Introduction
As organizations adopt Power Platform at scale, the number of connectors available to makers grows rapidly. Each connector represents a potential data pathway, a bridge between systems that can move sensitive information if left ungoverned. Without guardrails, a well-intentioned app or flow could inadvertently share customer financial data with a social media service or route proprietary information through an unapproved third-party API.
The scenario
Zava's Power Platform estate now spans hundreds of apps, flows, and Copilot Studio agents. Last quarter, an internal review found a cloud flow in the marketing department that connected Zava Pay's customer database (via Dataverse) to a third-party email marketing tool. This connection could expose PCI (Payment Card Industry)-regulated cardholder data outside approved systems. A separate Copilot Studio agent was pulling knowledge from a public website, inadvertently surfacing unverified financial guidance to customers.
These aren't malicious acts. They're the natural result of a platform designed for productivity operating without data boundaries. Zava's admin team needs a systematic way to control which connectors can share data and restrict specific actions within connectors. The team also needs to apply targeted policies to AI-powered resources, all without blocking the innovation that makes Power Platform valuable.
What you learn in this module
Data policies in Microsoft Power Platform let you define rules that govern which connectors can be used together, which actions are allowed, and how data flows between services. In this module, you create and scope data policies at the tenant and environment level, and configure granular connector and action restrictions. You also apply policies specifically to Copilot Studio agents, and design a layered strategy that balances security with maker productivity.
As part of designing your data policies, you implement both classic data policies (DLP) and the next generation of Advanced Connector Policies (ACP). Advanced Connector Policies currently apply to certified connectors only. Custom connectors and HTTP connectors aren't yet supported and continue to use DLP policies. Implementing advanced connector policies gives you greater control and granularity in securing and managing connector usage, and enhances the overall governance of your Power Platform environments.
By the end of this module, you can:
- Create and apply data policies at the tenant and environment level.
- Restrict connectors, actions, and endpoints to control data flow granularly.
- Configure data policies for Copilot Studio agents, including knowledge sources and channels.
- Design a multi-policy strategy that layers tenant-wide baselines with environment-specific controls.