Power Platform Governance Roadmap
All epics
S2P2DraftPlatform Run the Business
Tenant Configuration & Security Baseline
Bring tenant settings in line with recommended practice and lift the platform security score materially above its current 37%.
Tenant-level settings, isolation, auditing and the Microsoft security posture recommendations.
SupportVamsi NamuduriDogaru EduardOvidiu Kislaposi
Lead
Marius Oprea
Owner
—
Deliverables
7
Effort
7
sprints
Delivered
0/7
Deliverables
| Ref | Title | Phase | Priority | Owner | Sprints | Status | |
|---|---|---|---|---|---|---|---|
| S2.1 | Enable tenant isolation with tenant rules Turn on tenant isolation in the Power Platform Admin Center and implement approved deviations through tenant rules. Currently not set up, creating data loss risk between untrusted tenants. | Phase 1 | P1 | Vamsi Namuduri | 1 | Draft | |
| S2.2 | Restrict Copilot Studio authors to a trained group Point the Copilot Studio Authors setting at an Entra group of people who have been trained, rather than leaving authoring open across the tenant. | Phase 1 | P1 | Marius Oprea | 0.5 | Draft | |
| S2.3 | Restrict portal and non-admin environment creation Apply the recommended restrictions on portal creation and trial or developer environment creation by non-admin users, in line with the chosen zone model. | Phase 1 | P2 | Vamsi Namuduri | 0.5 | Draft | |
| S2.4 | Enable tenant capacity report for environment admins Change the tenant capacity summary view so environment admins can see and act on their own capacity consumption. | Phase 2 | P3 | Dogaru Eduard | 0.5 | Draft | |
| S2.5 | Restrict support request visibility Turn off support request visibility for all users so support tickets are not exposed tenant-wide. | Phase 1 | P3 | Vamsi Namuduri | 0.5 | Draft | |
| S2.6 | Enable auditing and define log retention Turn on auditing across environments and set retention. Microsoft flags 190 environments without auditing, and audit logging is currently prohibited but inconsistently applied. | Phase 2 | P2 | Dogaru Eduard | 2 | Draft | |
| S2.7 | Security score improvement plan A tracked plan to raise the security score from 37%, sequencing the high-impact items: client application access control, IP firewall and cookie binding, security groups on environments, guest access restriction and admin reduction. | Phase 2 | P2 | Marius Oprea | 2 | Draft |
By phase
- Phase 14 · 2.5 spr
- Phase 23 · 4.5 spr
- Phase 30 · 0 spr
By priority
- P12 items
- P23 items
- P32 items