Microsoft Copilot security directory

Power Automate Management

Published by Microsoft

High risk

Power Automate Management connector enables interaction with Power Automate Management service. For example: creating, editing, and updating flows. Administrators who want to perform operations with admin privileges should call actions with the 'as Admin' suffix. Service Principal authentication is supported for administrative actions only.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.

Available capabilities

This add-on exposes 23 tools or capabilities.

  • Cancel Flow Run
  • Create Connection
  • Create Flow
  • Delete Flow
  • Get Connector
  • Get Flow
  • Get Flow as Admin
  • List Callback URL
  • List Connectors
  • List Flow Owners
  • List Flow Run-Only Users
  • List Flows as Admin (V2)
  • List My Connections
  • List My Environments
  • List My Flows
  • Modify Flow Owners
  • Modify Flow Owners as Admin
  • Modify Run-Only Users
  • Restore Deleted Flow as Admin
  • Resubmit Flow
  • Turn Off Flow
  • Turn On Flow
  • Update Flow

The interactive security report will load automatically.