Post

Secure Power Pages by checking permissions and Web API gates

Diesen Beitrag auf Deutsch lesen

Review anonymous table permissions, Web API settings and custom web roles to prevent accidental Dataverse exposure through Power Pages.

TL;DR

Power Pages data access depends on web roles and table permissions, while the Web API also requires enabled table settings and an explicit fields list. A Global Read permission for Anonymous Users combined with Webapi/contact/enabled set to true and Webapi/contact/fields set to * can expose contact records without sign-in.

Original by Nick Doelman, on The ReadyXRM Blog. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Admins/CoE: Review every table permission assigned to Anonymous Users, every Global access grant, and each Web API enabled table; remove unjustified public access because permissions combine and the broadest grant wins.
  • Security/Compliance: Replace Web API fields wildcards with explicit columns, disable unused tables, and treat every listed column as published data; this limits accidental exposure of personal or commercially sensitive information.
  • Makers: Keep Authenticated Users Role set to No on custom web roles and use assigned contact membership; setting Yes grants the role to every signed-in user.
This post is licensed under CC BY 4.0 by the author.