Microsoft Power Platform Security Checklist (CISA SCuBA)
19 items · Security · Medium difficulty · 3 hours
Secure your Microsoft Power Platform with CISA-backed configuration steps.
-
Review the CISA SCuBA and Microsoft Power Platform guidance
Download and read the SCuBA baseline and Microsoft guidance before changes.
-
Inventory Power Platform tenants, environments, apps, connectors, and owners
Create a single list of environments, apps, connectors, and administrators.
-
Assign and review admin and service account roles; remove unnecessary privileges
Use role-based access, remove orphaned or legacy admin accounts.
-
Configure access controls
Set tenant and environment access policies to limit exposure.
-
Enable multi-factor authentication for all admins and privileged accounts
Require MFA for admin and service accounts to block credential misuse.
-
Enforce least privilege for service and user accounts
Grant only the roles and permissions required for tasks.
-
Implement Conditional Access policies for Power Platform
Block legacy auth and require compliant devices or location rules.
-
Disable or tightly control site and app creation in the tenant
Limit who can create sites/apps to reduce shadow IT (see MS guidance).
-
Configure Data Loss Prevention (DLP) policies across environments
Define policies to prevent sensitive data exfiltration via connectors.
-
Restrict and block unapproved connectors and external data connections
Whitelist approved connectors and block risky or legacy connectors.
-
Enable unified audit logging and monitoring for Power Platform
Ensure audit logs are captured and retained per policy.
-
Integrate audit logs with your SIEM and create actionable alerts
Forward logs to SIEM and configure alerts for suspicious activity.
-
Regularly review and apply Microsoft, CISA updates and CVE guidance
Subscribe to advisories and review CVEs affecting Power Platform.
-
Implement backup and recovery for Power Platform apps and data
Define backup schedules and test restores for apps and Dataverse data.
-
Conduct regular security assessments, configuration reviews, and penetration tests
Include environment-hardening and API/connector testing in reviews.
-
Train creators and end users on secure app development and phishing risks
Provide guidance on secure low-code practices and safe sharing.
-
Document and maintain incident response procedures specific to Power Platform
Include detection, containment, communication, and recovery steps.
-
Subscribe to Microsoft and CISA advisories and confirm support contacts
Add vendor and CISA contacts for timely advisories and incident help.
-
Review and restrict external sharing and guest access settings
Limit guest users, external sharing, and enforce tenant controls.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.