Security Best Practices in Dataverse
The seven practices below help you secure Dataverse environments, manage permissions cleanly with Azure Active Directory groups, and keep privileged access tightly scoped.
Solutions
Separate environments enable bug resolution and testing of new features before deployment to end users. Resource administration is also easier as all resources are bound to the location of the Dataverse environment. You can create environments by geography, although you must consider GDPR — the database is provisioned in the region specified during creation.
By default, no security group is selected, which means any user in the tenant can access the environment. To restrict access and strengthen security, select a security group.
Security roles can be associated with an Azure Active Directory group. To simplify permissions and data access, create AAD groups and associate roles with them.
Instead of creating a new security role from scratch, copy an existing role and update the privileges and access levels for the new role's requirements.
Grant only the minimum privileges required to any security role. Provide access to the minimum business data required for the task. Assign users the appropriate role for their job with minimum required access, and create a basic user role with the least permissions that all users must have.
Strictly limit the number of people assigned the System Administrator role. Don't grant system admin or similar high-privilege roles to too many users or service accounts, especially on production.
If many users require the same access, create a team and assign the required security role to the team rather than assigning it to each member. Use teams to create cross-functional groups so specific objects can be shared with the team.
References
- 7 best practices you need to secure Dataverse — MAQ Software
- Copy a security role — Power Platform — Microsoft, last updated February 15, 2022
- Create and manage environments in Dataverse — Microsoft, 2022
Need a Dataverse security review or role redesign? MAQ Software's Power Platform team can help.
Talk to our team
Azure Security Best Practices
Strengthen your cloud security and protect your assets with 19 security best practices.
Read More