Blog
All Posts
-
Power Platform Security Assessment: How Mature Is Your Tenant?
Read more →: Power Platform Security Assessment: How Mature Is Your Tenant?You have configured governance — but does it actually work? In the final blog of this series, we introduce a PowerShell script that automatically checks 10 security domains in your Power Platform tenant, built with GitHub Copilot. The result: an interactive HTML report, a maturity score, a concrete improvement plan, and guidance on what to…
-
Power Platform Technical Configuration: Silos, Policies, and Managed Environments
Read more →: Power Platform Technical Configuration: Silos, Policies, and Managed EnvironmentsGovernance on paper solves nothing. In this third blog of the series, we move from model to configuration: environment strategy in practice, enabling Managed Environments, layered DLP policies, service principals, Conditional Access, AI governance for Copilot Studio agents, and ALM as a security control.
-
Power Platform Governance: Environments as Trust Boundaries
Read more →: Power Platform Governance: Environments as Trust BoundariesMost organizations deploy Power Platform without a coherent governance model. In this second blog of the series, we dive into the governance framework: environments as trust boundaries, maker rights via Entra ID, DLP as a second line of defense, Microsoft Purview for data classification, and the deliberate approach to the Default environment.
-
Power Platform & Zero Trust: Why Default Settings Are a Security Risk
Read more →: Power Platform & Zero Trust: Why Default Settings Are a Security RiskMost organizations deploy Power Platform without thinking explicitly about security. The default settings are designed for adoption — not for a Zero Trust posture. In this first blog of a four-part series, we break down why Power Platform must be treated as an enterprise workload, how the three Zero Trust principles translate directly to the…
-
Hotpatching is the New Default: What Does This Mean for Your Update Strategy?
Read more →: Hotpatching is the New Default: What Does This Mean for Your Update Strategy?Starting May 2026, Microsoft is making hotpatch updates the norm for Windows, meaning security updates won’t need a reboot. This shift boosts compliance and efficiency for organizations. Admins will get new management controls to tailor this change while Windows Autopatch becomes key for smarter update management. Time to rethink your strategy!
-
RBAC for Applications – Least Privilege When Sending Email via the Graph API
Read more →: RBAC for Applications – Least Privilege When Sending Email via the Graph APIA while ago I received a question from a Power Platform team. They were building a Power App and wanted to add email functionality to it. To send emails from the app, they wanted to call the Microsoft Graph API. For this purpose, they had created an App Registration in Entra ID. The question was…
-
Conditional Access Policy Creation Improvements
Read more →: Conditional Access Policy Creation ImprovementsMicrosoft is constantly improving and developing existing services. This can be seen within Conditional Access, a few months ago the feature was introduced which made it possible to create a new policy based on a template. The templates that were available have recently been expanded considerably. The available templates are divided into several themes. For…






