Power Platform Solutions and Security¶
Table of Contents¶
- Solutions
- Application Lifecycle Management (ALM)
- Security Roles and Permissions
- Sharing and Collaboration
- Teams and Business Units
- Data Loss Prevention (DLP)
- Environments
- Exam Tips
Solutions¶
What are Solutions?¶
Containers for Power Platform components used for: - Packaging customizations - Transporting between environments - Managing dependencies - Version control - Application lifecycle management
Solution Types¶
Unmanaged Solutions¶
Characteristics: - Editable in target environment - Can add/remove components - Used for development - Cannot delete components (keeps dependencies) - Can be exported as managed or unmanaged
Use Cases: - Development environment - Active customization - Iterative changes - Source control integration
Managed Solutions¶
Characteristics: - Read-only in target environment - Cannot modify components - Can be uninstalled (removes all components) - Layer over system solution - Used for production deployment
Use Cases: - Production environments - UAT/Staging - Customer deployments - AppSource apps
Key Difference:
Unmanaged β Development, editable, source control
Managed β Production, read-only, deployable package
Solution Components¶
Common Components: - Tables (entities) - Columns (fields) - Forms - Views - Charts - Dashboards - Business rules - Workflows - Power Apps (canvas, model-driven) - Power Automate flows - Connection references - Environment variables - Security roles - Choices (option sets)
Adding Components:
1. Open solution
2. Click "Add existing" or "New"
3. Select component type
4. Add specific components
- Add required components (dependencies)
- Add subcomponents (child objects)
Solution Layering¶
Default Solution: - Base layer - All customizations without solution - Cannot export - Background container
Unmanaged Layer: - Above default solution - Active customizations - Multiple unmanaged solutions stack - Top layer takes precedence
Managed Layer: - Above unmanaged - Production customizations - Multiple managed solutions stack - Layering order matters
Example Layers (bottom to top):
1. System Solution (base)
2. Default Solution
3. Unmanaged Solution A
4. Unmanaged Solution B
5. Managed Solution 1
6. Managed Solution 2 β Active layer
Solution Dependencies¶
Types: - Published - Required components - Unpublished - Current draft dependencies - Internal - Within solution - External - Other solutions/system
Managing Dependencies:
Check dependencies:
Solutions β Select solution β Show dependencies
Required components:
- Tables used in forms
- Columns used in views
- Lookups to other tables
- Security roles referencing tables
Solution Publisher:
Display Name: Contoso
Name: contoso
Prefix: contoso (for schema names)
Option Value Prefix: 10000
Results in:
- Table: contoso_project
- Column: contoso_projectcode
- Choice value: 10000 (Active)
Application Lifecycle Management (ALM)¶
ALM Environments¶
Development: - Unmanaged solutions - Active development - Frequent changes - Source control integration
Test/UAT: - Managed solutions imported - User acceptance testing - Validation before production
Production: - Managed solutions only - End users - No direct customization - Monitored and supported
Solution Export¶
Export Unmanaged:
1. Select solution
2. Export β Unmanaged
3. Publish customizations
4. Next, Next, Export
5. Download .zip file
Use for: Source control, backup, dev-to-dev
Export Managed:
1. Select solution
2. Export β Managed
3. Publish customizations
4. Next, Next, Export
5. Download .zip file
Use for: Production deployment, customer delivery
Export Settings:
- System settings (Auto-numbering, currencies)
- Customization (Calendar, Organization settings)
- Email templates
- Security roles
- Connections (Environment variables instead)
Solution Import¶
Import Process:
1. Solutions β Import
2. Browse and select .zip file
3. Import solution dialog
- Upgrade or Update (existing solutions)
- Activate plugins and workflows
4. Configure environment variables
5. Configure connection references
6. Import
Watch for:
- Missing dependencies (error)
- Version conflicts (warning)
- Customization conflicts (warning)
Import Options:
Upgrade (managed solutions):
- Stage for upgrade
- Apply after import
- Old solution replaced
Update (unmanaged):
- Add new components
- Update existing
- Keep old components
Environment Variables¶
Purpose: Configuration values that change between environments.
Create:
Display Name: API Endpoint URL
Name: contoso_apiendpoint
Data Type: Text
Default Value: https://api-dev.contoso.com
Current Value: (set per environment)
Use in Flows:
HTTP Action:
URI: environmentVariables('contoso_apiendpoint')
Use in Canvas Apps:
Set(ApiUrl, LookUp('Environment Variable Values',
'Environment Variable Definition'.'Schema Name' = "contoso_apiendpoint",
Value
));
Import Process:
During solution import:
1. Prompt for environment variable values
2. Set per-environment values
3. Override defaults
Connection References¶
Purpose: Abstract connections from flows/apps.
Create:
Display Name: SharePoint Connection
Name: contoso_sharepointconnection
Connector: SharePoint
Connection: (selected during import)
Benefits: - Solution aware - No hard-coded connections - Different connections per environment - Easier deployment
Import:
During import:
1. Prompt for connections
2. Select existing or create new
3. Authorize if needed
Security Roles and Permissions¶
Security Role Fundamentals¶
Access Levels: 1. None - No access (Γ) 2. User - Own records only (β) 3. Business Unit - Records in user's BU (ββ) 4. Parent: Child Business Units - User's BU + child BUs (βββ) 5. Organization - All records (ββββ)
Privileges: - Create - Create new records - Read - View records - Write - Edit records - Delete - Delete records - Append - Add related records - Append To - Be related to - Assign - Change owner - Share - Share record
Creating Security Roles¶
Copy Existing Role:
Settings β Security β Security Roles
Select role (e.g., Salesperson) β Actions β Copy
Name: Custom Sales Rep
Set privileges per table
Setting Privileges:
Table: Account
- Create: Business Unit (ββ)
- Read: Organization (ββββ)
- Write: User (β)
- Delete: None (Γ)
- Assign: Business Unit (ββ)
- Share: Business Unit (ββ)
Common Security Roles¶
System Administrator: - Full access to all tables - Customize system - Manage users and security
System Customizer: - Customize system - Create/edit tables, forms, views - No user management
Basic User: - Minimal access - Read-only common tables - Own records for tasks/activities
Salesperson: - Account, Contact, Lead, Opportunity access - Business Unit level for most - Cannot customize
Field-Level Security¶
Enable for Column:
1. Edit column
2. Advanced options
3. Enable field security: Yes
4. Save
Then configure in Security Roles:
5. Settings β Security β Field Security Profiles
6. Create profile: "Sensitive Field Access"
7. Add users/teams
8. Set permissions: Read, Update, Create
Use Cases: - SSN, credit card numbers - Salary information - Confidential notes - Trade secrets
Record-Level Security¶
Ownership:
User/Team owned tables:
- Owner field
- Can assign to user/team
- Security role determines access
Hierarchical Security:
Enable: Settings β Security β Hierarchy Security
Configure: Manager Hierarchy or Position Hierarchy
Allows:
- Managers to access subordinate records
- Position-based access
- Independent of Business Units
Access Team:
Purpose: Grant specific users access to specific records
Create template:
1. Settings β Templates β Access Team Templates
2. Name: Account Collaboration Team
3. Select table: Account
4. Permissions: Read, Write, Append
Add team members:
Record β Teams β Add to access team
Sharing and Collaboration¶
Sharing Records¶
Share Single Record:
Record β Share
Add User/Team: [User email]
Permissions:
β Read
β Write
β Delete
β Assign
β Share (allow resharing)
Share Multiple:
View β Select records β Share
Add users/teams
Set permissions
Sharing Cascade:
Share Account with user:
Option: Share with related records
β Contacts
β Opportunities
β Cases
Team Collaboration¶
Owner Team:
Purpose: Group ownership of records
Type: Owner
Members: [Users]
Security Roles: [Assign roles]
Usage:
- Assign records to team
- All team members access via role
- Shared workload
Access Team:
Purpose: Ad-hoc access to specific records
Type: Access
Template: Account Collaboration
Usage:
- Automatically created for record
- Add members dynamically
- Record-specific permissions
Sharing Canvas Apps¶
Share App:
Power Apps β Apps β [App] β Share
Add users/co-owners:
User/Group: [Email/AAD group]
Permission: Can view/Can edit
Data permissions:
β Grant access to data sources
Security roles: [Select roles for Dataverse]
Co-Owner vs User: - Co-Owner - Edit app, share with others - User - Run app only
Teams and Business Units¶
Business Units¶
Purpose: - Organizational structure - Data security boundary - Reflect company hierarchy
Hierarchy:
Root Business Unit (Contoso)
ββ Sales BU
β ββ North Sales
β ββ South Sales
ββ Service BU
ββ Marketing BU
Creating:
Settings β Business Units β New
Name: North Sales
Parent: Sales BU
Save
User Assignment:
Settings β Users β [User] β Business Unit: North Sales
- User can be in ONE business unit
- Change: Transfer user to another BU
Security Implications:
Security Role: Business Unit access (ββ)
User in North Sales:
- Sees North Sales records
- Doesn't see South Sales records
- Unless Organization level access
Teams¶
Owner Team:
Settings β Teams β New
Name: North Sales Team
Business Unit: North Sales
Type: Owner
Add members:
- [User 1]
- [User 2]
Assign Security Roles:
- Salesperson
Usage:
- Assign records to team
- All members have access via role
Access Team:
Created automatically or manually
Purpose: Record-specific access
Template-based permissions
No security roles assigned
AAD Group Team:
Type: AAD Security Group or Office 365 Group
Sync from Azure AD
Members managed in AAD
Permissions via security roles
Data Loss Prevention (DLP)¶
DLP Policies¶
Purpose: - Prevent data leakage - Control connector usage - Enforce governance
Connector Groups: 1. Business - Corporate data (SharePoint, Dataverse) 2. Non-Business - External services (Twitter, Gmail) 3. Blocked - Prohibited connectors
Rules: - Business β Business: β Allowed - Non-Business β Non-Business: β Allowed - Business β Non-Business: Γ Blocked - Any β Blocked: Γ Blocked
Creating DLP Policies¶
Power Platform Admin Center β Data policies β New
Policy Name: Corporate Data Protection
Scope:
β All environments
β Specific environments (select)
β All except (exclude list)
Configure connectors:
Business:
- SharePoint
- Office 365 Outlook
- Dataverse
- SQL Server
Non-Business:
- Twitter
- Facebook
- RSS
Blocked:
- Consumer services
- Unapproved storage
Action:
- Block or warn
Connector Patterns:
Pattern: *.contoso.com
Applies to: HTTP connector
Allows: https://api.contoso.com
Blocks: https://api.external.com
DLP Impact¶
On Flows:
Violation:
Flow uses SharePoint (Business) + Twitter (Non-Business)
Result:
- Flow suspended
- Error message
- Must remove violating connector or request exception
On Apps:
Violation:
App uses Dataverse (Business) + Gmail (Non-Business)
Result:
- Cannot save
- Error shown in app checker
- Must remove connector or change grouping
Environments¶
Environment Types¶
Production:
Purpose: Live applications
Dataverse: Yes
Storage: Paid (1GB base + 10GB per license)
DLP: Enforced
Sandbox:
Purpose: Testing, UAT
Dataverse: Yes
Copy from Production: Yes
Refresh: Supported
Developer:
Purpose: Individual development
Dataverse: Yes
Limit: One per user (with Power Apps Developer Plan)
Storage: Limited
Default:
Purpose: Trial, learning
Dataverse: Created on-demand
Cannot delete: Built-in
Shared: All tenant users
Trial:
Purpose: Evaluation (30 days)
Dataverse: Yes
Convert: To production (requires license)
Environment Admin¶
Creating Environment:
Power Platform Admin Center β Environments β New
Name: UAT Environment
Type: Sandbox
Region: United States
Dataverse: Yes
URL: contoso-uat
Currency: USD
Language: English
Security Group (optional): [AAD group for access]
Copy Environment:
Source: Production
Target: New or existing sandbox
Copy type:
- Everything (full copy)
- Customizations and schemas only
- Reset environment
Includes:
- All data
- Customizations
- Apps
- Flows
Backup and Restore:
Automated backups:
- System backups: Daily (retained 28 days)
- Manual backups: On-demand (up to 3)
Restore:
Power Platform Admin Center β Environments
β [Environment] β Backups β Restore
Select backup point
Confirm restore (replaces current)
Exam Tips¶
Key Concepts¶
Solutions: - Unmanaged: Development, editable - Managed: Production, read-only, uninstallable - Components: Tables, apps, flows, roles - Publisher: Prefix for schema names
ALM: - Dev β Test β Production - Export: Unmanaged (dev) or Managed (prod) - Import: Check dependencies, set variables - Environment variables, connection references
Security: - Access levels: None, User, Business Unit, Parent-Child, Organization - Privileges: Create, Read, Write, Delete, Append, Assign, Share - Field-level security: Sensitive columns - Record-level: Owner, hierarchical, access team
Sharing: - Share records: Read, Write, Delete, Assign, Share - Apps: Co-owner (edit) vs User (run) - Teams: Owner (role-based) vs Access (record-specific)
Business Units: - Organizational structure - Security boundary - Hierarchy: Root β Child BUs - User: One BU only
DLP: - Connector groups: Business, Non-Business, Blocked - Rules: Block cross-group connections - Enforce data governance
Environments: - Production, Sandbox, Developer, Trial, Default - Copy, backup, restore - Security groups for access
Common Scenarios¶
Deploy Solution: 1. Dev: Export as Managed 2. Import to UAT (sandbox) 3. Set environment variables, connections 4. Test 5. Import to Production 6. Monitor
Security Configuration:
Requirement: Sales reps see own accounts, managers see team's
Solution:
1. Security role: Account Read = User (β)
2. Enable Manager Hierarchy
3. Assign role to sales reps
4. Managers auto-access subordinates
DLP Policy:
Requirement: Prevent corporate data (Dataverse) to external (Twitter)
Solution:
1. Create DLP policy
2. Dataverse β Business group
3. Twitter β Non-Business group
4. Apply to all environments
Field Security:
Requirement: Only HR sees Salary field
Solution:
1. Enable field security on Salary column
2. Create field security profile "HR Salary Access"
3. Add HR team
4. Grant Read, Update permissions
Decision Matrix¶
Solution Type: - Development β Unmanaged - Production β Managed - Source control β Unmanaged - Customer delivery β Managed
Environment Type: - Live users β Production - Testing β Sandbox - Personal dev β Developer - 30-day trial β Trial
Team Type: - Group ownership β Owner Team - Record-specific access β Access Team - AAD-managed β AAD Group Team
Access Level: - Own records β User (β) - Department β Business Unit (ββ) - Managers + reports β Parent-Child (βββ) - All records β Organization (ββββ)
Quick Reference¶
Solution Workflow:
1. Create publisher (prefix)
2. Create solution
3. Add components
4. Export (unmanaged β managed)
5. Import to target
6. Test and deploy
Security Role Privileges:
Γ None
β User
ββ Business Unit
βββ Parent-Child BUs
ββββ Organization
Sharing Permissions: - Read: View record - Write: Edit record - Delete: Delete record - Assign: Change owner - Share: Share with others - Append: Add related - Append To: Be related to
DLP Groups:
Business β Business: β
Non-Business β Non-Business: β
Business β Non-Business: Γ
Any β Blocked: Γ
Study Focus¶
- Understand solution types - Unmanaged vs Managed
- Master ALM process - Dev to production deployment
- Know security roles - Access levels and privileges
- Learn sharing - Records, apps, teams
- Understand Business Units - Hierarchy and security
- Know DLP policies - Connector groups and rules
- Master environments - Types and admin tasks
- Practice scenario-based questions
Final Checklist¶
- Solution types and layering
- Solution components
- Publisher and prefix
- ALM environments (Dev, Test, Prod)
- Export managed vs unmanaged
- Environment variables
- Connection references
- Security role access levels
- Security role privileges
- Field-level security
- Sharing records and apps
- Owner vs Access teams
- Business Unit hierarchy
- DLP policy configuration
- Connector groups
- Environment types
- Copy and backup environments