web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / With the current hype ...
Power Apps
Unanswered

With the current hype on security, what are the recommended security scans for Power Apps applications?

(0) ShareShare
ReportReport
Posted on by

With the current hype on security, what are the recommended security scans for Power Apps applications?

Actually I am referring to below security scans. As per the industry standards and best practices, which all security/vulnerability scans (DIYA, SAST, DAST, OSS, API Security, Pen Test) we suppose to complete for any Power Apps application to go live.

I have the same question (0)
  • cchannon Profile Picture
    4,702 Moderator on at

    Well, best practice would be to NOT choose your security scanning and testing procedures based on one application or platform, but based on the totality of your environment. Power Platform is only one facet of a modern organization's risk profile. A mature security control process considers it in context, not as a standalone.

     

    That said, an effective security control process for Power Platform includes evaluating any custom code being deployed to Power Platform, the permission controls in place in any Dataverse databases, the procedures involved with requesting, granting, and revoking elevated privileges, conditional access policies in AAD, Data Loss Prevention policies, and appropriate security around any supporting services, such as Azure.

     

    At a minimum, that means frequent static code analysis and remediation, a governance process for granting and monitoring access controls and consumption, and AAD log monitoring to watch for anomalous behavior. These are effective security controls that directly deliver value. After that, the organization's Cs folks can choose whatever scans they want based on the bigger environmental picture.

  • elmz Profile Picture
    49 on at

    Hi @cchannon,

     

    At a minimum, that means frequent static code analysis and remediation, a governance process for granting and monitoring access controls and consumption, and AAD log monitoring to watch for anomalous behavior. These are effective security controls that directly deliver value. After that, the organization's Cs folks can choose whatever scans they want based on the bigger environmental picture.

    What kind of static code analysis can we perform on PowerApps?

     

    Thanks!

  • cchannon Profile Picture
    4,702 Moderator on at

    Well, first there is the PowerApps Solution Checker. It is NOT a traditional security-focused SCA tool but it is built with platform best practice baked-in as well as a lot of specific code best practices. This makes it a useful tool as part of the solution, and one that yields very few false positives.

     

    The product group has also just added an npm project for eslint rules to push a lot of that best practice checking forward into the IDE (a very welcome improvement!) when working on web resources and PCFs (particularly useful for Typescript resources). @ScottDurow had an excellent blog on this one recently that every prodev should check out.

     

    Beyond that, if you're looking for risky behavior in procode customizations beyond the platform-specific stuff, I would just adopt a standard SCA tool and scan the source code outside the app. I use SonarQube on a few projects and have found it to be pretty easy to use and to have relatively few false positives (plus you can pretty easily customize the scan conditions so you can pre-filter false positives you want it to learn to skip). But there are many other options out there: you just need to pick one that you're comfortable with and that has good rulesets for your procode customizations (usually c# .net 4.6.2, html, js, ts, React).

     

    Happy hunting!

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Congratulations to the March Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Power Apps

#1
11manish Profile Picture

11manish 530

#2
WarrenBelz Profile Picture

WarrenBelz 459 Most Valuable Professional

#3
Haque Profile Picture

Haque 314

Last 30 days Overall leaderboard