Summary
Ungoverned data flows are one of the highest-risk gaps in any Power Platform estate. In this module, you learned how data policies create boundaries around connector data sharing, giving you systematic control over how information moves between services.
You explored how data policies work at two scope levels - tenant-wide baselines that can't be overridden, and environment-specific policies that add restrictions for sensitive workloads. You configured granular controls including action-level blocking, endpoint filtering, and custom connector classification using URL patterns. You applied these concepts to Copilot Studio agents, governing knowledge sources, publishing channels, and skills through virtual connectors. Finally, you designed a layered strategy that balances security with maker productivity across multiple governance zones.
With these skills, Zava's admin team can prevent data exfiltration scenarios, like the marketing flow that connected PCI-regulated data to an external email tool. Makers stay productive within well-defined boundaries. The layered approach ensures that governance scales with the organization: new environments inherit baseline protections automatically, and new connectors are handled predictably.