I am looking for some advice when using Application Insights and Canvas Apps.
Currently you can simply provide an instrumentation key to any Application Insight (AI) resource and you can get the app to log telemetry to it. This provides the ability for someone to log sensitive information outside the control of the organisation if they were wanting to be malicious as they could create there own AI resource and write data to it.
As its available through the Power Apps studio connectors aren't used so i don't believe DLP policies can help in this scenario.
Does anyone know if this can be controlled at all?
Any help appreciated.
Hi @MarkPP ,
Sorry, for now, Blocking or disabling connectors is not possible. There is no option in PowerApps or Flow that would let you block or disable a particular connector.
Please submit your feedback to PowerApps Ideas forum, or vote for this similar idea.
Hope this helps
Sik
I am not asking about blocking connectors as i know you can block certain connectors via a DLP policy.
This is all about using App Insights from a Power App and providing an instrumentation key.
So when you create a Power App you can log telemetry to Application Insights by providing an instrumentation key.
This key can be to any Application Insight resource and not necessarily the organisations resources. This means someone could build an app and log telemetry out to there own personal app insight resource containing information provided by the user and potentially containing sensitive data. What i would like to understand is if an organisation wants to assure this doesn't happen is there a way to restrict the app insight resources that telemetry gets written too or is there an api you can call to see if an app is using an instrumentation key?
Thanks
Hi @MarkPP ,
Sorry, I haven't seen any tool to achieve your needs.
Please try to submit your feedback to PowerApps Ideas forums or request a Microsoft Support.
Sik
This training provides practical hands-on experience in creating Power Apps solutions in a full-day of instructor-led App creation workshop.