惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
博客园 - 叶小钗
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
博客园 - 【当耐特】
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
Visual Studio Blog
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
IT之家
IT之家
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
爱范儿
爱范儿
罗磊的独立博客
雷峰网
雷峰网
量子位
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Hugging Face - Blog
Hugging Face - Blog
Cyberwarzone
Cyberwarzone
G
GRAHAM CLULEY
宝玉的分享
宝玉的分享
P
Privacy International News Feed
S
Schneier on Security
W
WeLiveSecurity
H
Heimdal Security Blog
I
Intezer
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
美团技术团队
N
News | PayPal Newsroom
T
The Exploit Database - CXSecurity.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
Project Zero
Project Zero
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Power Platform Environments
david wyatt · 2026-04-25 · via DEV Community

I had an interesting converstation with my Architect recently about Power Platform environments, we have the most fun chats lol. And it made me think I thought about how they should probably change, and what the future holds.

There are 3 things that I want to talk about

  1. Quick Fixes
  2. Big Fixes
  3. The Future

1. Quick Fixes

The trusty Power Platform environments hasn't changed much over the years. Yes we have had managed environments and developer environments. But they are only skin deep changes, deep down nothing has changed. And that makes sense, as its the foundation of the platform so we can't go around making breaking changes.

But I think there are still a few easy win changes.

Well first lets go back to that elephant in the room, Dynamics. As the Power Platform is built on Dynamics, that means every environment is setup like a Dynamics instance.

Security Roles

There are a 100 security roles added to each new environment, now I don't about you but I have probable used less then 10

# Role Name
1 Agent 365 Tools Role
2 AIB Roles
3 AIB SML Roles
4 ApolloServiceRole
5 App Deployment Orchestration Role
6 App Opener
7 Approvals Administrator
8 Approvals User
9 Async ingestion
10 Basic User
11 BizQAApp
12 Bot Author
13 Bot Contributor
14 Bot Transcript Viewer
15 Bulk Archival Role
16 BusinessApplicationPlatformRole
17 Cards Basic Role
18 Cards Role
19 CCI admin
20 ContextualAIS2SRole
21 Data Sync Framework Role
22 Data Sync Service Role
23 Dataflow Maker
24 DataLakeFolderEntityContributor
25 DataLakeWorkspaceAppAccess
26 DataProcessingConfigTableAppAccess
27 Dataverse as a Cluster App Role
28 Dataverse Search Role
29 Deflection Service Role
30 Delegate
31 Delegated Mailbox Approver
32 Desktop Flow Machine Configuration Admin
33 Desktop Flows AI Application User
34 Desktop Flows Machine Application User
35 Desktop Flows Machine Owner
36 Desktop Flows Machine User
37 Desktop Flows Machine User Can Share
38 Desktop Flows Module Developer
39 Desktop Flows Runtime Application User
40 EAC App Access
41 EAC Reader App Access
42 Environment Maker
43 Export Customizations (Solution Checker)
44 Fabric AI Skill Role
45 Federated Knowledge Role
46 FileStoreService App Access
47 Flow-CDS Native Connector Role
48 Flow-RP Role
49 Global Active Metrics Monitoring Alerting Custom Role
50 Global Discovery Service Role
51 Help Page Author
52 Help Page Consumer
53 Insights Apps Platform Role
54 IntegratedSearchApp
55 Knowledge Manager
56 Knowledge Quality Service
57 Knowledge Quality Service Role
58 Microsoft Copilot Administrator
59 Microsoft Copilot User
60 Non-Relational Data App Access
61 Office Collaborator
62 Omnichannel CDS Flush Role
63 Portal Application User
64 Portal RP Service Role
65 Power Apps Checker Service Role
66 Power Automate AI Flows Application User
67 Power Automate Operator
68 Power BI Embedded App Access
69 Power BI workspace admin
70 Power BI workspace contributor
71 Power BI workspace viewer
72 Power Platform Data Analytics Role
73 Power Platform Dataflows Service Role
74 Power Policy App User Role
75 PowerAppsRPRole
76 PowerPlatformInsightsRole
77 Process Mining Application
78 Process Mining User
79 Project Background Services App Role
80 Purview Label Role
81 Report Service Role
82 RPE Role
83 Service Deleter
84 Service Reader
85 Service Writer
86 Solution Checker
87 SuggestedActionS2SRole
88 Support User
89 SupportUserCustomAPI Role
90 Sustainability all - full access Role
91 Sustainability all - ingest - full access Role
92 Sustainability BusinessUnit - full access Role
93 Sustainability BusinessUnit - ingest - full access Role
94 Synapse Link Service Access
95 Sync Permissions
96 System Administrator
97 System Customizer
98 Teams Chat Sync App Access
99 Tour Author
100 Tour Consumer

Imagine if we only had Power Platform specific roles, maybe:

  • Environment Maker
  • System Administrator
  • System Customizer

We then have an option to add roles like Approvals, Copilot Studio and Power Automate Desktop. All of the system ones for spn's could be abstracted away. Finally I would make basic user on by default, so if you access the environment then you are given the role. And any that are removed with no way to add could be documented so that admins can create them themselves if needed (or our friend Copilot 😎.

System Customizer

There is also the problem with the system customizer role. Its Dynamics day role was to allow the maker to create custom tables. Without it if you create a custom table you can't add data to it without a custom security role (so you need to make the table, then make the role, then use the table). The idea was sound, as it removed the environment settings but allowed the developer full access to the data in the non-prod environment. But as the Power Platform grew and became solution aware the plan broke.

Because the platform is built on the platform i.e. flows are stored in the same way as custom data, we have a big issue with our security roles.

  • You want to create Dataverse tables - System Customizer/custom role
  • You want to add data to a table without a custom role - System Customizer
  • You want to create custom AI builder model - System Customizer
  • You want to create a security role - System Administrator

Thats right to do any of the above development I need the permission to see all Dataverse tables, including system tables like flows. And if you want to give someone that secuirty role, well only admins can, because you could easily give yourself any role.

There needs to be a new role that is purely scoped to custom tables created by the maker. That way if you create a table you can add data etc, but no one else can until they are given permission.

Common Data Model tables

We also have the Common Data Model tables, as the environment owner I should decide if I want a Accounts table, don't waste my expensive Dataverse storage with unused/misused tables, and clutter it with tables I will never use.

Not only would you save all that Dataverse capacity you get the added benefits of:

  • Simpler to administor
  • Less vector of attack (unecessary roles and consitent database structure is a hackers Christmas)

The simple approach would be to have the tables in a solution you can download/add.

As this is a quick fix section, the easy update would be to enable admins to delete the tables, so I may be forced to include on setup but I can at least run a script/flow post setup to remove them

2. Big Fixes

In a nutshell an environment is kind of a container.

Containers are lightweight, portable software packages that bundle an application's code with everything it needs to run (libraries, dependencies, settings) into a single, isolated unit, allowing it to run consistently and reliably anywhere

If you think of things like Dataverse tables, api's, model driven apps, as libraries, dependencies, settings, then it kind of makes sense.

In the Microsoft world you might even think of them as a Resource Group (I suspect under the hood they are). But a resource group is meant to act as a lifecycle boundary: everything in it is created, updated and deleted together. Guess what has a lifecycle boundary in the Power Platform, that's right a Solution.

So really a solution is a resource group, but its not treated like that. Because Resources groups also come with scope permissions to the Resource Group and its contents, Solutions do not have that, there is no permission to see a Solution, just its contents. A Solution is more like a filtered view then a folder.

And I think that contradiction has made a mess. And its because of the Dynamics, which treats solutions like components and the environment the container. If you see it through the eyes of Dynamics it makes sense, but through the eyes of the Power Platform it doesnt.

I think there needs to be a refocus, with the environments tending more to Power Platform needs.

We need to treat solutions more like the container. They need to have security roles scoped to them. So as an example a developer with a Solution Customizer role could:

  • See everything in the solution
  • Create custom tables and add data to them within the solution
  • Edit all flows/apps within the solution

But they couldn't

  • Delete the solution
  • Create security roles at the environment level
  • Edit solution details

That would be limited to the Solution Administrator or other role.

This would bring the power platform in line with PoLP (Principle of Least Privilege), as someone who simply wants to create a custom table and security profile should not need permission to change the environment settings and view/edit all other developers work.

The other big issue, which Microsoft is trying to fix is hierarchy. Each environment is a totally separate entity. This is ok when you work within the environment, but what about when you work above. As a environment admin dealing with environments is not fun. Everything is silo'd away, and getting a rolled up global view is only possible by a series of loops and copying of data.

The new Inventory setup in the PPAC is trying to solve this problem, and doing well. But under the hood it seems to be just doing the loops and copying for us, not fixing the underlying issue. It also is:

-Limited to Global Admins (PolP alert, though RBAC is planned)
-Limts data to PPAC

The environments should be structured in a hierarchy, with all platform data in one source. Then each environment role a given permissions to those records. Why have a hundred Security role tables when we could have one that is filtered to each environment.

Although that sounds like more work for the CoE, who now cant outsource environment administration so easily, it doesn't stop this, and it gives them greater visibility and control (and don't forget, with a Solution Customizer role you shouldn't need admins purely to create security roles).

3. The Future

So that's how I would fix enviroments, strip them down to focus on the Power Platform, and create lower-level granular security roles at the solution level.

But what about the future, well that's where I think the environment update becomes more important. The Power Platform is growing beyond Low-Code, for a long time the platform was simply to enable the low-code tools. But with the advent of AI, and the democracising of Pro-Code we are fast approaching a would where the platform becomes the value.

Code Apps prove this, if you think about it, I can now use GitHub Copilot to create feature which Pro-Code apps/sites, but that is only ski deep. Things like security, Auth, life cycle, deploying, load balancing, etc are all things that AI can maybe do, but not easily. Enter the Power Platform, now my AI generated apps are secure, have built in auth, deployments, roles, life cycle, everything that you would worry about, How cool is that, you have the walled garden that you can unleash AI in with a lot less risk.


For a while its felt like its hard to get improvements in the Power Platform unless its Copilot/AI related, so for a while I doubted updates to the environments would ever happen. But now with the ability to use the platform for AI generated code instead of Low-Code, I think it might get the support now, come on Micrsooft, lets get environments fixed.