TECHNOLOGIES: POWER APPS

Power Apps Security Review and Access Configuration Testing

A Power App puts a slice of Dataverse, or whatever data source it connects to, in front of a defined group of internal users, and what each of them can actually do comes down to three separate decisions: how the app was shared, which security role came with that share, and which connection its calls run under. Get any one of those wrong and a user without the role you meant to give them still sees the same screen, or a connection created under someone else’s login does the fetching for everyone the app reaches. We test the app under every role it’s shared with, review each connection and environment behind it, and check the platform governance, DLP policy, custom connectors and any custom component built on top. CREST-certified testers, fixed price from £3,920 for a 3-day single-environment scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Power Apps Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Connections

Every action a Power App takes runs through a connection, and by default that connection belongs to whoever created it, not to the app or the person using it.

A Power App is only as private as the connection running behind it

A Power App is a thin layer over Dataverse or another data source, and how far a user gets through it depends on how the app was shared and what came with that share. Sharing a canvas app grants User or Co-Owner access to the app itself and separately assigns a Dataverse security role, or an app-level role where that feature is turned on; a model-driven app has no separate layer at all, so the security role assigned in Dataverse is the only thing deciding what a user can see.

Underneath the sharing model sits the connection, and a connection belongs to whoever created it, not to the app or the person using it. Some connections are shared implicitly the moment the app is shared; others have to be created and authorised by every individual user, and where that split is misunderstood, one maker’s own login ends up doing the work for everyone the app reaches.

The environment around the app matters just as much: a Dev, Test and Production split only holds if nothing still points at the wrong environment, the tenant’s default environment, where every licensed user is a Maker by default, hasn’t quietly picked up a business-critical app, and the data policy actually blocks or classifies the connectors in use. We review that configuration alongside the app itself, the same way we do for Dynamics 365 environments built on the same Dataverse security model, plus any custom connector or component the app depends on.

SCOPE

What we review in a Power Apps environment

PA-01

Canvas app sharing: User, Co-Owner and app-level roles

Sharing a canvas app grants User access to run it or Co-Owner access to edit and reshare it, and where the app uses Dataverse the share dialog also assigns a security role to each person added, or a role from App reader, App user, App maker or App admin where app-level security is turned on. We test what each tier can actually reach once the app is open, not what the share dialog implies.

PA-02

Model-driven app sharing and Dataverse role assignment

A model-driven app has no security of its own: Dataverse role-based security decides what every user can see, and the person sharing the app needs a security role with privileges equal to or greater than the one they hand out, in practice usually System Administrator or System Customizer. We test whether the roles actually assigned match what the business intended, not what the role’s name suggests.

PA-03

Security roles, access levels and business units

Each security role sets a Create, Read, Write, Delete, Append, Append To, Assign or Share privilege at a User, Business Unit, Business Unit and Child Business Units, or Organisation access level, and every user is assigned to exactly one business unit that anchors how far their own access reaches. We test the effective privilege each role grants in practice, including what a user in a child business unit can reach up or across the hierarchy.

PA-04

Connector identity: who a connection actually runs as

Every action a Power App takes runs through a connection, and a connection belongs to whoever created it: some, such as SQL Server with SQL authentication, are shared implicitly the moment the app is shared, while others, including Dataverse, OneDrive for Business and SQL Server with Microsoft Entra authentication, require every user to create and authorise their own. We map each connection the app depends on and test whether one user’s connection is doing the work for everyone the app is shared with.

PA-05

Environment separation between dev, test and production

An app built in one environment can only connect to the connections, gateways, flows and Dataverse databases deployed in that same environment, so an app in a Test environment cannot reach a Dev database even by accident. We test that this separation actually holds, and that nothing in the app, a connection reference or a custom connector still points at the wrong environment after a move.

PA-06

The default environment and what has landed in it

Every tenant gets one default environment created automatically, and every licensed user is added to its Maker role with no admin action required; Microsoft’s own guidance is that the default environment carries no backup guarantee and is not intended for production workloads. We test what has been built there anyway, and whether a business-critical app or production data has ended up in an environment nobody is administering.

PA-07

Data loss prevention policy scope and connector classification

A data policy, still widely known as a DLP policy, classifies every connector into a Business, Non-Business or Blocked group, and applies either at tenant level, where it can include or exclude specific environments, or directly on one environment. We test what the current policy actually blocks and classifies against what the environment’s apps and flows are still calling, including any connector added after the policy was set.

PA-08

Custom connectors and how they authenticate

A custom connector wraps an external API from an OpenAPI definition, a Postman collection or the connector portal built from scratch, and once registered it is classified and governed the same way as any other connector; an OAuth-secured connection to it can only be explicitly shared with a user representing a service principal, not another person. We test how each custom connector authenticates and what it is classified as, against what it actually exposes.

PA-09

Custom components built with the Power Apps component framework

A code component built with the Power Apps component framework runs inside the app with access to the platform’s own Web API calls, device features such as camera, location and microphone, and full-page rendering. We review what a custom component actually calls and stores, since its code sits outside the maker’s no-code configuration and outside the checks a standard control gets.

PA-10

Delegation limits and client-side filtering

When a canvas app formula can’t be delegated to its data source, Power Apps pulls the first 500 records, or up to 2,000 if the limit is raised, to the device and applies the rest of the filter locally instead of at the source. We test what a non-delegable filter is actually hiding, since a security-relevant condition applied only on the client can still be sitting inside the records the app already downloaded.

OUR PROCESS

Microsoft Power Apps Security Review: From Scope to Attestation

01

App, Role and Environment Mapping

We list every app in scope, the security roles and business units behind it, who it’s shared with, and which environment it runs in.

02

Sharing, Role and Connection Testing

Each app is tested under every relevant security role and sharing tier, and we map and test every connection it depends on, including whose identity each one actually runs under.

03

Environment, DLP and Custom Code Testing

We test environment separation and the default environment, review the data policy against the connectors actually in use, and assess any custom connector or component built on top of the app.

04

Reporting and Retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Power Apps pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Microsoft Power Apps Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£3,920–£5,760
3 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£9,210–£14,030
6 to 8 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Microsoft Power Apps Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need?

Maker or admin access to the app or apps in scope, plus at least one login for each Dataverse security role you want tested. Read access to the environment’s security roles, business units and connection list isn’t required to start, but it speeds up confirming what we find.

Will you touch our live data?

We test read-only against production by default. Where proving a write, update or delete needs real records, we agree a sandbox environment or specific test data with you first, and anything we create during testing is documented and removed afterwards.

Is this hosted on our infrastructure or Microsoft’s?

Power Apps and the Dataverse environment behind it run entirely on Microsoft’s infrastructure, so there’s nothing for you to host. The test is scoped to your apps, security roles, connections, environment configuration and any custom connector or component, not to Microsoft’s platform itself.

Does this cover Power Pages portals or Dynamics 365 too?

No. Power Pages puts a public-facing site on top of Dataverse with its own web roles and table permissions, which we cover on our Power Pages page. Where an app is built on the standard Dynamics 365 apps, the deeper Dataverse security role and business unit review is covered on our Dynamics 365 page; this page is scoped to Power Apps shared internally within your tenant, not portals.

What is out of scope?

Other tenants’ apps and environments, Microsoft’s own infrastructure, denial-of-service testing, and Power Pages web roles or Dynamics 365 first-party apps, which we cover on their own pages, are all out of scope here.

Is penetration testing our own Power Apps environment allowed under Microsoft’s rules?

Yes. Microsoft’s penetration testing rules of engagement for its cloud services permit testing your own tenant and the assets you’re authorised for, provided you don’t access data or systems you don’t own, don’t use credentials that aren’t yours, and don’t disrupt the service for other tenants, and we test inside those rules.

How long does a Power Apps test take?

A single-environment engagement covering a handful of apps and roles typically runs to a 3-day scope. More apps, security roles, connections or custom components extend it, and we confirm the exact day count once we’ve seen the environment.

Do you need the source of any custom connectors or components?

No, though if the environment uses custom connectors or code components built with the Power Apps component framework, having the connector definition or component source available speeds up root-causing anything we find. A source code review is a separate service that pairs well with this one.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Power Apps environment

A Power App puts a slice of Dataverse, or whatever data source it connects to, in front of a defined group of internal users, and what each of them can actually do comes down to three separate decisions: how the app was shared, which security role came with that share, and which connection its calls run under. Get any one of those wrong and a user without the role you meant to give them still sees the same screen, or a connection created under someone else’s login does the fetching for everyone the app reaches. We test the app under every role it’s shared with, review each connection and environment behind it, and check the platform governance, DLP policy, custom connectors and any custom component built on top. CREST-certified testers, fixed price from £3,920 for a 3-day single-environment scope, quoted within 24 hours.