Power Automate: Schedule desktop flows directly with Scheduled Triggers

🚨 The Signal: Power Automate desktop flows can now be scheduled directly, bypassing cloud flows. This simplifies automation but increases the attack surface for unmanaged desktop environments and potentially unapproved automation.

The Impact

Admins and security teams are affected by increased risk from unmanaged desktop automation and potential privilege escalation.

  • Security Teams: Increased risk from unmonitored or malicious desktop automations.
  • Admins: New vector for unapproved automation and potential privilege misuse.
  • Compliance Officers: Challenges in demonstrating control over automated processes.
  • End Users: Simplified automation, but potential for misconfiguration or abuse.

The Action

  1. Review existing Power Automate Data Loss Prevention (DLP) policies for desktop flows.
  2. Implement or refine policies to restrict desktop flow connections and actions.
  3. Monitor Power Automate activity logs for scheduled desktop flow creations and executions.
  4. Educate users on responsible automation practices and policy adherence.
  5. Assess the need for dedicated service accounts with least privilege for unattended desktop flows.

Domain: Other · Impact: high · Workload: Other · Essential Eight: Application Control, Restrict Administrative Privileges · ISM: ISM-0445, ISM-0843, ISM-1175, ISM-1380, ISM-1490, ISM-1507, ISM-1508, ISM-1509, ISM-1544, ISM-1582, ISM-1647, ISM-1648, ISM-1650, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1686, ISM-1688, ISM-1689, ISM-1870, ISM-1871, ISM-1883, ISM-1897, ISM-1898