Microsoft Copilot security directory

Power Platform for Admins V2

Published by Microsoft

High risk

Unified connector for all administrative capabilities in Microsoft Power Platform

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Can spend money on your behalf: This connector can initiate charges, orders, or subscriptions. An AI executing these actions could trigger unauthorized financial transactions.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 156 tools or capabilities.

  • Add allowed IP addresses on a Power Pages website
  • Add the environment to the environment group
  • Allocate and deallocate the currencies for the environment
  • Apply the system administrator role to the selected user
  • Convert a trial Power Pages website to production
  • Copy the environment from the specified source to the target (Preview)
  • Create a Power Pages website
  • Create an ISV contract
  • Create environment group role assignment
  • Create environment group rule based assignment
  • Create environment management settings
  • Create environment role assignment
  • Create environment rule based assignment
  • Create role assignment
  • Create rule based policy
  • Create Rule Set
  • Create the environment group
  • Create web application Firewall rules on a Power Pages website
  • Creates a backup of the specified environment (Preview)
  • Creates the billing policy at tenant level
  • Delete a bot in Copilot Studio
  • Delete a connection for DSR compliance
  • Delete a flow for DSR compliance
  • Delete a Power Pages website

The interactive security report will load automatically.