Govern Power Platform Environments
Route makers into governed Power Platform environments and enforce consistent guardrails — sharing limits, security scanning, and Dataverse data protection — so agents are built inside a controlled boundary rather than the open default environment.
Core capabilities
-
Enable the managed boundary first — every environment-scoped guardrail below depends on it
-
Route makers into their own managed developer environments so agents are never built in the ungoverned default environment
-
Group those environments and enforce one consistent set of security, sharing, and lifecycle rules across all of them at scale
-
Cap how widely apps, flows, and agents can be shared to contain the blast radius of an over-shared agent
-
Enforce the security ruleset on import so injection-prone or insecure components are blocked before they reach production
Supporting capabilities 5
-
Restrict Dataverse access to trusted IP ranges and bind sessions to their origin to block exfiltration and token replay
-
Hold the encryption key for the environment's data at rest, with the option to revoke Microsoft access
-
Require explicit approval before a Microsoft engineer can access the environment's data
-
Mask sensitive Dataverse columns so agents see obfuscated values unless a profile permits the real value (preview)
-
Log data changes and access across the environment for accountability and later investigation