Power Automate: Build and visualize desktop flows using Flowchart mode

🚨 The Signal: Power Automate desktop flows now offer a visual flowchart mode for authoring. This simplifies complex automation creation and maintenance, potentially increasing adoption and the attack surface for malicious flows.

The Impact

Power Automate users gain a new authoring method, increasing the risk of unmanaged or malicious automations if not properly governed.

  • Security teams face increased risk from complex, unmonitored automations.
  • Admins must ensure governance policies are applied to all Power Automate flows.
  • End-users might create more complex flows, increasing potential for privilege misuse.
  • Organisations risk data exfiltration or system compromise from rogue automations.

The Action

  1. Review existing Power Automate DLP policies to ensure they cover desktop flows.
  2. Implement or refine Power Automate tenant-level isolation policies via the Power Platform admin center.
  3. Audit Power Automate desktop flow permissions and connections regularly.
  4. Educate users on secure automation practices and the risks of over-privileged flows.
  5. Monitor Power Automate audit logs for unusual or high-risk flow executions.

Domain: Other · Impact: medium · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898