cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
theBIbutler
New Member

Common Data Service Database Security

Hi,

 

I have created a database within my organisations default Environment.

 

I have selected Restrict Access and then have not added any Permission Sets to the Organization User.

 

All users still seem to be able to access the database and entities when in PowerApps.

 

I thought that by default no access rights were assigned?

 

Anyone help?

 

Cheers

 

Mark

3 REPLIES 3
mr-dang
Community Champion
Community Champion

Therein lies the dilemma: your users need create/update/read/delete permissions to your entities so that they can interact with the data, but in turn, users can download the entity and see all the data in Excel. If you revoke read access, they can't pull up any data.

 

It's a huge security flaw if you want to use CDS for sensitive or semi-sensitive data that you don't want all your users to download. I quit making my gradebook app because of this concern.

 

In December, I proposed an Idea expanding permissions to include limiting access to Excel or adding more specific read access. Please upvote the idea--it should the a top priority:

https://powerusers.microsoft.com/t5/PowerApps-Ideas/Expand-CDM-Permissions/idi-p/16475

 

Microsoft Employee
@8bitclassroom

Hi mr-dang,

 

I'm aware that for them to have access to specific entities through an app they will inherit access to the whole entity; agree that's not great.

 

However my issue is that I haven't given any users access to anything yet but they can still see all of the entities in Power Apps. How do I set it up so no one can see anything until I assign permission sets to user roles and add users to them?

 

Cheers

 

Mark

Hi Mark - can you quickly check if you have granted any of the other roles like DB owner to users? If not, I'd like our team to have a look at your environment. If you could please go to https://powerapps.microsoft.com/support/ and create a new support ticket - we will have one of our team investigate.

 

Thanks,

 

Thanks,
Clay.

Helpful resources

Announcements
PA_User Group Leader_768x460.jpg

Manage your user group events

Check out the News & Announcements to learn more.

Power Query PA Forum 768x460.png

Check it out!

Did you know that you can visit the Power Query Forum in Power BI and now Power Apps

Carousel 2021 Release Wave 2 Plan 768x460.jpg

2021 Release Wave 2 Plan

Power Platform release plan for the 2021 release wave 2 describes all new features releasing from October 2021 through March 2022.

R2 (Green) 768 x 460px.png

Microsoft Dynamics 365 & Power Platform User Professionals

DynamicsCon is a FREE, 4 half-day virtual learning experience for 11,000+ Microsoft Business Application users and professionals.

Users online (1,483)