Microsoft Power Platform · Tenant Administration
Power Apps Administrator
Tenant-wide administration of Power Apps. Lower-privilege alternative to Power Platform Administrator for organisations only using Power Apps. Cross-listed from Microsoft Entra ID.
Scope: Tenant-wide Power Apps administration
Permissions
- Environments - Manage Power Apps environments
- Apps - View and govern apps across the tenant
- Flows - View and govern Power Automate flows
- Admin center - Access Power Platform admin center for Power Apps scope
Common use cases
- Power Apps-only organisations
- Delegated admin for the Power Apps footprint when D365 is admin-managed separately
Best practices
- Use only when the org is Power-Apps-only and does NOT use Dynamics 365 or broader Power Platform features
- For most orgs, prefer Power Platform Administrator — narrower roles fragment governance
- Pair with the Power Platform CoE Kit for visibility
Security considerations
- Can view all apps and flows tenant-wide
- Does NOT govern DLP policies tenant-wide — use Power Platform Administrator for tenant DLP
- Cannot manage Dataverse capacity or AI Builder credits
Common questions
When should I assign the Power Apps Administrator role?
Assign Power Apps Administrator when you need to: Power Apps-only organisations; and Delegated admin for the Power Apps footprint when D365 is admin-managed separately. It is part of Microsoft Power Platform and should be granted as a least-privilege alternative to broader roles like Global Administrator.
What can someone with the Power Apps Administrator role do?
The Power Apps Administrator role grants permissions including: Environments - Manage Power Apps environments; Apps - View and govern apps across the tenant; Flows - View and govern Power Automate flows; and Admin center - Access Power Platform admin center for Power Apps scope. See the Permissions section above for the full list.
What are the security risks of the Power Apps Administrator role?
Key considerations when assigning Power Apps Administrator: Can view all apps and flows tenant-wide; Does NOT govern DLP policies tenant-wide — use Power Platform Administrator for tenant DLP; and Cannot manage Dataverse capacity or AI Builder credits. Review the Security considerations section before assignment, and pair with Privileged Identity Management (PIM) for just-in-time access where possible.