Dataverse - Assign non-Power Platform licensed Entra users to Dataverse Activities

🚨 The Signal: Dataverse will allow non-Power Platform licensed Entra users to be assigned to Dataverse activities. This creates 'stub users' at runtime, expanding the attack surface by introducing unmanaged identities into Dataverse.

The Impact

Security teams and identity administrators are affected by new unmanaged identities, increasing the risk of unauthorized access and data exposure.

  • Security teams: Increased attack surface from unmanaged identities.
  • Identity administrators: New stub users require monitoring and governance.
  • Compliance officers: Potential non-compliance with identity management policies.
  • Data owners: Risk of unauthorized access to Dataverse activities and data.

The Action

  1. Review Dataverse security roles and permissions for all users, including new stub users.
  2. Implement a process to identify and govern stub users created in Dataverse.
  3. Monitor Dataverse activity logs for unusual behavior from non-licensed users.
  4. Update identity and access management policies to account for Dataverse stub users.
  5. Assess existing Dataverse data classification and access controls for alignment with new user types.

Domain: Entra · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898