select=fullname", for instance, and it respects the Table Permission for that table, however it is limited to the fields selected when enabling the API.

 

For my scenario, I want to give Table Permission to a definitions table so I can consult it via Liquid/FetchXML and retrieve a value, but the logged on user should not have access to any other fields from that table.

Categories:
I have the same question (0)
  • oliver.rodrigues Profile Picture
    9,482 Most Valuable Professional on at

    Hi @T1ago 

    Lists/FetchXML/Web API will always respect your Table Permissions definition

    On top of that, for Web API you also need to specify the fields that the user can retrieve

     

    you can still retrieve all fields via Liquid if you need, and then limit for just subset of fields via API, is this the scenario you need? 

     

    I posted an idea on introducing Field-Level Security concept to Portals, would be great if you could vote for it if this is what you are looking for:

    Add Field-Level Security concept to Power Apps Por... - Power Platform Community (microsoft.com)

  • T1ago Profile Picture
    74 on at

    Hi, thanks for replying.

     

    My question refers to Entity Permissions only. If I give read access to a table and list the records, with a view with only 1 field, can the user somehow access the other fields of that table, because he does in fact have permission to do so. Since it's not specified which fields the Entity Permission is applied to.

     

    I mentioned the webAPI because fields can be specified there, but not in the table permission settings. And accessing via URI will show all available fields.

     

    Hopefully this makes it clearer.

  • Verified answer
    oliver.rodrigues Profile Picture
    9,482 Most Valuable Professional on at

    Hi, answer here is no. As long as you have no form/list with the additional fields, they won't be able to hack and retrieve the fields.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Congratulations to the June Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Pages

#1
sannavajjala87 Profile Picture

sannavajjala87 38 Super User 2026 Season 1

#2
Valantis Profile Picture

Valantis 35

#3
Fubar Profile Picture

Fubar 23 Super User 2026 Season 1

Last 30 days Overall leaderboard