Collab365 SpacesCollab365 Spaces
SpacesBoardsPricingAcademy membersHow It Works
Collab365 Spaces

AI changes work. Know what to do.

Follow Collab365

FacebookLinkedInInstagramX (Twitter)TikTokYouTube
Excellent on TrustpilotTrustScore 4.5/514 reviews

Platform

  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams

Company

  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Cookie Policy

© 2026 Collab365 Spaces Limited. All rights reserved.

Badhan Ct, Castle St, Hadley, Telford, Shropshire, TF1 5QX, UK

AI changes work. Know what to do.
Start free trial

Microsoft tightens Power Pages security by enforcing access inside Dataverse

Reviewed by Helen Jones13 JulLast review 13 Jul 2026
Microsoft tightens Power Pages security by enforcing access inside Dataverse

Microsoft opened a public preview of Native Dataverse Authorization for Power Pages. Access checks now run inside Dataverse itself rather than only through the older portal layer. External contacts are treated as Dataverse users, web roles line up with Dataverse security roles, and operations run in the signed-in user’s context. The preview also adds column security profiles, Custom Scope rules for row-level access based on business conditions, and audit logs that show the actual external user. Makers turn the feature on per website. The studio experience for building pages stays the same, but custom plugins or logic that previously ran with elevated privileges may start failing and need retesting.

Until now, many Power Pages sites relied on a shared application identity for data access. That made external portals easier to stand up, but it blurred who really touched which rows and fields, and audit trails often looked like the system rather than the person outside the company. With native authorization, the same Dataverse security model that protects internal apps can govern external users more tightly. That is useful if your org ever shares request trackers, case forms, or partner portals on Dataverse. It does not change how a typical internal canvas app talks to a SharePoint list, and it is still preview, so early adopters must recheck custom code before flipping the switch.

Analysis

Treat this as a watch item unless you already run Power Pages against Dataverse for people outside your tenant. If you do, list any plugins or custom logic that assumed elevated rights, then test them on a non-production site with the new authorization enabled before you touch production.

Read full story on microsoft.com

Source note

Source note

Pulse published by Collab365 Spaces, reviewed by Helen Jones on 13 Jul 2026. Cite as "Microsoft tightens Power Pages security by enforcing access inside Dataverse", Collab365 Spaces. 4 sources referenced.

spaces.collab365.com/posts/microsoft-tightens-power-pages-security-by-enforci-kSuR29