Introduction
A well-designed environment topology and data policy strategy prevents data exfiltration and controls what makers can build. But without matching security controls at the tenant and environment level, unauthorized users can still access environments, create resources, and reach sensitive data. Securing the platform itself by setting who can enter, what they can do once inside, and how you detect unauthorized activity completes the governance foundation.
Scenario: Unauthorized access risks at Zava
Zava's Power Platform adoption has grown rapidly across 200+ environments. Recently, a contractor retained access to the Zava Pay production environment weeks after their engagement ended and their Microsoft Entra ID account was disabled, but no one updated the environment's security group membership. A store manager accidentally shared a canvas app containing customer payment data with "Everyone" in the organization. And a developer's stolen session token was replayed from an unauthorized network to extract Dataverse records.
The admin team realized that environment creation was unrestricted, sharing had no limits, and IP-based access controls weren't enforced. They need tenant-level security controls, environment-level access management, and Entra ID security group governance to close these gaps.
What you learn in this module
This module addresses the security layer that sits between your governance structure (environments, policies) and your data model (Dataverse security, covered in the next module):
- Configuring tenant-level security settings that restrict who can create environments, share resources, and access administrative functions
- Securing individual environments with IP firewall rules, sharing limits, and Customer Lockbox
- Managing Entra ID security groups to control precisely who can access each environment
By the end of this module, you can configure a security baseline that prevents unauthorized access while maintaining the agility your maker community needs.