Post

Secure Dataverse secrets with Azure Key Vault

Diesen Beitrag auf Deutsch lesen

Move API keys from text environment variables to Azure Key Vault and retrieve them securely in Power Automate.

TL;DR

Store sensitive Dataverse environment variable values in Azure Key Vault rather than Text variables. Create a Secret variable with Azure Key Vault as its secret store, set an environment-specific current value reference, then use the Dataverse RetrieveEnvironmentVariableSecretValue action in a cloud flow with Secure Outputs enabled.

Original by Jonas Rapp, on JonasR.app. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Makers: Use Secret environment variables and RetrieveEnvironmentVariableSecretValue instead of placing API keys in flows or Text variables.
  • Admins/CoE: Configure the Dataverse identity as Key Vault Secrets User and register Microsoft.PowerPlatform for the subscription.
  • Security/Compliance: Avoid default references across environments and enable Secure Outputs so retrieved secrets are hidden in run history.

Frequently asked questions

Where should sensitive Dataverse environment variable values be stored?

Sensitive values such as API keys belong in Azure Key Vault through a Secret variable, not in Text variables or directly in flows.

How does a cloud flow read the secret?

With the Dataverse action RetrieveEnvironmentVariableSecretValue and Secure Outputs enabled, so the retrieved secret stays hidden in run history.

What do admins have to set up?

Give the Dataverse identity the Key Vault Secrets User role and register Microsoft.PowerPlatform for the subscription. Avoid default references across environments.

This post is licensed under CC BY 4.0 by the author.