web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Power Apps - Power Apps Governance and Administ...
Unanswered

Controlling dataverse access within production environments

(0) ShareShare
ReportReport
Posted on by 46

I was wondering if it was possible to restrict specific users from accessing dataverse information outside of a Canvas app.

 

For most of our users we use the web link for them to access a canvas app on each of their computers. Using the app in this way only allows for data to be accessed using the linked Canvas app. However a user could log into powerapps from Microsoft's home page bringing them to the PowerApps' home screen. Here they have access to Dataverse tables, option sets, flows and can create apps. From my testing even giving a user no permissions within the environment still allows them a shocking amount of access to your data. They can access any of your dataverse tables, delete tables and edit records. They can't create tables citing "you are missing the necessary privilege to create tables" so I know something is preventing them from having completely unrestricted access. To apply security roles I am going to the admin center then Environments/"Environment name"/Settings/Users/Manage security roles. Are security roles managed somewhere else in the admin center?

 

What is the purpose of creating specific user privileges when a user can open the environment and subvert all of the carefully designed controls in a canvas app? What am I missing here? 

 

Any help is appreciated.

I have the same question (0)
  • Hamish Sheild Profile Picture
    3,005 Most Valuable Professional on at
    Re: Controlling dataverse access within production environments

    Hi @jchenevert , the behaviour you are describing doesn’t sound quite right. What security roles have you given your users? It is the security roles that control the access to Dataverse data. I assume you have looked at the definition of the security roles assigned to your users and have seen what they have access to?

  • jchenevert Profile Picture
    46 on at
    Re: Controlling dataverse access within production environments

    Hi @HSheild. I agree it doesn't make any sense. I have attached a picture of my custom "norights" user that I used to access my dataverse tables. I all of the tabs have no read/write access in any of my custom dataverse entities. Do previous user permissions linger on after being changed? I made sure to refresh my test user's permissions after changing them and completely logining out before accessing the dataverse information.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Coming soon: forum hierarchy changes

In our never-ending quest to improve we are simplifying the forum hierarchy…

Chiara Carbone – Community Spotlight

We are honored to recognize Chiara Carbone as our Community Spotlight for November…

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 651 Most Valuable Professional

#2
Michael E. Gernaey Profile Picture

Michael E. Gernaey 385 Super User 2025 Season 2

#3
MS.Ragavendar Profile Picture

MS.Ragavendar 230 Super User 2025 Season 2

Last 30 days Overall leaderboard

Featured topics