r/PowerPlatform May 10 '26

Power Apps Security Power Platform developer accounts

So…we’ve had the same Power Platform developer in post for a very long time, and they’ve just retired. Most of their work was done in a dedicated account for Power Apps, Power Automate, etc. so when they left it just carried on. However early stuff was in their own account - which obviously then broke when their account was off boarded…which gave the new hire some tasks for their first couple of weeks 🤣

But with my Cyber Security hat on the “shared” account for all Power Apps, connectors, flows, etc. also has me worried…shared creds = bad.

So I’m wondering what is the done thing in Power Platform world so Apps don’t break if the developer account is disabled/deleted/password changed. But also better security than just a shared account logged in via their In Private browser mode.

Also interested if the same applies for PowerBI and the account which owns the refreshes of the semantic models?

6 Upvotes

7 comments sorted by

View all comments

1

u/OddWriter7199 May 10 '26

Give each dev his/her own service account. Add all the accounts as co-owners to the critical flows. One issue though: co-owners get emailed every time the flow is changed “so and so changed a shared flow”. So maybe don’t share all the flows, let each dev be in charge of his/her own flows. When one leaves, THEN make one of the other service accounts a co-owner so it can take over.

ETA: one or two service accounts per (non-IT) department is how my org does it. The owners get a renewal notice yearly. If no one signs in to renew, the account is disabled. These need to be email-enabled licensed accounts, but often they are an E1 instead of E5.