cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
DS2
Advocate IV
Advocate IV

Power Apps Service Accounts in Environments Best Practices

Hi All,
I have two questions surrounding service accounts and Power Apps if anyone has some best practices they could share.
We use service accounts for our environments and our environments are usually in the format of DEV, QA and PROD
For example, we have a premium environment set of 3 that allows premium connectors, SQL and Dataverse use and it may follow a naming convention as so:

Premium-DEV environment for development
Premium-QA environment for testing
Premium-Prod environment for production

These three environments would have Power Apps within them. For an example, let's say that a Power App named Marketing Pictures exists in all of these environments.
The way we are doing things right now, that Marketing Pictures App would have 3 service accounts, one for each environment, where the service account is the owner of the Marketing Pictures App, with a naming convention of:

service.MarketingPictures-DEV (in Dev Environment)
service.MarketingPictures-QA (in QA Environment)
service.MarketingPictures-Prod (in Prod Environment)

My questions about best practice\best way forward are as follows:

1) Security roles: What security roles should these service accounts have? If you're working with Dataverse, usually the account that is the owner of the App requires at least System Customizer, but this role allows other access within the environment o the App. Same with Exporting and Importing the App into different environments (DEV > QA > PROD). This usually requires the System Administrator role, but then the service account can do anything within the environment including modifying Power Apps that aren't their own.
2) Security of passwords: We sometimes use third-party developers to help with actual code needed in the low-code Power Platform, or they may build an App for us. We provide the service account passwords to them so they can develop in the respective environments. For password security, is there some better way than providing the third-party devs with the passwords to the 3 service accounts and then changing those passwords (and all the connections!) for within the 3 environments?

1 ACCEPTED SOLUTION

Accepted Solutions
BCLS776
Super User
Super User

It sounds like you recognize the risks that come from sharing passwords to service accounts that may have System Admin level access.

A far better practice: create separate accounts for third-party or internal developers with least privilege to perform their work. Then, as flows/apps are constructed add the service account as a co-owner to each. You can do this through a Power Automate flow that runs daily and does this automatically. 

 

Hope that helps,

Bryan

_________________________________________________________________________________________
Help the community help more users by choosing to "Accept as Solution" if this post met your needs. If you liked the post and want to show some appreciation, please give it a Thumbs Up.

View solution in original post

6 REPLIES 6
BCLS776
Super User
Super User

It sounds like you recognize the risks that come from sharing passwords to service accounts that may have System Admin level access.

A far better practice: create separate accounts for third-party or internal developers with least privilege to perform their work. Then, as flows/apps are constructed add the service account as a co-owner to each. You can do this through a Power Automate flow that runs daily and does this automatically. 

 

Hope that helps,

Bryan

_________________________________________________________________________________________
Help the community help more users by choosing to "Accept as Solution" if this post met your needs. If you liked the post and want to show some appreciation, please give it a Thumbs Up.
DS2
Advocate IV
Advocate IV

Thanks, @BCLS776 - very helpful. When you say "Then, as flows/apps are constructed add the service account as a co-owner to each. You can do this through a Power Automate flow that runs daily and does this automatically," can you please elaborate a little? What would the daily Flow do? Would it enumerate all Flows and check membership and then add the service account as co-owner or something else? Much thanks!

 

BCLS776
Super User
Super User

This YouTube video will walk you through using the functionality: https://www.youtube.com/watch?v=-ZWm4VGwWe0

 

In short, you create a flow that runs daily and looks for all flows in the environment created in the last 24 hours. Then, add the service account as a co-owner to each of those flows. PowerShell also offers functionality around this.

 

If you are looking for additional help around governance, Microsoft created a Center of Excellence package that you can install in your tenant to help with managing.

_________________________________________________________________________________________
Help the community help more users by choosing to "Accept as Solution" if this post met your needs. If you liked the post and want to show some appreciation, please give it a Thumbs Up.
doppers
Frequent Visitor

Hi and very grateful someone has already asked this question 😀 , I wanted to follow on from this point as we have a similar situation in my firm.

Can I please confirm  :
a) that the 3rd party developers have named account with least privilege access (quite rightly!) to build the app and flows?

b) can the developer add the service account to the app and flows to be a co-owner manually or this has to be done as suggested 

c) once developer has completed the work, we can disable the named developer account so app and flows will not break as the service account is the co-owner?


@doppers wrote:

Hi and very grateful someone has already asked this question 😀 , I wanted to follow on from this point as we have a similar situation in my firm.

Can I please confirm  :
a) that the 3rd party developers have named account with least privilege access (quite rightly!) to build the app and flows?

b) can the developer add the service account to the app and flows to be a co-owner manually or this has to be done as suggested 

c) once developer has completed the work, we can disable the named developer account so app and flows will not break as the service account is the co-owner?


To more fully answer your questions, I suggest searching on here for what firms do when citizen developers leave a company and their account gets shut off - it is a very similar situation.

Yes, you can add co-owners manually, but an automatic flow that does this for you is a great fail-safe.

 

I recommend having a conversation with your developers about what you intend to do with their accounts after the work is done. You want to be clear with them that you expect any functionality they build to continue working after the account is disabled. Depending on what they are doing for you, this may require more than adding co-ownership to flows/apps.

Hope that helps,

Bryan

_________________________________________________________________________________________
Help the community help more users by choosing to "Accept as Solution" if this post met your needs. If you liked the post and want to show some appreciation, please give it a Thumbs Up.

Hi @doppers 
We are following this path:
1)The third-party developers get least privilege and named accounts and they only have access to the dev environment. We move the solutions either via pipelines, manually or eventually ALM Accelerator and therefore the correct account (service account for the App) gets ownership 
2) We ensure they transfer ownership of the solution in Dev before their contract is done

Does that help?

Helpful resources

Announcements

Power Platform Connections - Episode 7 | March 30, 2023

Episode Seven of Power Platform Connections sees David Warner and Hugo Bernier talk to Dian Taylor, alongside the latest news, product reviews, and community blogs.     Use the hashtag #PowerPlatformConnects on social media for a chance to have your work featured on the show.     

Announcing | Super Users - 2023 Season 1

Super Users – 2023 Season 1    We are excited to kick off the Power Users Super User Program for 2023 - Season 1.  The Power Platform Super Users have done an amazing job in keeping the Power Platform communities helpful, accurate and responsive. We would like to send these amazing folks a big THANK YOU for their efforts.      Super User Season 1 | Contributions July 1, 2022 – December 31, 2022  Super User Season 2 | Contributions January 1, 2023 – June 30, 2023    Curious what a Super User is? Super Users are especially active community members who are eager to help others with their community questions. There are 2 Super User seasons in a year, and we monitor the community for new potential Super Users at the end of each season. Super Users are recognized in the community with both a rank name and icon next to their username, and a seasonal badge on their profile.    Power Apps  Power Automate  Power Virtual Agents  Power Pages  Pstork1*  Pstork1*  Pstork1*  OliverRodrigues  BCBuizer  Expiscornovus*  Expiscornovus*  ragavanrajan  AhmedSalih  grantjenkins  renatoromao    Mira_Ghaly*  Mira_Ghaly*      Sundeep_Malik*  Sundeep_Malik*      SudeepGhatakNZ*  SudeepGhatakNZ*      StretchFredrik*  StretchFredrik*      365-Assist*  365-Assist*      cha_cha  ekarim2020      timl  Hardesh15      iAm_ManCat  annajhaveri      SebS  Rhiassuring      LaurensM  abm      TheRobRush  Ankesh_49      WiZey  lbendlin      Nogueira1306  Kaif_Siddique      victorcp  RobElliott      dpoggemann  srduval      SBax  CFernandes      Roverandom  schwibach      Akser  CraigStewart      PowerRanger  MichaelAnnis      subsguts  David_MA      EricRegnier  edgonzales      zmansuri  GeorgiosG      ChrisPiasecki  ryule      AmDev  fchopo      phipps0218  tom_riha      theapurva  takolota     Akash17  momlo     BCLS776  Shuvam-rpa     rampprakash  ScottShearer     Rusk  ChristianAbata     cchannon  Koen5     a33ik   Heartholme     AaronKnox        Matren        Alex_10        Jeff_Thorpe        poweractivate        Ramole        DianaBirkelbach        DavidZoon        AJ_Z        PriyankaGeethik        BrianS        StalinPonnusamy        HamidBee        CNT        Anonymous_Hippo        Anchov        KeithAtherton        alaabitar        Tolu_Victor        KRider        sperry1625        IPC_ahaas      zuurg    rubin_boer   cwebb365   Dorrinda   G1124   Gabibalaban   Manan-Malhotra   jcfDaniel   WarrenBelz   Waegemma      If an * is at the end of a user's name this means they are a Multi Super User, in more than one community. Please note this is not the final list, as we are pending a few acceptances.  Once they are received the list will be updated. 

Microsoft Power Platform Conference | Registration Open | Oct. 3-5 2023

We are so excited to see you for the Microsoft Power Platform Conference in Las Vegas October 3-5 2023! But first, let's take a look back at some fun moments and the best community in tech from MPPC 2022 in Orlando, Florida.   Featuring guest speakers such as Charles Lamanna, Heather Cook, Julie Strauss, Nirav Shah, Ryan Cunningham, Sangya Singh, Stephen Siciliano, Hugo Bernier and many more.   Register today: https://www.powerplatformconf.com/   

Check out the new Power Platform Communities Front Door Experience!

We are excited to share the ‘Power Platform Communities Front Door’ experience with you!   Front Door brings together content from all the Power Platform communities into a single place for our community members, customers and low-code, no-code enthusiasts to learn, share and engage with peers, advocates, community program managers and our product team members. There are a host of features and new capabilities now available on Power Platform Communities Front Door to make content more discoverable for all power product community users which includes ForumsUser GroupsEventsCommunity highlightsCommunity by numbersLinks to all communities Users can see top discussions from across all the Power Platform communities and easily navigate to the latest or trending posts for further interaction. Additionally, they can filter to individual products as well.       Users can filter and browse the user group events from all power platform products with feature parity to existing community user group experience and added filtering capabilities.     Users can now explore user groups on the Power Platform Front Door landing page with capability to view all products in Power Platform.    Explore Power Platform Communities Front Door today. Visit Power Platform Community Front door to easily navigate to the different product communities, view a roll up of user groups, events and forums.

Welcome to the Power Apps Community

Welcome! Congratulations on joining the Microsoft Power Apps community! You are now a part of a vibrant group of peers and industry experts who are here to network, share knowledge, and even have a little fun! Now that you are a member, you can enjoy the following resources:   The Microsoft Power Apps Community Forums If you are looking for support with any part of Microsoft Power Apps, our forums are the place to go. They are titled "Get Help with Microsoft Power Apps " and there you will find thousands of technical professionals with years of experience who are ready and eager to answer your questions. You now have the ability to post, reply and give "kudos" on the Power Apps community forums! Make sure you conduct a quick search before creating a new post because your question may have already been asked and answered!   Microsoft Power Apps IdeasDo you have an idea to improve the Microsoft Power Apps experience, or a feature request for future product updates? Then the "Power Apps Ideas" section is where you can contribute your suggestions and vote for ideas posted by other community members. We constantly look to the most voted Ideas when planning updates, so your suggestions and votes will always make a difference.   Community Blog & NewsOver the years, more than 600 Power Apps Community Blog Articles have been written and published by our thriving community. Our community members have learned some excellent tips and have keen insights on building Power Apps. On the Power Apps Community Blog, read the latest Power Apps related posts from our community blog authors around the world. Let us know if you would like to become an author and contribute your own writing — everything Power Apps related is welcome!   Power Apps Samples, Learning and Videos GalleriesOur galleries have a little bit of everything to do with Power Apps. Our galleries are great for finding inspiration for your next app or component. You can view, comment and kudo the apps and component gallery to see what others have created! Or share Power Apps that you have created with other Power Apps enthusiasts. Along with all of that awesome content, there is the Power Apps Community Video & MBAS gallery where you can watch tutorials and demos by Microsoft staff, partners, and community gurus in our community video gallery.   Again, we are excited to welcome you to the Microsoft Power Apps community family! Whether you are brand new to the world of process automation or you are a seasoned Power Apps veteran. Our goal is to shape the community to be your ‘go to’ for support, networking, education, inspiration and encouragement as we enjoy this adventure together!   Let us know in the Community Feedback if you have any questions or comments about your community experience.To learn more about the community and your account be sure to visit our Community Support Area boards to learn more! We look forward to seeing you in the Power Apps Community!The Power Apps Team

Top Solution Authors
Top Kudoed Authors
Users online (3,421)