I'm used to Canvas apps connecting to SharePoint, where all apps/sites have access to AD, and where permissions can be site on one site that are completely different than another site, as each site can have different SharePoint groups with different permissions.
For Power Apps, I can have different security roles to support different apps, but users are still going to be grouped into business units which are specific to the environment. In App 1, all HR staff need permission to view all data for all child business units. In App 2, HR staff should only see their own rows, and its IT staff that should see all rows for all business units. Does this mean these apps should be in different environments as to get access to unique parent/child business units for each environment?
Also, I need to do approvals with managers, which is not synced from AD automatically. So, I need to set up a flow to sync managers to the users in dataverse? If I'm going to have 10 environments, I need to configure this flow for all 10?


Report
All responses (
Answers (