Power Pages- Information regarding the end of support for Wildcard (*) in the Web API field configuration
🚨 The Signal: Power Pages will end support for wildcard (*) in Web API field configurations by September 2026. This change mandates explicit column listing for Dataverse tables, enhancing security by enforcing least-privilege access and preventing unintended data exposure.
The Impact
Power Pages administrators are affected, facing a risk of service disruption and potential data exposure if configurations are not updated.
- Power Pages administrators: Risk of service disruption if Web API configurations are not updated.
- Security teams: Reduced data exposure risk through enforced least-privilege access.
- Dataverse owners: Enhanced control over data exposed via Power Pages Web API.
- Users of Power Pages: Potential service interruption if underlying APIs fail due to misconfiguration.
The Action
- Identify all Power Pages websites using wildcard (*) in Webapi//fields site settings.
- Review the Dataverse tables and columns currently exposed via the Power Pages Web API.
- Replace the wildcard (*) with an explicit, comma-separated list of required columns in the Webapi//fields site setting.
- Thoroughly validate website functionality after updating the Web API configuration.
- Contact Microsoft support if assistance is required for complex configurations.
Domain: Other · Impact: high · Workload: Other