cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
dpj620
Frequent Visitor

Security Role assigned in Flow but access denied

My flow successfully assigns a custom security role and shares a Power App. The Power app uses a Dataverse table.  This works—the app is shared and the user shows up in the list of users assigned that security role. 

 

However, when the user attempts to open the Power App they are denied permission. In the flow, I've tried putting in Delays and reversing the steps, but still have the problem.

 

If I manually re-share the app then the data permissions dropdown is pre-populated with the correct security role for the entity. If I continue and click Share, the user can now access the Power App. Clearly my flow is needing another step, but what?

1 ACCEPTED SOLUTION

Accepted Solutions
dpj620
Frequent Visitor

Many thanks for the link to the document about sharing a canvas app. This lead me to read the section entitled Share an app with Microsoft 365 groups. Following the instructions, I set the property SecurityEnabled to true for the group that everyone is joined to in the flow. Then I manually shared the app with that M365 group while choosing the correct security role. Once a user is joined to the group, they inherit the security role and the app share from the group. This worked and is more elegant.

View solution in original post

9 REPLIES 9
ChrisPiasecki
Most Valuable Professional
Most Valuable Professional

Hi @dpj620,

 

Can you share a bit more detail about the flow such as some screenshots of the steps?

 

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.
Chris
dpj620
Frequent Visitor

Pertinent flow steps shown in attached PDF. Flow triggers in adding a new table record from a Power App.

ChrisPiasecki
Most Valuable Professional
Most Valuable Professional

Hi @dpj620 ,

 

Thanks for providing the detailed steps. Is there an Azure AD Security Group assigned to the environment? If so, is one of the steps you have listed adding the user to this particular group? Adding the user into that security group would add them to the environment.

 

Also, not sure if you tried this already, but I wonder if maybe assigning the user's security role before sharing the app with them would make a difference. Additionally, not sure what your business unit structure is like in the environment, but you may want to explicitly associate them with a business unit, then assign security role, then share the app. If you only have the root business unit then its probably not required, but I would recommend doing it anyway.

 

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.

 

 

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.
Chris
dpj620
Frequent Visitor

There is no AAD Security Group assigned to the environment. Although this page indicates that  all properly licensed users will be enabled by default ("If a Dataverse environment does not have an associated security group, all users with a Dataverse license (customer engagement apps (Dynamics 365 Sales, Dynamics 365 Customer Service, Dynamics 365 Field Service, Dynamics 365 Marketing, and Dynamics 365 Project Service Automation), Power Automate, Power Apps, etc.) will be created as users and enabled in the environment.").

 

Also, I've reversed the order of assigning the security role and app sharing, It made no difference.

 

Here's the difference between sharing via the Flow and sharing manually as far assigned security role:

Sharing.png

EricRegnier
Most Valuable Professional
Most Valuable Professional

Hi @dpj620, is looks like a canvas app but can you confirm if you are trying to share a model-driven app or canvas app? If your database is Dataverse, it seems you're also missing a step to assign a Dataverse security role to the user before sharing the app. 

Cheers

dpj620
Frequent Visitor

Canvas app.

 

The step to assign the security role is in the flow (PDF above) and it works. It made no difference which order (assign security role then share app or share app then assign security role) I had them in the Flow.

 

I can go to the Power Platform Admin center and see the employee assigned in the flow listed under that role.

 

dpj620_0-1617691012276.png

 

EricRegnier
Most Valuable Professional
Most Valuable Professional

Sharing a canvas app manually like in your previous screenshot actually does 2 things:

  1. Shares the app directly the user
  2. (Optionally) if you select a security role, it will auto-assign that role to the user for convenience.
    Note: when selecting a user, if the user does roles, then you'll see those roles pre-selected. If the user doesn't have any then it means he/she doesn't have any roles assigned yet.

Regardless if the user has a security role assigned or not, shouldn't affect whether they see the app. Sharing the app grants access to the app, security roles to the data access by the app. But in saying that, I just tried from my side (without assign a role) and getting the same behavior as you with the error message "The security roles didn't load" when I open the Share app window afterwards. I thing this is actually a bug and would lodge a Microsoft support ticket at: https://admin.powerplatform.microsoft.com/support

Keep up posted!

ChrisPiasecki
Most Valuable Professional
Most Valuable Professional

Yes I agree with @EricRegnier that this behavior is not as designed and warrants a support ticket with MS. You should not have to go through this additional hoop of trying to assign the Security Role for every Dataverse table data source, rather just setting the security role once at the user level like you already are doing in the flow.

 

The doc on Sharing a Canvas App has a strange note at the bottom that doesn't seem to make much sense, so I don't know if it would all be related to this or not but figured I'd post it here incase it is relevant.

 

When you share an app that's based on an older version of Dataverse, you must share the runtime permission to the service separately. If you don’t have permission to do this, see your environment administrator.

 

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.

---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.
Chris
dpj620
Frequent Visitor

Many thanks for the link to the document about sharing a canvas app. This lead me to read the section entitled Share an app with Microsoft 365 groups. Following the instructions, I set the property SecurityEnabled to true for the group that everyone is joined to in the flow. Then I manually shared the app with that M365 group while choosing the correct security role. Once a user is joined to the group, they inherit the security role and the app share from the group. This worked and is more elegant.

Helpful resources

Announcements

Tuesday Tip | How to Get Community Support

It's time for another Tuesday Tip, your weekly connection with the most insightful tips and tricks that empower both newcomers and veterans in the Power Platform Community! Every Tuesday, we bring you a curated selection of the finest advice, distilled from the resources and tools in the Community. Whether you’re a seasoned member or just getting started, Tuesday Tips are the perfect compass guiding you across the dynamic landscape of the Power Platform Community.       This Week: All About Community Support Whether you're a seasoned community veteran or just getting started, you may need a bit of help from time to time! If you need to share feedback with the Community Engagement team about the community or are looking for ways we can assist you with user groups, events, or something else, Community Support is the place to start.   Community Support is part of every one of our communities, accessible to all our community members.   Within each community's Community Support page, you'll find three distinct areas, each with a different focus to help you when you need support from us most. Power Apps: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pa_community_support Power Automate: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpa_community_support Power Pages: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpp_community_support Copilot Studio: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pva_community-support   Community Support Form If you need more assistance, you can reach out to the Community Team via the Community support form. Choose the type of support you require and fill in the form accordingly. We will respond to you promptly.    Thank you for being an active part of our community. Your contributions make a difference!   Best Regards, The Community Management Team

Community Roundup: A Look Back at Our Last 10 Tuesday Tips

As we continue to grow and learn together, it's important to reflect on the valuable insights we've shared. For today's #TuesdayTip, we're excited to take a moment to look back at the last 10 tips we've shared in case you missed any or want to revisit them. Thanks for your incredible support for this series--we're so glad it was able to help so many of you navigate your community experience!   Getting Started in the Community An overview of everything you need to know about navigating the community on one page!  Community Links: ○ Power Apps ○ Power Automate  ○ Power Pages  ○ Copilot Studio    Community Ranks and YOU Have you ever wondered how your fellow community members ascend the ranks within our community? We explain everything about ranks and how to achieve points so you can climb up in the rankings! Community Links: ○ Power Apps ○ Power Automate  ○ Power Pages  ○ Copilot Studio    Powering Up Your Community Profile Your Community User Profile is how the Community knows you--so it's essential that it works the way you need it to! From changing your username to updating contact information, this Knowledge Base Article is your best resource for powering up your profile. Community Links: ○ Power Apps ○ Power Automate  ○ Power Pages  ○ Copilot Studio    Community Blogs--A Great Place to Start There's so much you'll discover in the Community Blogs, and we hope you'll check them out today!  Community Links: ○ Power Apps ○ Power Automate  ○ Power Pages  ○ Copilot Studio    Unlocking Community Achievements and Earning Badges Across the Communities, you'll see badges on users profile that recognize and reward their engagement and contributions. Check out some details on Community badges--and find out more in the detailed link at the end of the article! Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio    Blogging in the Community Interested in blogging? Everything you need to know on writing blogs in our four communities! Get started blogging across the Power Platform communities today! Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio   Subscriptions & Notifications We don't want you to miss a thing in the community! Read all about how to subscribe to sections of our forums and how to setup your notifications! Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio   Getting Started with Private Messages & Macros Do you want to enhance your communication in the Community and streamline your interactions? One of the best ways to do this is to ensure you are using Private Messaging--and the ever-handy macros that are available to you as a Community member! Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio   Community User Groups Learn everything about being part of, starting, or leading a User Group in the Power Platform Community. Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio   Update Your Community Profile Today! Keep your community profile up to date which is essential for staying connected and engaged with the community. Community Links: ○ Power Apps  ○ Power Automate  ○ Power Pages  ○ Copilot Studio   Thank you for being an integral part of our journey.   Here's to many more Tuesday Tips as we pave the way for a brighter, more connected future! As always, watch the News & Announcements for the next set of tips, coming soon!

Hear what's next for the Power Up Program

Hear from Principal Program Manager, Dimpi Gandhi, to discover the latest enhancements to the Microsoft #PowerUpProgram, including a new accelerated video-based curriculum crafted with the expertise of Microsoft MVPs, Rory Neary and Charlie Phipps-Bennett. If you’d like to hear what’s coming next, click the link below to sign up today! https://aka.ms/PowerUp  

Tuesday Tip: Community User Groups

It's time for another TUESDAY TIPS, your weekly connection with the most insightful tips and tricks that empower both newcomers and veterans in the Power Platform Community! Every Tuesday, we bring you a curated selection of the finest advice, distilled from the resources and tools in the Community. Whether you’re a seasoned member or just getting started, Tuesday Tips are the perfect compass guiding you across the dynamic landscape of the Power Platform Community.   As our community family expands each week, we revisit our essential tools, tips, and tricks to ensure you’re well-versed in the community’s pulse. Keep an eye on the News & Announcements for your weekly Tuesday Tips—you never know what you may learn!   Today's Tip: Community User Groups and YOU Being part of, starting, or leading a User Group can have many great benefits for our community members who want to learn, share, and connect with others who are interested in the Microsoft Power Platform and the low-code revolution.   When you are part of a User Group, you discover amazing connections, learn incredible things, and build your skills. Some User Groups work in the virtual space, but many meet in physical locations, meaning you have several options when it comes to building community with people who are learning and growing together!   Some of the benefits of our Community User Groups are: Network with like-minded peers and product experts, and get in front of potential employers and clients.Learn from industry experts and influencers and make your own solutions more successful.Access exclusive community space, resources, tools, and support from Microsoft.Collaborate on projects, share best practices, and empower each other. These are just a few of the reasons why our community members love their User Groups. Don't wait. Get involved with (or maybe even start) a User Group today--just follow the tips below to get started.For current or new User Group leaders, all the information you need is here: User Group Leader Get Started GuideOnce you've kicked off your User Group, find the resources you need:  Community User Group ExperienceHave questions about our Community User Groups? Let us know! We are here to help you!

Super User of the Month | Ahmed Salih

We're thrilled to announce that Ahmed Salih is our Super User of the Month for April 2024. Ahmed has been one of our most active Super Users this year--in fact, he kicked off the year in our Community with this great video reminder of why being a Super User has been so important to him!   Ahmed is the Senior Power Platform Architect at Saint Jude's Children's Research Hospital in Memphis. He's been a Super User for two seasons and is also a Microsoft MVP! He's celebrating his 3rd year being active in the Community--and he's received more than 500 kudos while authoring nearly 300 solutions. Ahmed's contributions to the Super User in Training program has been invaluable, with his most recent session with SUIT highlighting an incredible amount of best practices and tips that have helped him achieve his success.   Ahmed's infectious enthusiasm and boundless energy are a key reason why so many Community members appreciate how he brings his personality--and expertise--to every interaction. With all the solutions he provides, his willingness to help the Community learn more about Power Platform, and his sheer joy in life, we are pleased to celebrate Ahmed and all his contributions! You can find him in the Community and on LinkedIn. Congratulations, Ahmed--thank you for being a SUPER user!  

Tuesday Tip: Getting Started with Private Messages & Macros

Welcome to TUESDAY TIPS, your weekly connection with the most insightful tips and tricks that empower both newcomers and veterans in the Power Platform Community! Every Tuesday, we bring you a curated selection of the finest advice, distilled from the resources and tools in the Community. Whether you’re a seasoned member or just getting started, Tuesday Tips are the perfect compass guiding you across the dynamic landscape of the Power Platform Community.   As our community family expands each week, we revisit our essential tools, tips, and tricks to ensure you’re well-versed in the community’s pulse. Keep an eye on the News & Announcements for your weekly Tuesday Tips—you never know what you may learn!   This Week's Tip: Private Messaging & Macros in Power Apps Community   Do you want to enhance your communication in the Community and streamline your interactions? One of the best ways to do this is to ensure you are using Private Messaging--and the ever-handy macros that are available to you as a Community member!   Our Knowledge Base article about private messaging and macros is the best place to find out more. Check it out today and discover some key tips and tricks when it comes to messages and macros:   Private Messaging: Learn how to enable private messages in your community profile and ensure you’re connected with other community membersMacros Explained: Discover the convenience of macros—prewritten text snippets that save time when posting in forums or sending private messagesCreating Macros: Follow simple steps to create your own macros for efficient communication within the Power Apps CommunityUsage Guide: Understand how to apply macros in posts and private messages, enhancing your interaction with the Community For detailed instructions and more information, visit the full page in your community today:Power Apps: Enabling Private Messaging & How to Use Macros (Power Apps)Power Automate: Enabling Private Messaging & How to Use Macros (Power Automate)  Copilot Studio: Enabling Private Messaging &How to Use Macros (Copilot Studio) Power Pages: Enabling Private Messaging & How to Use Macros (Power Pages)

Users online (3,584)