Microsoft Power Platform · Environment Roles

Environment Admin

Full administration of a single Power Platform environment. Manage members, environment settings, Dataverse provisioning, backups, and capacity allocation.

Scope: Single Power Platform environment

Permissions

  • Members - Add or remove environment members and assign security roles
  • Settings - Configure environment-level settings (region, type, security)
  • Dataverse - Add or remove a Dataverse database to the environment
  • Backups - Create on-demand backups and restore points
  • Capacity - Allocate capacity to the environment
  • Apps & flows - View and manage all apps and flows in the environment
  • Connections - Manage connection references and shared connections

Common use cases

  • Business unit IT lead managing their team's environment
  • Solution architect during a Power Apps project
  • Delegated environment ownership in a federated governance model

Best practices

  • Use security groups for environment membership
  • Document environment purpose, owner, and lifecycle in CoE inventory
  • Schedule periodic backups before major changes
  • Pair with Environment Maker for citizen developer enablement

Security considerations

  • Can grant Environment Admin to others, expanding the privileged set
  • Can view all apps and flows in the environment
  • On Dataverse-enabled environments, has System Administrator security role

Common questions

When should I assign the Environment Admin role?

Assign Environment Admin when you need to: Business unit IT lead managing their team's environment; Solution architect during a Power Apps project; and Delegated environment ownership in a federated governance model. It is part of Microsoft Power Platform and should be granted as a least-privilege alternative to broader roles like Global Administrator.

What can someone with the Environment Admin role do?

The Environment Admin role grants permissions including: Members - Add or remove environment members and assign security roles; Settings - Configure environment-level settings (region, type, security); Dataverse - Add or remove a Dataverse database to the environment; Backups - Create on-demand backups and restore points; Capacity - Allocate capacity to the environment; and Apps & flows - View and manage all apps and flows in the environment. See the Permissions section above for the full list.

What are the security risks of the Environment Admin role?

Key considerations when assigning Environment Admin: Can grant Environment Admin to others, expanding the privileged set; Can view all apps and flows in the environment; and On Dataverse-enabled environments, has System Administrator security role. Review the Security considerations section before assignment, and pair with Privileged Identity Management (PIM) for just-in-time access where possible.

Official Microsoft Learn documentation →

Open the interactive RBACMap →