Showing results for 
Search instead for 
Did you mean: 
Level: Powered On

How secure are PowerApps - what data would you not put through and why?

Would you allow a user to create a powerApp to send personal/secure date to a Sharepoint list that only HR can access?


Developers insist it's all encrypted, security office would like encryption on top of this.


What are people's opinion on this please?


It's a lot more work to write an in-house system to a SQL Express DB with encrypted fields that a PowerApp.

Community Support Team
Community Support Team

Re: How secure are PowerApps - what data would you not put through and why?

Hi @Bulldog ,


If you mean that you want to show different data for different users in PowerApps, you could achieve this using Filter and User() function. Something like:


For more information about User function, please refer to:




Community Support Team _ Mona Li
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Super User
Super User

Re: How secure are PowerApps - what data would you not put through and why?

Hi @Bulldog . That depends on how savvy your Sharepoint folks are and who is developing the PowerApp. There are some pitfalls to beware of. 


- You typically have to grant your PowerApps users "Contribute" permission to read/write to a Sharepoint list.

- When you do this, IF they know the URL of the list, they might be able to directly access it through the browser.

- Supposedly there is something called "Target Audiences" in Sharepoint where you can eliminate direct access to a list. Wrote about it here, but I've yet to implement it.

- If you spin up a SQL server thinking you'll get super secret agent, beware of that as well. There is a longstanding "issue" or "idea" regarding PowerApps and SQL.

- Something along the lines of: If you share an app that has a SQL connector with someone, they can then create their own PowerApp (separate from yours) and reuse the SQL connection to explore the tables. There are likely ways to prevent this, but thats my understanding of the rub.

- I believe CDS supports encryption and row-level security. Might be an option if you want to go that route though its a whole other ball of wax.

I'm VERY interested in what you come away with. Please share your results as they develop.
Good luck!

Microsoft KhanPower

Re: How secure are PowerApps - what data would you not put through and why?

were you able to find out best fit . i have similar situation 

Helpful resources

New Ranks and Rank Icons in April

'New Ranks and Rank Icons in April

Read the announcement for more information!

Better Together’ Contest Finalists Announced!

'Better Together’ Contest Finalists Announced!

Congrats to the finalists of our ‘Better Together’-themed T-shirt design contest! Click for the top entries.

Power Platform 2019 release wave 2 plan

Power Platform 2019 release wave 2 plan

Features releasing from October 2019 through March 2020


Community Summit North America

Innovate, Collaborate, Grow - The top training and networking event across the globe for Microsoft Business Applications

Top Solution Authors
Top Kudoed Authors
Users online (10,418)