Power Platform Governance Without Killing Innovation: Security, DLP, Environments & Citizen Development with Michael Roth [MVP]
Key Takeaways
- Michael Roth emphasizes that Power Platform is not a hobby tool; it is an enterprise application platform embedded across the Microsoft cloud that requires configuration, security, and operational ownership.
- A successful governance strategy must act as guardrails for citizen developers, giving them clarity and confidence to build faster and safer without killing organizational innovation.
- Starting any Power Platform governance initiative requires a comprehensive inventory of the tenant to uncover existing apps, flows, abandoned experiments, and unmanaged environments.
- Data Loss Prevention (DLP) policies primarily control which connectors can be used together within a solution and must be thoughtfully designed alongside an organization's environment strategy.
- Effective governance goes beyond documentation; it requires an ongoing operating model that continuously monitors assets, defines clear roles, and separates personal productivity tools from business-critical solutions.
Power Platform makes it possible for people across an organization to solve problems, automate processes, and build business applications faster than traditional development approaches. But that accessibility also creates difficult enterprise questions: Who can build what? Where does company data go? How should environments be structured? And how can organizations prevent shadow IT without becoming the department that says no to every new idea?
In this episode of M365 FM, Mirko Peters talks with Michael Roth [MVP] about building Power Platform governance that protects the organization without killing innovation. They explore security, Data Loss Prevention policies, environment architecture, inventory, application lifecycle management, citizen development, and the responsibilities organizations take on when Power Platform becomes part of their business infrastructure.
ㅤ
FROM ORGANIZATIONAL CONSULTING TO POWER PLATFORM GOVERNANCE
Michael shares his unconventional journey from organizational development and change management into the Microsoft ecosystem. After working on information-classification projects and experiencing the limitations of managing enterprise information through enormous Excel files, he became increasingly interested in the technical side of digital transformation.
His work with Microsoft 365, SharePoint, Power Automate, and Power Apps eventually brought together two complementary perspectives: technical platform knowledge and an understanding of people, communication, organizational change, and adoption. Today, Michael uses this combination to help organizations establish sustainable governance, administration, and security models for Power Platform.
ㅤ
POWER PLATFORM IS NOT A HOBBY TOOL
Power Platform is frequently presented as a collection of approachable low-code services, including Power Apps, Power Automate, Power Pages, Dataverse, and Copilot Studio. Michael explains why organizations must also understand the platform underneath those individual services.
For users, these products can feel like simple software-as-a-service applications. For administrators and platform owners, however, Power Platform is an enterprise application platform embedded across the Microsoft cloud. It requires configuration, security, maintenance, ownership, monitoring, and operational processes.
The fact that someone can create an application quickly does not mean that the resulting solution is automatically secure, maintainable, scalable, or ready for production.
ㅤ
WHEN SMALL AUTOMATIONS BECOME BUSINESS-CRITICAL
A Power Automate flow or Power Apps application may begin as a harmless personal productivity project. Once colleagues start depending on it, sharing it, modifying it, or using it to access enterprise systems, its risk profile changes dramatically.
Michael discusses examples in which apparently simple solutions expanded far beyond their original purpose. A personal integration with an enterprise database can eventually give dozens of users automated read or write access. Even a harmless seasonal application can create governance problems when hundreds of employees are added and its user list is never maintained.
Business criticality is therefore not determined only by what an application does. It is also influenced by the number of users, the sensitivity of the connected data, external dependencies, business reliance, ownership, and the consequences of failure.
ㅤ
CITIZEN DEVELOPMENT NEEDS CLARITY AND INTENTION
Citizen development does not have to mean uncontrolled development. A strong governance model gives makers clear boundaries, suitable environments, understandable responsibilities, and a reliable path for turning useful ideas into supported business solutions.
Governance should help employees understand where they can experiment, which connectors they may use, when a solution requires professional support, and what happens when an application becomes important to the organization.
The objective is not to block makers. It is to help them build with greater confidence while ensuring that security, compliance, ownership, supportability, and business continuity are considered from the beginning.
ㅤ
START GOVERNANCE WITH AN INVENTORY
Organizations cannot govern assets they cannot see. Michael explains why an inventory should be one of the first steps in any Power Platform governance initiative.
A tenant may already contain hundreds of applications and flows, numerous environments, unmanaged custom connectors, abandoned experiments, and solutions without active owners. Opening the Power Platform Admin Center and inspecting the real tenant estate is like switching on the light in a dark room: only after seeing what exists can administrators make sensible decisions.
The conversation examines the native inventory capabilities available in the Power Platform Admin Center, the changing role of the Center of Excellence Starter Kit, the Copilot Studio Kit, and the option of creating a customized inventory with Power Platform APIs. For many organizations, a purpose-built inventory can provide better alignment with their licenses, services, risks, and governance requirements.
ㅤ
DESIGNING AN ENVIRONMENT STRATEGY
The default environment should not become the permanent home for every experiment, automation, shared application, and business-critical solution. Michael outlines an environment architecture that separates different purposes and risk levels.
This can include strongly restricting the default environment, creating dedicated environments for IT-managed assets, providing shared maker environments for citizen development, using personal developer environments for experimentation, and establishing development, test, and production environments for important solutions.
A clear environment strategy makes it easier to apply security policies, assign responsibilities, monitor assets, manage costs, and introduce lifecycle processes appropriate to each category of solution.
ㅤ
APPLICATION LIFECYCLE MANAGEMENT FOR POWER PLATFORM
Not every personal automation requires a sophisticated deployment pipeline. Business-critical solutions, however, need controlled development, testing, deployment, versioning, and recovery processes.
Michael discusses Power Platform Pipelines, GitHub integration, Azure DevOps, the Power Platform SDK, and the growing complexity of application lifecycle management as solutions become larger. When multiple developers work on different components, custom plug-ins are involved, or several solutions must be combined, organizations need more mature engineering practices.
This illustrates how far Power Platform has evolved. It remains accessible to citizen developers, but it can also support complex enterprise solutions that require professional software-development disciplines.
ㅤ
WHAT POWER PLATFORM DLP REALLY DOES
Data Loss Prevention is one of the most important—and most misunderstood—elements of Power Platform security. Power Platform DLP policies do not behave exactly like every other Microsoft security feature carrying the DLP name.
Michael explains that these policies primarily control which connectors can be used together within a solution and which connectors should be blocked. Organizations can use them to prevent business data from being combined with unsuitable external or consumer services.
Because DLP policies operate in the context of environments, they should be designed together with the environment strategy. Managed Environments and advanced connector policies can provide additional granularity, but enabling a policy once does not constitute a complete governance program.
ㅤ
THE FOUR FOUNDATIONS OF POWER PLATFORM SECURITY
Michael identifies four essential foundations that organizations should understand: tenant security settings, environment architecture, Data Loss Prevention policies, and clearly defined roles and responsibilities.
A fifth principle connects them all: default settings should never be accepted without review. Microsoft understandably wants its products to be easy to discover and use, but broad default access may not match an organization’s security, compliance, or operational requirements.
This is particularly important for organizations using Dynamics 365. They may focus on the Dynamics application without realizing that a wider Power Platform foundation exists underneath it and may already be available to users.
ㅤ
GOVERNANCE IS AN OPERATING MODEL, NOT A DOCUMENT
A governance document alone will not secure a tenant or support makers. Effective governance needs continuous inventory, ownership, environment management, lifecycle processes, monitoring, communication, training, and periodic review.
Organizations also need to distinguish between personal productivity solutions, shared departmental tools, and critical enterprise applications. Each category requires a different level of control. Applying the same process to everything either creates unnecessary bureaucracy or leaves important solutions dangerously unmanaged.
Michael’s approach focuses on helping organizations become experts in their own working environment. Governance should be tailored to the organization’s actual technologies, capabilities, risks, licenses, and business needs.
ㅤ
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
Frequently Asked Questions
What is Power Platform governance?
Power Platform governance is a framework of security controls, Data Loss Prevention policies, environment architectures, and administrative processes that help organizations manage citizen development, protect business data, and prevent shadow IT without stifling innovation.
Why is Power Platform considered an enterprise tool rather than a hobby tool?
Although the platform offers approachable low-code services, it operates as an enterprise application platform connected to core organizational infrastructure, requiring professional administration, security maintenance, and lifecycle management.
What do Power Platform Data Loss Prevention (DLP) policies actually do?
Power Platform DLP policies control which connectors can be used together within a solution and block unauthorized connections, preventing sensitive business data from being mixed with unsafe external or consumer services.
How should organizations start their Power Platform governance journey?
Organizations should begin with a comprehensive inventory of their tenant estate using native admin centers, the Center of Excellence Starter Kit, or custom APIs to discover all existing apps, flows, and abandoned experiments.
1
00:00:00,000 --> 00:00:04,420
Welcome back everybody to the M665s and podcasts.
2
00:00:04,420 --> 00:00:06,940
Today we are talking about one of the most important
3
00:00:06,940 --> 00:00:10,860
and often misunderstood parts of Power Platform governance.
4
00:00:10,860 --> 00:00:13,620
Power Apps, Power Automate, PowerPages,
5
00:00:13,620 --> 00:00:15,220
Co-Pilot Studio, DataWerrors,
6
00:00:15,220 --> 00:00:19,260
and the wider Power Platform gives people,
7
00:00:19,260 --> 00:00:23,620
yeah, gives people across the business,
8
00:00:23,620 --> 00:00:27,740
the ability to solve problems really quick.
9
00:00:27,740 --> 00:00:30,580
The accessibility is the magic,
10
00:00:30,580 --> 00:00:33,380
but it also creates real enterprise questions.
11
00:00:33,380 --> 00:00:34,680
Who can build what?
12
00:00:34,680 --> 00:00:36,500
Where do business data go?
13
00:00:36,500 --> 00:00:39,300
How do we keep environments secure?
14
00:00:39,300 --> 00:00:42,660
How do we prevent shadow IT without becoming the team,
15
00:00:42,660 --> 00:00:44,500
say, no to everything?
16
00:00:44,500 --> 00:00:51,100
My guest today is Michael Rod. Michael has been working as a consulate since 2011,
17
00:00:51,100 --> 00:00:56,980
and has been a part of the IT and Microsoft ecosystem since around 2015.
18
00:00:56,980 --> 00:00:59,500
His experience spends from Microsoft 365,
19
00:00:59,500 --> 00:01:03,340
collaboration technologies and organizational consulting,
20
00:01:03,340 --> 00:01:08,740
give him a broad view of what it really takes to make digital solutions sustainable.
21
00:01:08,740 --> 00:01:11,420
Today, Michael focused on Power Platform governance,
22
00:01:11,420 --> 00:01:14,700
administration security and organization enablement.
23
00:01:14,700 --> 00:01:15,700
He has organization,
24
00:01:15,700 --> 00:01:18,660
practical governance frameworks from DLP strategies,
25
00:01:18,660 --> 00:01:21,980
and environment architecture to custom and
26
00:01:21,980 --> 00:01:24,220
mentoring, lifecycle management,
27
00:01:24,220 --> 00:01:27,460
and adoption tuning built directly from the platform.
28
00:01:27,460 --> 00:01:35,340
This perspective is simple, but Power Platform is not a hobby tool.
29
00:01:35,340 --> 00:01:38,140
It's an enterprise software that happens to be accessible.
30
00:01:38,140 --> 00:01:43,620
The goal is not to slow make us down,
31
00:01:43,620 --> 00:01:45,140
but it gives the clarity,
32
00:01:45,140 --> 00:01:47,620
confidence and God-wraiths to build faster,
33
00:01:47,620 --> 00:01:51,140
saver and gives more business value.
34
00:01:51,140 --> 00:01:54,860
Michael, why come to the MC65 with M podcast?
35
00:01:54,860 --> 00:01:56,580
It's great to have you here.
36
00:01:56,580 --> 00:01:59,820
Thank you very much for the invitation. It's great to be here.
37
00:01:59,820 --> 00:02:02,700
Just a small clarification right at the beginning,
38
00:02:02,700 --> 00:02:05,020
the goal to give the maker clarification is
39
00:02:05,020 --> 00:02:08,220
the goal of my governance approach and not the goal of the Power Platform.
40
00:02:08,220 --> 00:02:11,860
But I think that's pretty clear to everyone who's listening.
41
00:02:11,860 --> 00:02:15,100
Sorry, it's for both in Germany.
42
00:02:15,100 --> 00:02:17,100
I wasn't Germany. It's really odd today.
43
00:02:17,100 --> 00:02:21,460
I think it's a little bit of a put on the break, but thank you.
44
00:02:21,460 --> 00:02:25,940
Michael, before we go deep into governance,
45
00:02:25,940 --> 00:02:29,900
security, administration, tell us a little bit about your journey.
46
00:02:29,900 --> 00:02:33,020
You started in consulting 2011,
47
00:02:33,020 --> 00:02:35,580
then moved more deeply into it.
48
00:02:35,580 --> 00:02:38,900
Yeah, the Microsoft ecosystem around 2015,
49
00:02:38,900 --> 00:02:43,140
what drew you into this world?
50
00:02:43,140 --> 00:02:47,300
Pure accident and a little bit of laziness, I would say.
51
00:02:47,300 --> 00:02:52,300
In 2011, when I started my journey into consulting,
52
00:02:52,300 --> 00:02:54,140
it wasn't necessarily IT consulting,
53
00:02:54,140 --> 00:02:57,380
but it was more organizational development,
54
00:02:57,380 --> 00:03:02,740
where I worked with mostly managers
55
00:03:02,740 --> 00:03:06,900
in all kinds of ranks towards how to create a team,
56
00:03:06,900 --> 00:03:10,260
how communication works, how change management actually works,
57
00:03:10,260 --> 00:03:11,780
what is necessary into that.
58
00:03:11,780 --> 00:03:14,340
So that was more or less my origin.
59
00:03:14,340 --> 00:03:19,740
And during this time, I stumbled upon a project
60
00:03:19,740 --> 00:03:22,340
that was closely reloaded later to IT,
61
00:03:22,340 --> 00:03:25,540
to information classification, so IT security, actually.
62
00:03:25,540 --> 00:03:28,380
And I managed the...
63
00:03:28,380 --> 00:03:32,620
Intramanagement plan, how this company would build up
64
00:03:32,620 --> 00:03:34,980
an information classification system.
65
00:03:34,980 --> 00:03:40,060
And there was so much work, because it was a big enterprise.
66
00:03:40,060 --> 00:03:43,020
At some point, we even maxed out our excel tables.
67
00:03:43,020 --> 00:03:44,620
We had excel tables with all the list,
68
00:03:44,620 --> 00:03:46,660
all the information that we needed, and we maxed it out,
69
00:03:46,660 --> 00:03:49,540
so we had more than 1 million lines.
70
00:03:49,540 --> 00:03:54,380
There was a point where I realized the thing with the computers and IT,
71
00:03:54,380 --> 00:03:55,940
maybe they would stick around,
72
00:03:55,940 --> 00:04:03,140
and maybe it would make sense to dive more into the technical part of life and all work.
73
00:04:03,140 --> 00:04:04,980
So it's kind of out of the blue,
74
00:04:04,980 --> 00:04:08,380
I applied for a job at a IT company,
75
00:04:08,380 --> 00:04:10,540
and they were like, "Great, do you have any clues?"
76
00:04:10,540 --> 00:04:12,180
And they said, "No."
77
00:04:12,180 --> 00:04:16,260
So there was a little bit awkward interview, to be honest,
78
00:04:16,260 --> 00:04:22,260
because I got lots of IT questions, and I couldn't answer them.
79
00:04:22,260 --> 00:04:25,620
In fact, I think last week, I thought about one of those questions,
80
00:04:25,620 --> 00:04:28,180
and I still have no idea where this comes from.
81
00:04:28,180 --> 00:04:30,180
There was a guy, and he was like, "Out of the blue,
82
00:04:30,180 --> 00:04:32,220
do you know what a forest is in IT?"
83
00:04:32,220 --> 00:04:35,700
There was like, "No, never heard that term before in IT."
84
00:04:35,700 --> 00:04:37,300
And I still haven't.
85
00:04:37,300 --> 00:04:41,860
I know that this is now the collection of all the entries in your enter ID,
86
00:04:41,860 --> 00:04:43,860
something like that, but there was...
87
00:04:43,860 --> 00:04:46,740
I was completely lost in that interview,
88
00:04:46,740 --> 00:04:54,260
but somehow I managed to build, I think, a car park management app,
89
00:04:54,260 --> 00:04:56,500
or something like that.
90
00:04:56,500 --> 00:04:58,660
Each app was list and all this stuff.
91
00:04:58,660 --> 00:05:00,820
There was way before part of that form,
92
00:05:00,820 --> 00:05:04,180
when I even started in that.
93
00:05:04,180 --> 00:05:07,460
Yeah, and then I kind of was stuck in IT,
94
00:05:07,460 --> 00:05:12,340
and focused on change management and introduction of Office 365 and M365.
95
00:05:12,340 --> 00:05:16,820
What is teams and planar and project, and how does it work?
96
00:05:16,820 --> 00:05:20,900
So I would say the soft skills guide side of IT.
97
00:05:20,900 --> 00:05:23,060
And then, because I'm really lazy,
98
00:05:23,060 --> 00:05:25,380
I discovered Paul Orman, Paul Epps, and I was like,
99
00:05:25,380 --> 00:05:27,540
"Yeah, that sounds like my kind of gem.
100
00:05:27,540 --> 00:05:29,460
Like automate your task.
101
00:05:29,460 --> 00:05:32,500
That's what I want to do for my task."
102
00:05:32,500 --> 00:05:35,780
And I failed miserably, but then I discovered the community,
103
00:05:35,780 --> 00:05:38,740
the Microsoft community around it, and I got so much help,
104
00:05:38,740 --> 00:05:41,140
and I engaged with different people.
105
00:05:41,140 --> 00:05:45,380
And then, at some point, I built my first flow,
106
00:05:45,380 --> 00:05:48,580
and then I got better at building flows, and then apps,
107
00:05:48,580 --> 00:05:51,380
and then I worked as a, yeah, more or less app and flow,
108
00:05:51,380 --> 00:05:55,060
and I developed for quite some time.
109
00:05:55,060 --> 00:05:58,820
But I realized it was a struggle for me,
110
00:05:58,820 --> 00:06:01,620
because coding doesn't get naturally to me,
111
00:06:01,620 --> 00:06:03,460
as I mentioned, I didn't study IT,
112
00:06:03,460 --> 00:06:06,340
or didn't have any experience.
113
00:06:06,340 --> 00:06:12,100
So, after a couple of years working with the Power Platform,
114
00:06:12,100 --> 00:06:17,700
I decided that I should use my skill that I had from my university,
115
00:06:17,700 --> 00:06:23,220
like communication, change management, analyzing situations,
116
00:06:23,220 --> 00:06:27,940
that I should use this together with IT, and the end is,
117
00:06:27,940 --> 00:06:34,740
that I now consult companies with how to work with Power Platform,
118
00:06:34,740 --> 00:06:37,780
why in general, work with Power Platform, how to make it secure,
119
00:06:37,780 --> 00:06:39,620
because somehow no one talks about it,
120
00:06:39,620 --> 00:06:43,620
like administration security and governance.
121
00:06:43,620 --> 00:06:48,100
So, I kind of took this niche or this road by accident,
122
00:06:48,100 --> 00:06:52,180
because nearly no one was there, and it kind of fitted my skills.
123
00:06:52,180 --> 00:06:56,820
So, it is fun for me now, and I'm still at the point where,
124
00:06:56,820 --> 00:06:59,780
and say, I can develop my apps and flows,
125
00:06:59,780 --> 00:07:03,460
and I do that for myself, but on an enterprise scale, for example,
126
00:07:03,460 --> 00:07:06,020
please let the code us do their work,
127
00:07:06,020 --> 00:07:08,580
because I'm clearly not as good as them are.
128
00:07:08,580 --> 00:07:11,620
So, yeah, that's how I ended in my spot,
129
00:07:11,620 --> 00:07:14,020
in a short story.
130
00:07:14,020 --> 00:07:15,780
Yeah, awesome, awesome.
131
00:07:15,780 --> 00:07:21,220
And you're also well-regunized sports star,
132
00:07:21,220 --> 00:07:24,980
you are a mini golf champion, how would you?
133
00:07:24,980 --> 00:07:28,420
How do you achieve your career?
134
00:07:28,420 --> 00:07:32,660
Well, this sounds bigger than it actually is, I guess.
135
00:07:32,660 --> 00:07:37,700
That was, with a bunch of people from the community,
136
00:07:37,700 --> 00:07:41,780
I attended the South Coast Summit in the UK,
137
00:07:41,780 --> 00:07:45,300
and I don't know why, but we thought, we come from Germany,
138
00:07:45,300 --> 00:07:46,980
we drive through Belgium and the Netherlands,
139
00:07:46,980 --> 00:07:49,540
and then we can go by car to the UK.
140
00:07:49,540 --> 00:07:52,580
So, let's make a road trip, this is fun, right?
141
00:07:52,580 --> 00:07:55,780
It was fun, I would say, first 15, 20 minutes,
142
00:07:55,780 --> 00:07:58,340
and then you have like a day-long road trip in a car,
143
00:07:58,340 --> 00:08:04,420
and it was a little bit, it was a lot, a lot of driving,
144
00:08:04,420 --> 00:08:06,740
so we decided to take a break at some point,
145
00:08:06,740 --> 00:08:08,900
and there wasn't any golf course.
146
00:08:08,900 --> 00:08:14,660
And I won this game, and since I won this game
147
00:08:14,660 --> 00:08:18,900
against many other Microsoft MVPs from different areas,
148
00:08:18,900 --> 00:08:21,540
I decided to call myself a Raining Mini Golf Champion,
149
00:08:21,540 --> 00:08:25,700
from that point on, that's all this,
150
00:08:25,700 --> 00:08:27,940
but that's the stories about, actually.
151
00:08:27,940 --> 00:08:30,660
Maybe I could delete it now from this,
152
00:08:30,660 --> 00:08:34,260
but it's still there, and I don't know.
153
00:08:34,260 --> 00:08:39,780
Yeah, a lot of people see the power platform,
154
00:08:39,780 --> 00:08:42,740
I say, as collection of tools like PowerX Power Automate,
155
00:08:42,740 --> 00:08:47,620
Power BI, DataWords, Co-Pilot Studio, and once also in it.
156
00:08:47,620 --> 00:08:50,820
You see it as an organizational capability.
157
00:08:50,820 --> 00:08:56,260
What's the difference between those, yeah, both mindsets?
158
00:08:56,260 --> 00:08:57,060
Yeah.
159
00:08:57,060 --> 00:09:02,020
All platform consists of many different services,
160
00:09:02,020 --> 00:09:04,580
so Power Automate is a service, Power Apps is a service,
161
00:09:04,580 --> 00:09:06,500
Power pages is a service, and so on and so on.
162
00:09:06,500 --> 00:09:13,060
So what you get there is a classic software as a service thing.
163
00:09:13,060 --> 00:09:15,460
And that's still true, but the whole platform
164
00:09:15,460 --> 00:09:19,300
that combines, or basically is a foundation
165
00:09:19,300 --> 00:09:21,700
for all these services to run on,
166
00:09:21,700 --> 00:09:24,980
that is the Power Platform that is baked into your tenant,
167
00:09:24,980 --> 00:09:27,700
into your Azure subscription, into everything with that.
168
00:09:27,700 --> 00:09:29,700
Then that is not software as a service,
169
00:09:29,700 --> 00:09:31,300
that is a platform as a service.
170
00:09:31,300 --> 00:09:33,060
And there's a difference between that,
171
00:09:33,060 --> 00:09:37,300
what kind of features are managed by Microsoft
172
00:09:37,300 --> 00:09:40,260
when you have a software as a service product,
173
00:09:40,260 --> 00:09:42,500
versus what is managed by Microsoft,
174
00:09:42,500 --> 00:09:45,380
when you have a platform as a service product.
175
00:09:45,380 --> 00:09:46,580
And that is a difference.
176
00:09:46,580 --> 00:09:49,140
And therefore, Power Platform is kind of both,
177
00:09:49,140 --> 00:09:52,660
it's a platform as a service, and if you have enabled it in your tenant
178
00:09:52,660 --> 00:09:57,540
and you use it, the services is software as a service for your users,
179
00:09:57,540 --> 00:10:00,180
but not for you as, let's say, administrator,
180
00:10:00,180 --> 00:10:02,580
as someone who owns the tenant, as someone who is in charge.
181
00:10:02,580 --> 00:10:06,980
And that makes a fundamental difference in how to act,
182
00:10:06,980 --> 00:10:10,020
as a, let's say, Power Platform developer,
183
00:10:10,020 --> 00:10:11,540
or Power Platform administrator,
184
00:10:11,540 --> 00:10:13,620
or Power Platform, I don't know, owner.
185
00:10:13,620 --> 00:10:15,780
If you are the owner of the platform,
186
00:10:15,780 --> 00:10:17,380
or the services in your company,
187
00:10:17,380 --> 00:10:20,500
then you have to ask different questions and do different things.
188
00:10:20,500 --> 00:10:23,940
Evolving and running flows is one thing,
189
00:10:23,940 --> 00:10:27,060
but managing the whole group of makers and citizen developers
190
00:10:27,060 --> 00:10:28,580
who do that is a different thing.
191
00:10:29,460 --> 00:10:34,020
So that is something, yeah, sometimes I think,
192
00:10:34,020 --> 00:10:37,860
Microsoft started to deliver the story,
193
00:10:37,860 --> 00:10:40,980
to really make this a story,
194
00:10:40,980 --> 00:10:44,420
that even this is just a low-code platform,
195
00:10:44,420 --> 00:10:47,700
it still requires work and setup and maintenance.
196
00:10:47,700 --> 00:10:51,620
That is something, and I really like that Microsoft started
197
00:10:51,620 --> 00:10:54,740
to spread the story more and more,
198
00:10:54,740 --> 00:10:58,180
because in the very beginning, it was all a little bit,
199
00:10:58,180 --> 00:10:59,940
it's easy, everyone can do that.
200
00:10:59,940 --> 00:11:01,380
It's a little bit, okay, okay, here,
201
00:11:01,380 --> 00:11:04,020
and then, voila, you have a flow, a business critical flow.
202
00:11:04,020 --> 00:11:09,220
So that is, yeah, that is, I guess, the main difference between,
203
00:11:09,220 --> 00:11:11,780
why? Because I say, there's a platform,
204
00:11:11,780 --> 00:11:14,820
on this platform, there are services like Power,
205
00:11:14,820 --> 00:11:16,420
or my Power Apps, and whatnot.
206
00:11:16,420 --> 00:11:21,060
Yeah, and that comes, you're, I say, your clear statement,
207
00:11:21,060 --> 00:11:23,060
you say, Power Platform, there's not a hobby tool,
208
00:11:23,060 --> 00:11:24,260
it's an enterprise software.
209
00:11:24,260 --> 00:11:27,300
I love the story.
210
00:11:28,260 --> 00:11:30,420
Yeah, I would love to repart the platform to be a hobby tool,
211
00:11:30,420 --> 00:11:33,780
because I have so many things I would automate for myself,
212
00:11:33,780 --> 00:11:35,780
but for Power Platform, you need a business license.
213
00:11:35,780 --> 00:11:37,300
That is the point.
214
00:11:37,300 --> 00:11:44,580
That means even if you do something as a hobby tool
215
00:11:44,580 --> 00:11:46,900
with Microsoft, then you always bound to your,
216
00:11:46,900 --> 00:11:49,060
not to your talent, but to your license,
217
00:11:49,060 --> 00:11:49,940
is so to say.
218
00:11:49,940 --> 00:11:51,300
That is something, but yeah, sorry,
219
00:11:51,300 --> 00:11:53,460
didn't want to interrupt, it's not a hobby tool.
220
00:11:53,460 --> 00:11:54,980
No, it's a pure,
221
00:11:55,940 --> 00:11:58,660
pure professional business application platform.
222
00:11:58,660 --> 00:12:03,140
Yeah, what's the, other more common
223
00:12:03,140 --> 00:12:06,180
misconceptions you have when they hear low-code,
224
00:12:06,180 --> 00:12:08,100
citizen development, and I think,
225
00:12:08,100 --> 00:12:11,460
actually, we have also Star Wars low-code on the platform.
226
00:12:11,460 --> 00:12:14,660
A vibe coding, or low-code?
227
00:12:14,660 --> 00:12:15,860
I don't know how, how, how,
228
00:12:15,860 --> 00:12:17,220
Microsoft actually called it.
229
00:12:17,220 --> 00:12:22,420
We are still on a low-code platform with the Power Platform.
230
00:12:24,660 --> 00:12:28,340
Vibe coding is getting more and more into the,
231
00:12:28,340 --> 00:12:29,140
into the platform.
232
00:12:29,140 --> 00:12:32,580
There was, I was called, Power Apps Plan,
233
00:12:32,580 --> 00:12:34,900
Power Apps Plan, or something like that,
234
00:12:34,900 --> 00:12:37,700
where you basically build your apps and codes,
235
00:12:37,700 --> 00:12:39,140
and whatever, with prompts.
236
00:12:39,140 --> 00:12:43,700
So this vibe coding element is getting more and more into the platform.
237
00:12:43,700 --> 00:12:46,500
Not sure how I think about that,
238
00:12:46,500 --> 00:12:49,780
but the most common misconception, I guess,
239
00:12:49,780 --> 00:12:53,540
I guess it changes, or it kind of changed.
240
00:12:53,540 --> 00:12:56,660
And for very long years, I think it always was
241
00:12:56,660 --> 00:13:00,820
following the Microsoft message, it's easy, and everyone can do that.
242
00:13:00,820 --> 00:13:08,260
That is not wrong, but to have it, or to treat it more like an enterprise,
243
00:13:08,260 --> 00:13:11,300
or business tool, then it's not easy.
244
00:13:11,300 --> 00:13:13,140
If you want to use it in a professional way,
245
00:13:13,140 --> 00:13:16,500
if you want to have a regional profit, for example,
246
00:13:16,500 --> 00:13:17,940
or if you want to solve a problem,
247
00:13:17,940 --> 00:13:19,540
then you would have to put in some effort.
248
00:13:20,100 --> 00:13:24,180
And it's, especially, I would say, Powerpages, Power Apps.
249
00:13:24,180 --> 00:13:28,980
That is something, or at least, not all Power Apps, but Canvas Apps,
250
00:13:28,980 --> 00:13:31,540
that require some kind of coding.
251
00:13:31,540 --> 00:13:33,300
That requires some kind of learning,
252
00:13:33,300 --> 00:13:35,620
and some time and effort to put in.
253
00:13:35,620 --> 00:13:39,540
And that is, I guess, we had, if you see this, like,
254
00:13:39,540 --> 00:13:43,700
like, wave way of the development,
255
00:13:43,700 --> 00:13:45,060
at the beginning, everyone was like,
256
00:13:45,060 --> 00:13:49,060
"Yeah, there's a super easy, and everyone built a whole lot of apps and flows,
257
00:13:49,060 --> 00:13:50,820
and they are all stored in default environment."
258
00:13:50,820 --> 00:13:55,940
And after a while, they broke, they never really got finished.
259
00:13:55,940 --> 00:14:00,740
It was all tests, and they realized, "Okay, we have to do some series.
260
00:14:00,740 --> 00:14:02,980
We have to put in some series effort here."
261
00:14:02,980 --> 00:14:08,020
And then this, the usage of Power Platform went a little bit down, I think.
262
00:14:08,020 --> 00:14:11,540
And then there was a point where the more IT professionals
263
00:14:11,540 --> 00:14:16,020
started to do a "Urto Discover Power Platform" and put in some more work.
264
00:14:16,020 --> 00:14:21,140
And now, what I see is lots of organization use Power Platform.
265
00:14:21,140 --> 00:14:25,220
And users are using that for their first productivity projects,
266
00:14:25,220 --> 00:14:27,220
so small kind of flows remind us,
267
00:14:27,220 --> 00:14:29,540
something like this.
268
00:14:29,540 --> 00:14:30,820
And on the other hand, we have
269
00:14:30,820 --> 00:14:36,260
not even business apps, but whole business projects,
270
00:14:36,260 --> 00:14:40,580
like solutions that contain dozens of flows and apps and tables and everything.
271
00:14:40,580 --> 00:14:43,780
And that is, and plugins and custom coding.
272
00:14:43,780 --> 00:14:45,140
And all of that, that is like,
273
00:14:45,540 --> 00:14:51,300
a lot on the one hand side and just lower effort on the other side.
274
00:14:51,300 --> 00:14:54,500
So that's kind of interesting.
275
00:14:54,500 --> 00:14:57,860
There seems to be no in-between, more or less.
276
00:14:57,860 --> 00:15:01,860
Yeah, that's good.
277
00:15:01,860 --> 00:15:06,980
But I think for people to understand what's happened,
278
00:15:06,980 --> 00:15:10,980
can you give us one or two examples where we have seen it's
279
00:15:11,860 --> 00:15:20,260
yeah, flow at become, start with a good attention, but it becomes critical in the business?
280
00:15:20,260 --> 00:15:25,780
Yes.
281
00:15:25,780 --> 00:15:33,220
It's a little bit tricky because when you say a flow or an app or whatever,
282
00:15:33,220 --> 00:15:35,620
a Power Platform solution becomes business critical,
283
00:15:35,620 --> 00:15:37,700
it always depends on what you mean with critical.
284
00:15:38,180 --> 00:15:47,060
Because when you have a flow that helps you get the correct data from a big database,
285
00:15:47,060 --> 00:15:55,780
like SAP, I write my own code, I have access to the SAP database and so I can delegate my access to
286
00:15:55,780 --> 00:16:01,940
my flow to really get access and you even get, get, let, show me the data that I need for
287
00:16:01,940 --> 00:16:10,020
personal work. That is fine, that in a few terms can be a non-business critical.
288
00:16:10,020 --> 00:16:16,020
If now this flow gets shared with more and more people and they edit it and they customize
289
00:16:16,020 --> 00:16:23,300
a little bit and in the end you have 40 people that have automated access to SAP and they would
290
00:16:23,300 --> 00:16:28,580
not only receive data, but also write data, then you would, that would become a problem because
291
00:16:30,020 --> 00:16:34,180
you don't know what kind of data is getting in and you don't have like a layoff proof or something
292
00:16:34,180 --> 00:16:39,860
like that is something that you want to avoid. That could be a business critical, a flow that
293
00:16:39,860 --> 00:16:45,060
started with good attention, but then got business critical. I have another example yet a completely
294
00:16:45,060 --> 00:16:52,580
different example. I had a company and they used in the pre-Christmas season, they have like
295
00:16:52,580 --> 00:16:58,580
these Christmas parties and celebrations and they do a secret center and stuff like that. So
296
00:16:58,580 --> 00:17:03,780
very harmless, right? They would do this every year and at some point they said okay let's do this
297
00:17:03,780 --> 00:17:09,700
with power element because to figure out who is gifting to whom, like the secret center, a center.
298
00:17:09,700 --> 00:17:15,220
We can do this with a little bit IT with a little bit automation that works, right? So they build
299
00:17:15,220 --> 00:17:22,180
a secret center app. Absolutely not business critical. The point is now every employee of the company
300
00:17:22,180 --> 00:17:26,900
was invited to this app, which is also fine, but then you have one, I have one small little app
301
00:17:26,900 --> 00:17:32,660
that doesn't do something critical, but there are 500 people in there. And over the time you got a
302
00:17:32,660 --> 00:17:38,980
lactation in your stuff, like people are leaving the organization, new people are coming and so this
303
00:17:38,980 --> 00:17:45,620
app was kind of the list of members was outdated. And that means that you had at least 15 to 20 people
304
00:17:45,620 --> 00:17:53,300
or accounts in there that were not active anymore. And that is like a huge security gap because
305
00:17:53,300 --> 00:18:01,300
these accounts could be utilized, they were still in the Entra ID, whatsoever. And with those accounts,
306
00:18:01,300 --> 00:18:07,540
you could use some serious harm. So that is another example of an application or an idea that is
307
00:18:07,540 --> 00:18:13,220
very harmless and very fun and lighthearted, but if you don't maintain it and you have so many people
308
00:18:13,220 --> 00:18:22,420
involved, there's so much potential for mischief, let's say. So it all depends on the context, what is
309
00:18:22,420 --> 00:18:29,460
critical or what is not, what is secure, what is insecure, it's never the app, almost never the app,
310
00:18:29,460 --> 00:18:37,620
it's almost always the behavior of the people. And that is something important to understand,
311
00:18:37,620 --> 00:18:42,900
especially if you think about governance and security, all the tools that we have in the admin center,
312
00:18:42,900 --> 00:18:48,180
you have data loss prevention policies in that, that are tools to make your governance work,
313
00:18:48,900 --> 00:18:54,660
but in the end, you have to train your people because they are first and last baseline of security,
314
00:18:54,660 --> 00:19:00,580
basically. Yeah, tools help, absolutely. If we wouldn't have a tool like the app or something,
315
00:19:00,580 --> 00:19:05,940
that would be tricky. Yeah, I think, yeah, for governance, you're the
316
00:19:05,940 --> 00:19:14,980
specialist, the governance specialist around the world. So many makers here, the word governance,
317
00:19:14,980 --> 00:19:21,940
and yeah, immediately, they think of bureaucracy, tickets, approvals and restrictions.
318
00:19:21,940 --> 00:19:27,620
Yes, absolutely. I do really find governance for them.
319
00:19:27,620 --> 00:19:36,020
Actually, I think I don't really find governance, I explain governance. I think that is a thing,
320
00:19:36,020 --> 00:19:43,220
because in governance and security as well, you always have something like
321
00:19:43,940 --> 00:19:50,260
you have to decide, do you want it to be super secure and super governed, then it's really not
322
00:19:50,260 --> 00:19:54,420
handy to work. Then it takes effort, it takes time. You have to write tickets and you have to
323
00:19:54,420 --> 00:20:01,620
make backup copies and all that. That takes time and it's not this easy breezy. I just click around
324
00:20:01,620 --> 00:20:07,140
and move ahead of the flow. That is something different. If you want this to be super easy and
325
00:20:07,140 --> 00:20:12,020
with no restrictions at all and everyone can use it any time and it's super fast, then it's probably
326
00:20:12,020 --> 00:20:21,700
not that secure. So you have that decision to make anyhow. But the idea that people think of
327
00:20:21,700 --> 00:20:27,860
governance and now it's going to be slow and it's super awkward and I can't use all the connectors
328
00:20:27,860 --> 00:20:32,260
that I want so that they don't want really governance or security. That's understandable and
329
00:20:32,260 --> 00:20:39,140
they absolutely see that. I have a very interesting example that I've seen with a German company,
330
00:20:39,140 --> 00:20:44,260
surprised it was a German one. They said, "Okay, we want this secure." They came up with a process
331
00:20:44,260 --> 00:20:51,940
who can develop apps and flows, who would prove and test those apps and flows and then
332
00:20:51,940 --> 00:21:00,980
they would be raised at some point. The whole process was kind of solid. It was secure,
333
00:21:00,980 --> 00:21:07,780
it was good, understandable. Everyone knew how to work, how to handle it, how this process works,
334
00:21:07,780 --> 00:21:13,700
but this process took in the best case if I have, from my first idea, what kind of app offloader
335
00:21:13,700 --> 00:21:20,100
do I want to build? From I requested the access to the environment and to the right connectors.
336
00:21:20,100 --> 00:21:26,580
If everything went through smoothly, this process went for six months. So best case, I have an idea for
337
00:21:26,580 --> 00:21:32,100
an app and six months later it's done, regardless if I work six months on the app or just finish it in one
338
00:21:32,100 --> 00:21:36,900
day. So that was a little bit of security and governance overkill and people were really angry
339
00:21:36,900 --> 00:21:42,580
and they were like, "We don't take this anymore. That doesn't make any sense." And that was just the
340
00:21:42,580 --> 00:21:48,900
best case. So if you work on your app and two weeks, three weeks into work, you realize, "Oh, dang,
341
00:21:48,900 --> 00:21:54,100
I need another connector." The whole process started from the beginning. So it could be that your
342
00:21:54,100 --> 00:21:59,460
application development lifecycle would take a year for an app that you would build in a week.
343
00:21:59,460 --> 00:22:06,500
That was overkill. Now, the point is, so you can overdo it for sure, but the
344
00:22:06,500 --> 00:22:14,740
governance insecurity doesn't automatically mean flows, luggage and not usable anymore. And quite often
345
00:22:14,740 --> 00:22:22,820
in my workshops, I use an example that I think fits really well. And this is the idea if we think about
346
00:22:22,820 --> 00:22:29,220
traffic rules that we have in our everyday life. We do have traffic rules right now. We have
347
00:22:29,220 --> 00:22:40,900
lights and signs in Germany. We have so many sites on the road. And we do have a driver's license test.
348
00:22:40,900 --> 00:22:47,220
That is something as well. So if I want to use a vehicle, I have to take a driver's license. I have
349
00:22:47,220 --> 00:22:51,140
to learn all the rules and I have to identify all the signs. I have to know what they mean.
350
00:22:51,780 --> 00:23:01,460
And then I can participate in traffic. And I even sometimes put my kits in my car. So I make them
351
00:23:01,460 --> 00:23:07,220
participate in traffic because I feel safe enough in traffic to navigate around and everything is fine.
352
00:23:07,220 --> 00:23:12,500
Now, if you ever imagine we wouldn't have any signs or any rules in traffic, like no traffic lights,
353
00:23:12,500 --> 00:23:18,100
no clear rules of who drives first and you wouldn't have to take a test. Anyone who has access could
354
00:23:18,100 --> 00:23:25,540
just enter a car and just go for it. Then what happened, it would feel very insecure for us to
355
00:23:25,540 --> 00:23:30,820
participate in traffic because you would have to feel that every at every corner, someone would
356
00:23:30,820 --> 00:23:36,340
smash into you or just ignore the lights if you would have any in the first place. So what would
357
00:23:36,340 --> 00:23:41,620
happen then if you would participate in traffic in such a world without without any rules inside?
358
00:23:41,620 --> 00:23:47,700
What would you say? I think chaos. Teos? Yes. Would you participate in traffic?
359
00:23:47,700 --> 00:23:58,260
No. No. Like every day. You would be cautious. From not a really good car driver. So I'm my woman
360
00:23:58,260 --> 00:24:09,220
drives. So I think, I think, let me know, Cologne, I drive there for sometimes. Yeah, for me,
361
00:24:09,220 --> 00:24:17,140
it's double hard. I think. Yeah. Okay. You know, very much. And that is with traffic rules. So most people,
362
00:24:17,620 --> 00:24:22,340
answer me this question like this. They would say, yes, I would participate in traffic. I would
363
00:24:22,340 --> 00:24:28,580
drive in my car, but not all the time. Only if it's really necessary. Like I need something
364
00:24:28,580 --> 00:24:34,100
re-urgently or something like that. Would I take my kids? I don't think so. And especially I would
365
00:24:34,100 --> 00:24:40,980
drive very slow because I always have to take into calculation that someone would smash into me or
366
00:24:40,980 --> 00:24:46,660
would drive way too fast or something. So the whole process would be slowed down extremely.
367
00:24:47,140 --> 00:24:51,540
And it would be a lot of effort to do that. It would be insecure. You're not allowed what to do
368
00:24:51,540 --> 00:24:57,620
when and stuff like that. And it's it's the same with governance rules in power platform.
369
00:24:57,620 --> 00:25:01,780
If everyone is allowed to do anything all the time and you don't have any regulations,
370
00:25:01,780 --> 00:25:07,300
you don't have any rules or people don't know the rules, then what happens at least for
371
00:25:07,300 --> 00:25:12,260
the administrators in every environment all of the time they are always apps and flows popping
372
00:25:12,260 --> 00:25:22,740
up, being deleted. Things would break all the time. The IT administrator would have to act like a
373
00:25:22,740 --> 00:25:26,740
firefighter. They wait for an emergency to happen, then they rush to it and try to fix things.
374
00:25:26,740 --> 00:25:32,260
That is frustrating for everyone. For users now, if they don't know what's allowed and what not,
375
00:25:32,260 --> 00:25:38,660
where am I allowed to build? What can I use and what not? They get cautious because sometimes you get
376
00:25:38,660 --> 00:25:47,940
emails from IT, you broke a rule or you got a DLP violation error or something like that. I didn't
377
00:25:47,940 --> 00:25:52,340
intend to do that, but I didn't know any better. So the whole process is sometimes slow.
378
00:25:52,340 --> 00:25:57,460
If you have a clear set of rules and regulations and it's that is the second
379
00:25:57,460 --> 00:26:02,500
amount in part is communicated to everyone that is using the power platform and they understand it.
380
00:26:02,500 --> 00:26:07,300
Like here is your environment where you can build. Just go wild, do whatever you want. We've
381
00:26:07,300 --> 00:26:14,980
secured it. You can try whatever you want to try. Then the makers and the citizens develop us. They
382
00:26:14,980 --> 00:26:21,140
have the confidence to build free, to experiment, to break things even because that is, I think,
383
00:26:21,140 --> 00:26:26,580
a necessary part in learning and developing. It's like if you do something and breaks, usually,
384
00:26:26,580 --> 00:26:32,660
at some point you learn a lesson and you say, "Why does it break? Why is it me? Is it the restriction?
385
00:26:32,660 --> 00:26:41,220
Something like this." I often see from, as a result, from my work in companies where I work and I
386
00:26:41,220 --> 00:26:47,940
and we worked on a governance approach, that the development cycle actually gets faster and
387
00:26:47,940 --> 00:26:58,420
accelerates. The incidents, the incident rate gets lower and usually that is a win-win for both sides.
388
00:27:00,420 --> 00:27:04,740
That is often the problem when people and makers hear the word governance and security, they think,
389
00:27:04,740 --> 00:27:10,980
"No, no, I'm not allowed to do stuff anymore." The point is often most administrators and
390
00:27:10,980 --> 00:27:16,740
platform owners, I know, they would be happy if they knew what people want to do and why.
391
00:27:16,740 --> 00:27:21,620
So if someone says, "I have a great idea for the Instagram connector and our business data."
392
00:27:21,620 --> 00:27:27,940
The answer to that would say, "No, that doesn't sound too good." But if they put their ideas into
393
00:27:27,940 --> 00:27:34,420
a plan, why would you want to do that? What would you want to do? Even maybe you would give them a
394
00:27:34,420 --> 00:27:39,700
demo example where they can try out a bit of words, let's see how the result is, then maybe it's a valuable idea.
395
00:27:39,700 --> 00:27:46,100
I don't know that yet, but from the administrator or owner perspective, I can't really evaluate the idea
396
00:27:46,100 --> 00:27:56,020
yet enough if I just hear this kind of scenario. So what really the important point of my work is
397
00:27:56,020 --> 00:28:02,820
to explain what is governance and what is it for because in the end, governance is a part of the
398
00:28:02,820 --> 00:28:09,220
solution that everyone that works in companies still has a job tomorrow because really big upsies,
399
00:28:09,220 --> 00:28:15,860
they cost jobs and money and that is something that we don't want, especially not with a cool and fun
400
00:28:15,860 --> 00:28:22,180
tool like Power Platform. Yeah, I think just this last thought maybe.
401
00:28:24,900 --> 00:28:31,860
What Power Platform does is it democratizes the accessibility to software solutions.
402
00:28:31,860 --> 00:28:38,100
So even without extensive computer or programming knowledge, you can build your own solutions
403
00:28:38,100 --> 00:28:42,340
because you are the expert of your own for your own work. You know what really sucks at work and
404
00:28:42,340 --> 00:28:47,300
what could be done better and now you have the possibility to solve it yourself and that is
405
00:28:47,300 --> 00:28:54,340
really, really important and brings lots of value and I don't want to restrict that too much.
406
00:28:54,340 --> 00:29:02,740
That would be a shame basically. So explaining what governance is is usually it lowers the
407
00:29:02,740 --> 00:29:15,300
fear I would say. Yeah, fear. Yeah, roots fear. I think one of some of your articles,
408
00:29:15,300 --> 00:29:20,180
you are a little bit reframing the governance to clarity, confidence and boundaries.
409
00:29:22,580 --> 00:29:27,860
That's a little bit unpagnate. First let's a little bit talk about clarity.
410
00:29:27,860 --> 00:29:33,700
What does clarity looks like in a major Power Platform organization? Is it the key ownership,
411
00:29:33,700 --> 00:29:39,540
key environment, key data classification, connect, rules, escalation path, what is clarity?
412
00:29:39,540 --> 00:29:45,940
Yeah, so first of all, I think and that is not only for Power Platform, but for every aspect in
413
00:29:45,940 --> 00:29:54,020
life, clarity brings freedom. If I know if I have clarity in the if I know what I can do,
414
00:29:54,020 --> 00:30:00,740
what is expected of me, what is supposed to happen, I know rules. Then I have the freedom to
415
00:30:00,740 --> 00:30:09,860
choose how I act. That is an if I don't have clarity and if some things are uncertain and the
416
00:30:09,860 --> 00:30:15,220
outcome and the expected outcome is uncertain, then I maybe hesitate to take action. If I know what
417
00:30:15,220 --> 00:30:21,620
will happen, if everything is clear to me, then I can choose my actions and do so. And clarity
418
00:30:21,620 --> 00:30:25,860
in Power Platform is exactly that. On the one hand side for the maker, on the one other hand side
419
00:30:25,860 --> 00:30:31,380
for the administrators, let's say, it's up with the maker side. That means if a maker knows,
420
00:30:31,380 --> 00:30:40,580
default environment is forbidden. No, no, don't build here. If the maker knows, I can have my personal
421
00:30:40,580 --> 00:30:46,260
developer environment and I can build there within all those restrictions, restrictions that we have.
422
00:30:46,260 --> 00:30:51,300
For example, we won't use the Twitter or X connector or the Instagram connector.
423
00:30:51,300 --> 00:30:56,980
Fine, then I have the freedom of building my flows and apps, but without those connectors.
424
00:30:56,980 --> 00:31:05,220
I can do that. If I still want to use those connectors, for example, and I can ask for it, maybe like
425
00:31:05,220 --> 00:31:12,340
a demo, extra secure demo environment or something, then clarity would mean that I know whom to ask.
426
00:31:12,340 --> 00:31:18,180
Where do I go to if I have a question? Where do I go to if something breaks? That is like a first
427
00:31:18,180 --> 00:31:24,020
level support process that I have. And if I have such a process, it's really necessary that my
428
00:31:24,020 --> 00:31:29,540
makers and all users, basically, all of them, they know, they know how to do it. How does it work?
429
00:31:29,540 --> 00:31:34,020
Where do I go to? Where do I have to click? What language should I use? Something like that.
430
00:31:34,820 --> 00:31:40,180
And this clarity is important for users of the kind, but for powerful platforms, especially I think.
431
00:31:40,180 --> 00:31:46,580
On the other hand, clarity for administrators looks different. As an administrator, I want to know
432
00:31:46,580 --> 00:31:52,340
what's going on in my tenant because I'm responsible for security. And I can't be responsible if,
433
00:31:52,340 --> 00:31:58,180
let's say, 100-maker would don't have any clarity and they just click around aimlessly.
434
00:31:58,820 --> 00:32:05,780
Then I can't provide the security that is my job. So I need the clarity to see what's going on. I might
435
00:32:05,780 --> 00:32:11,460
and my tenant. What environments are there? Who has access to this environments? Are there any
436
00:32:11,460 --> 00:32:21,540
other administrators or people who have extended rights? Is there a citizen developer, an account
437
00:32:21,540 --> 00:32:27,780
that has developed 50 new custom connectors? And I would like to know about this. What do they connect
438
00:32:27,780 --> 00:32:32,740
to all those connectors do? I don't want to restrict the development of connectors, but I just want to know
439
00:32:32,740 --> 00:32:40,180
if they are working within the compliance rules of our organization. I just need to know that.
440
00:32:40,180 --> 00:32:46,900
And before I can evaluate some of this, I need to know what's there and what's in it. So clarity,
441
00:32:46,900 --> 00:32:53,300
I need a good inventory. So for administrators, the term clarity is more technical term. I need a good
442
00:32:53,300 --> 00:33:00,900
fucking inventory. Otherwise, I have no idea what's going on. I can't go on it. So clarity,
443
00:33:00,900 --> 00:33:09,540
it's absolutely a must have. Okay, the clarity brings the freedom and then we have confidence.
444
00:33:09,540 --> 00:33:17,460
What brings confidence? Well, as I said, clarity brings confidence. That is kind of the point.
445
00:33:17,460 --> 00:33:21,700
It follows each other. If I know what I'm allowed to do and what I'm not allowed to do,
446
00:33:21,700 --> 00:33:25,540
then I have the confidence to build within those restrictions that I have.
447
00:33:25,540 --> 00:33:32,180
If I don't know, if I'm doing something forbidden right now, then I don't act confident.
448
00:33:32,180 --> 00:33:38,340
Then I always act like I'm trying to stay under the radar. I'm trying to be hidden to not get caught
449
00:33:38,340 --> 00:33:43,140
or something. That is not confident. That is sneaking around. And that is what we, for decades,
450
00:33:43,140 --> 00:33:50,100
now called shadow IT. Well, shadow IT is a term not necessarily fitting in this discussion or in
451
00:33:50,100 --> 00:33:56,020
the, in this confidence discussion, but shadow IT is an important term. And in power platform
452
00:33:56,020 --> 00:34:01,540
has the opportunity to build this inventory, to get this clarity for all participants.
453
00:34:01,540 --> 00:34:08,980
And that means that confidence coding is possible for everyone, for administrators and for users,
454
00:34:08,980 --> 00:34:13,860
for citizens, developers, for all the people that we have. And this confidence,
455
00:34:16,500 --> 00:34:21,940
I think clarity brings confidence and confidence on the other brings clarity.
456
00:34:21,940 --> 00:34:26,580
Because if I build confidence in there and I can transport my ideas and I can communicate my ideas
457
00:34:26,580 --> 00:34:32,180
and show the output, like, proud and confident, then I have a foundation to talk about what I've
458
00:34:32,180 --> 00:34:37,780
done. Is it a good solution? Is it valuable? Is it nice to have? But if I don't have this,
459
00:34:37,780 --> 00:34:44,820
then I can't talk about this. And then we drift into this shadow IT world where I try to
460
00:34:44,820 --> 00:34:47,860
be not get caught by administrators because I build something that is not really allowed.
461
00:34:47,860 --> 00:34:59,540
Yeah. And then we have the last key, yeah, the last, the last word boundaries. What, what, what's
462
00:34:59,540 --> 00:35:05,060
that there all the point? Why I put this word in there is boundaries is something else
463
00:35:05,060 --> 00:35:12,820
from restrictions. If something is forbidden, I know it is, I'm just not allowed to do that. A
464
00:35:12,820 --> 00:35:23,940
boundary, at least in my, in my hat, in my understanding is something that is not necessary for
465
00:35:23,940 --> 00:35:30,420
bitten, but we don't do that because of a specific reason. So we have reasoning for it. And that is
466
00:35:30,420 --> 00:35:36,820
kind of often another misconception that we have in IT between IT and business often. IT says no,
467
00:35:37,460 --> 00:35:45,380
but not why. And the business is, well, that sucks. A boundary for me is usually communicated within
468
00:35:45,380 --> 00:35:57,140
a reasonable, but we do have a reason for that. And when I say, I don't want to allow the, the
469
00:35:57,140 --> 00:36:04,180
Instagram connector in our tenant, then I should be better in the position to say why because it's
470
00:36:04,180 --> 00:36:09,220
linked to matter and matter collects data like crazy. And we don't want our business data
471
00:36:09,220 --> 00:36:15,620
like to get to matter because we don't know what they do actually with it. And that is not our
472
00:36:15,620 --> 00:36:21,860
goal. So that is a little bit, maybe it's a little bit sneaky of me to, to swap the turn,
473
00:36:21,860 --> 00:36:28,100
being forbidden, being restricted, but being, there's a boundary, but you can always discuss
474
00:36:28,100 --> 00:36:33,140
about a boundary. And if you ever fix through, there's not much room for discussion. So maybe it's
475
00:36:33,140 --> 00:36:39,140
a little bit, but it's, as you said in the beginning, it's reframing. It's reframing what governance means
476
00:36:39,140 --> 00:36:46,420
and why we do that, why we do have boundaries and what reason behind it. Once again,
477
00:36:46,420 --> 00:36:55,380
and these boundaries and those security rules and governance rules that we have, they have to be
478
00:36:55,380 --> 00:37:02,420
flexible in a way because that means a rule that was yesterday absolutely fine, doesn't mean it's
479
00:37:02,420 --> 00:37:10,980
absolutely fine tomorrow. Sometimes the compliance rules that we have to follow, they change as well.
480
00:37:10,980 --> 00:37:21,140
Example would be the EU AI Act that just came to terms. This now is a major change in how we act
481
00:37:21,140 --> 00:37:27,140
in the European Union. And now we have to adapt our rules and compliance for that. Another example
482
00:37:27,140 --> 00:37:34,900
would be seat belts. Seat belts were not mandatory in class for quite sometimes in the 60s and so
483
00:37:34,900 --> 00:37:42,660
now they are. So we have to adapt our compliance and our rules. So I think boundaries are a little
484
00:37:42,660 --> 00:37:48,420
bit more flexible and they can be adapted. So they, that's, that's the important point. So reframing
485
00:37:48,420 --> 00:37:55,300
governance and explaining why we do what we do and also be in the position to take some critical
486
00:37:55,300 --> 00:38:00,340
questions. If all of you say that doesn't make sense and I explain you why, then I should be
487
00:38:00,340 --> 00:38:04,500
confident enough and I can be confident if I have the clarity, if I know what's going on.
488
00:38:04,500 --> 00:38:10,980
To take this discussion, why do we do that? Or why don't we allow that? And that is something
489
00:38:10,980 --> 00:38:16,500
that is necessary, I think, in the whole security, IT security and the governance area.
490
00:38:16,500 --> 00:38:23,540
Partly, from kind of shows it because so many people have access all of sudden and yeah, makes it
491
00:38:23,540 --> 00:38:32,260
kind of a more open issue. Yeah, I work for, I don't know, three years for one of the biggest
492
00:38:32,260 --> 00:38:39,380
automotive companies. I don't know the law to say their name, but my time in Voss book.
493
00:38:39,380 --> 00:38:43,700
I was, all right, got it.
494
00:38:43,700 --> 00:38:51,700
Was therefore a Microsoft fabric project and that's what was really interesting because they,
495
00:38:51,700 --> 00:38:58,500
they used the power platform every, really every day. I have flows that give the data back,
496
00:38:58,500 --> 00:39:02,820
transform it. There was bots that were working with it. They have custom connections to it.
497
00:39:02,820 --> 00:39:13,540
SharePoint was connected and also a variety of, of data was a database is also connected to this.
498
00:39:13,540 --> 00:39:21,380
And then I think I know the answer, but from your perspective, why is inventory the foundation
499
00:39:21,940 --> 00:39:29,220
of governance? As I said earlier, if you don't know what you have, you don't know what to have
500
00:39:29,220 --> 00:39:37,940
to do to government to make it secure. It's as easy as that. And for that, I have plenty of
501
00:39:37,940 --> 00:39:43,380
examples because usually it's when I work with companies and organizations, ask them, do you have
502
00:39:43,380 --> 00:39:48,980
a governance and say, yes, we do. Second question is, and have you written it down? Like recommended,
503
00:39:50,500 --> 00:39:58,420
no, almost no, something like that. So when we start the governance project,
504
00:39:58,420 --> 00:40:02,980
usually we start with inventory, okay, what do we have? We open a hood and let's see what really
505
00:40:02,980 --> 00:40:09,620
out there. And quite often we find something like, I don't know, 600 apps in default environment.
506
00:40:09,620 --> 00:40:17,940
And that is not best practice. That is in fact, security risk. And quite often we find just a few,
507
00:40:17,940 --> 00:40:23,380
a couple of accounts like those very power users who are very confident, they're funnily, and they
508
00:40:23,380 --> 00:40:28,500
develop a few custom connectors. And then you realize, okay, they could do a lot of
509
00:40:28,500 --> 00:40:33,380
stupe those custom connectors. I just want to see what's happening to my data. Where is it right now?
510
00:40:33,380 --> 00:40:39,540
It's a little bit like switching on the light in a dark room. You have to see what there is in
511
00:40:39,540 --> 00:40:48,980
order to decide how to proceed. And sometimes you have funny moments for that. A good friend of mine
512
00:40:48,980 --> 00:40:54,580
once also works in governance. He had a project in the customer and they found a custom connector to,
513
00:40:54,580 --> 00:41:02,180
let's say, to an internet site, to let's say an adult film site. I don't want to say the name,
514
00:41:02,180 --> 00:41:07,300
but I think everyone knows what's meant by that. And they got a custom connector. You just
515
00:41:07,300 --> 00:41:13,780
would receive data. This would receive playlists and stuff. And I don't know what the background was,
516
00:41:13,780 --> 00:41:18,580
if they have like any business with that, or if they just weren't very curious, can we do this?
517
00:41:18,580 --> 00:41:23,620
Because of course, there is an API and you can connect with that. And that was really interesting.
518
00:41:23,620 --> 00:41:34,820
And if you want to make a rule in your company, don't connect our tenant to adult film sites.
519
00:41:34,820 --> 00:41:41,700
Then you have to know that people do that in the first place. And yeah, that why inventory is
520
00:41:41,700 --> 00:41:45,460
the absolutely first and important thing for governance.
521
00:41:45,460 --> 00:41:54,580
Yeah, that's a really funny thing to go. There was one guy who gets a little bit famous.
522
00:41:54,580 --> 00:42:08,740
And yeah, he, oh, what's the English word? He has also a connector. I have never used this word in
523
00:42:08,740 --> 00:42:20,100
English. I have to look at betting stuff. And they sell it. What they have used in these movies.
524
00:42:20,100 --> 00:42:29,860
So they have a marketing, funny marketing idea. Yeah, I think it's really interesting for what you can
525
00:42:29,860 --> 00:42:36,020
use these custom connectors. But the other thing with the darkroom, you say, and bring the lighter,
526
00:42:36,020 --> 00:42:46,580
okay, not all dark rooms like it in Kalon, but I say it's the visibility topic. And how can we start
527
00:42:46,580 --> 00:42:53,860
bringing visibility to the inventory? What's your tips? Yeah, that's a good question.
528
00:42:53,860 --> 00:42:58,900
For the last couple of years, I always say use the center of excellence data kit.
529
00:42:58,900 --> 00:43:06,900
Well, surprise. So now it's replicated now, which means we can use it still, but there won't be any
530
00:43:06,900 --> 00:43:14,820
updates. And yeah, now we have to think about how we do that. Now, the good thing is that we have a
531
00:43:14,820 --> 00:43:22,260
new inventory in the power platform admin center natively. So it's there and it's not bad. I usually
532
00:43:22,260 --> 00:43:28,020
don't say very good things about the PPEC power platform admin center. But this I really like,
533
00:43:28,020 --> 00:43:32,100
it's not bad. It's by the pure inventory. It shows you what is there.
534
00:43:32,100 --> 00:43:38,660
Compared to the center of excellence data kit, I use that inventory to combine it with my rules.
535
00:43:38,660 --> 00:43:44,500
So I have those tables with all my flows, environments, apps. And usually I build my flows on top of
536
00:43:44,500 --> 00:43:51,220
those tables to make like rules and alerts and stuff like that. It's not possible within the admin
537
00:43:51,220 --> 00:43:58,260
center now. But this is this inventory in the admin center. It's kind of fast because it doesn't
538
00:43:58,260 --> 00:44:04,980
use a flow together with data from all the tenant, but it it queries the API directly. And that means
539
00:44:08,340 --> 00:44:14,820
whereas with the center of excellence data kit, all the synch flows to run through you have the
540
00:44:14,820 --> 00:44:20,260
all time time we know from like 24 hours or something like that to get new set of data.
541
00:44:20,260 --> 00:44:26,260
If something changed, talk a while until you realize, hey, there's something new. Now this goes
542
00:44:26,260 --> 00:44:32,340
within 10, 15 minutes. The query against the API is very fast. It's very cool. It's not complete yet.
543
00:44:32,340 --> 00:44:36,900
A few things are missing like we don't have custom connectors in that and we don't have names of
544
00:44:36,900 --> 00:44:42,020
owners or planters I think for all this stuff. So it's still under development, but it's it's a very
545
00:44:42,020 --> 00:44:47,220
good start. And especially for smaller and medium sized companies, this is absolutely sufficient.
546
00:44:47,220 --> 00:44:53,860
So no need to build something more complex than that or to buy a governance product from
547
00:44:53,860 --> 00:45:02,500
from one of the vendors we have out there. So this is cool. If we don't want that or we want
548
00:45:02,500 --> 00:45:10,740
something that is a little bit more customized than the then the ppex thing, it's not that hard to
549
00:45:10,740 --> 00:45:16,660
build your own inventory with the power platform API. We have like three or four APIs that we need
550
00:45:16,660 --> 00:45:25,460
to build up something like a center of excellence clone or something like that. And with all the AI
551
00:45:25,460 --> 00:45:34,100
we have like a chat with the AI and whatever we have, it's kind of of doable to build your inventory
552
00:45:34,100 --> 00:45:40,980
even if you are not that deep into coding. So that kind of works good. And for all medium sized
553
00:45:40,980 --> 00:45:47,220
and bigger companies, that's what I do and I suggest all the time basically is build your own
554
00:45:47,220 --> 00:45:53,940
inventory based on your customized needs because if you don't have premium licenses and you have
555
00:45:53,940 --> 00:45:58,420
no one in your company that can build model-driven apps or custom connectors, then you don't need to
556
00:45:58,420 --> 00:46:05,940
monitor for a model-driven apps or custom connectors. Easy as that. So kind of depends on your
557
00:46:05,940 --> 00:46:14,980
on your needs. But two things, the ppex API inventory is very good now, not completely yet.
558
00:46:14,980 --> 00:46:21,780
And the other hand is build it yourself. And that is something that is necessary now because
559
00:46:21,780 --> 00:46:32,340
center of excellence data kit is well not that, but not a life too. And especially with all the
560
00:46:32,340 --> 00:46:40,740
agents that we have now, Copilot Studio agents, there is another toolkit, the Copilot Studio Kit.
561
00:46:40,740 --> 00:46:45,860
No, no, if you know about it, but that is quite nice for an inventory as well,
562
00:46:46,820 --> 00:46:56,180
especially an only for Copilot Studio. But then once again, for a good inventory, how to do that,
563
00:46:56,180 --> 00:47:01,140
how to start is use the kit set out there, maybe even use the use of center of excellence data kit,
564
00:47:01,140 --> 00:47:08,340
but have a backup plan because in the next 12 or 18 months, you won't use it anymore and build up
565
00:47:08,340 --> 00:47:14,340
your own thing, what you need. So once again, start with an, let's say, a project like inventory,
566
00:47:14,340 --> 00:47:19,620
switch on the lights in your environments and see what you have, see what you have to take care of,
567
00:47:19,620 --> 00:47:24,900
and then build up an inventory and governance, according to those needs that you have.
568
00:47:24,900 --> 00:47:31,300
Yeah, well, we have our inventory. I think the next step we have to talk about is life cycle
569
00:47:31,300 --> 00:47:34,740
management. Can you tell us a little bit how, how do you handle this?
570
00:47:34,740 --> 00:47:42,580
Yes, I can do that. Before that, I would say the first thing that I do after the inventory is more
571
00:47:42,580 --> 00:47:51,060
or less to get like a map. I split the tenant into different environments and see what do we need.
572
00:47:51,060 --> 00:47:54,740
I start, we do have the default environment and we don't get rid of that.
573
00:47:54,740 --> 00:48:01,780
Usually I restrict that very, very strongly, but then I have an environment for the IT department,
574
00:48:01,780 --> 00:48:10,900
administrators. So everything that is just for the IT department, plug-ins, professional code of
575
00:48:10,900 --> 00:48:16,260
that is thought in the IT department and I have a citizen developer or maker shared environment where
576
00:48:16,260 --> 00:48:21,220
they can all use their, put in their, their flows and apps and share what they have. Everyone
577
00:48:21,220 --> 00:48:25,700
get their personal developer environment where they can code all that for special and business
578
00:48:25,700 --> 00:48:32,180
critical projects. We have like environment with environments with deaf tests and production.
579
00:48:32,180 --> 00:48:40,820
And that is when it comes to life cycle management. First of all, I, yeah, I structure everything
580
00:48:40,820 --> 00:48:45,460
that I have into different parts because I, if I have to clean up and take care of what I,
581
00:48:45,460 --> 00:48:53,380
I don't want to clean up everything but just the parts that really need ALM. And ALM is an interesting
582
00:48:53,380 --> 00:49:00,900
topic for me right now because right now I'm in front of a new challenge for me personally and in my business life.
583
00:49:03,700 --> 00:49:13,540
I've usually used the, not get up the pipelines, part of the pipelines because they are quite good now
584
00:49:13,540 --> 00:49:20,980
and I do like the features that come with it and it's super cool for small and medium-sized companies
585
00:49:20,980 --> 00:49:27,940
to use those if you have premium licenses that is a condition to use them. To have like
586
00:49:28,820 --> 00:49:35,780
with chain of environments, deaf test, project, we develop, we test it and then you take it into production.
587
00:49:35,780 --> 00:49:41,060
And this, they work nice. They do have this GitHub integration now so you can have a single
588
00:49:41,060 --> 00:49:46,420
source of truth in the cloud and the internet so you don't rely on your own project and service
589
00:49:46,420 --> 00:49:53,700
and stuff. That is really cool. But if you start developing solutions that are more complex
590
00:49:53,700 --> 00:50:01,140
and bigger and you have custom plugins for example if you have multiple solutions that have to merge
591
00:50:01,140 --> 00:50:06,740
into one in the end. If you have multiple developers who work on different parts of an application or
592
00:50:06,740 --> 00:50:15,300
a solution and that you have to merge those results then it can get nasty. And for that,
593
00:50:15,300 --> 00:50:22,340
for usually what is used often is DevOps and I've never worked with DevOps in my life. Now I have a
594
00:50:22,340 --> 00:50:27,620
whole team they're working with DevOps and they ask me all kind of questions how to make it secure,
595
00:50:27,620 --> 00:50:33,380
how to make it more better and stuff like that. And so I have to speed up my learning right now,
596
00:50:33,380 --> 00:50:41,780
especially with DevOps, GitHub and ALM in general. And what I'm, what right now is on my table is
597
00:50:41,780 --> 00:50:49,620
how to make a database ALM experience that is kind of similar to GitHub. So that means that if I work
598
00:50:49,620 --> 00:50:56,500
at a, on one solution and one part or let's say one page or one side of an app and another
599
00:50:56,500 --> 00:51:01,300
developer is working on another side, now we are both finished with our work and we put it back
600
00:51:01,300 --> 00:51:09,300
into the main solution. How do we make sure that there are no errors coming up? Some one or
601
00:51:09,300 --> 00:51:14,820
something has to check if everything will work in the future in production and that is something that
602
00:51:15,780 --> 00:51:20,900
I have a good idea for that. It's a little bit tricky right now, but basically it's with the,
603
00:51:20,900 --> 00:51:27,460
with the connection to GitHub that is something, well, it's kind of, I realize I'm getting,
604
00:51:27,460 --> 00:51:32,900
I'm getting too deep right now. I'm getting too deep a little bit. It's very complex and not
605
00:51:32,900 --> 00:51:38,580
complex and not yet, you know, yet finished. But ALM, all platform pipelines are very good.
606
00:51:40,260 --> 00:51:49,940
Sometimes I've just smaller teams and it's not that time critical, you could even do the
607
00:51:49,940 --> 00:51:58,260
our platform SDK works really well if you want to work with VS Code. So there are many different
608
00:51:58,260 --> 00:52:05,460
options and opportunities how to work with ALM and that is a funny thing or an interesting thing
609
00:52:05,460 --> 00:52:09,860
actually because at the beginning we were talking about our platform as a local platform and even
610
00:52:09,860 --> 00:52:18,180
people without IT background could work with it. Now ALM and talking about DevOps, pipelines,
611
00:52:18,180 --> 00:52:24,500
GitHub, all of a sudden is on the other side of the end right? This is because citizen developer,
612
00:52:24,500 --> 00:52:32,500
I know they pretty much are a little bit overwhelmed when it comes to to GitHub and tokens and how
613
00:52:32,500 --> 00:52:38,980
this all works and how a pipeline works. And that is, and that shows how our professional,
614
00:52:38,980 --> 00:52:46,260
the platform is by now. But ALM is something that is very important for the business critical
615
00:52:46,260 --> 00:52:50,820
solutions for the important solutions but not for the everyday life solutions. Like the personal
616
00:52:50,820 --> 00:52:55,860
project, the things that you do, like the reminder flow that reminds me when I don't know,
617
00:52:55,860 --> 00:52:59,540
my boss sent me an email or something like that. That doesn't need ALM.
618
00:53:04,660 --> 00:53:10,820
I think we have the most of the big works now for, I think, yeah, all the buzzwords.
619
00:53:10,820 --> 00:53:15,140
Yeah, one is missing, one is missing, data loss prevention, I think.
620
00:53:15,140 --> 00:53:24,660
Yeah, we did this also. Yeah, I think a lot of companies handle data loss prevention, like
621
00:53:24,660 --> 00:53:34,180
one click on solution. So can you tell a little bit? So we have the big,
622
00:53:34,180 --> 00:53:40,340
the big ones about, you see data loss prevention? I don't know how many big words we have,
623
00:53:40,340 --> 00:53:45,780
but big five or something. I don't know. But yes, data loss prevention. Oh, that is the topic.
624
00:53:45,780 --> 00:53:53,940
And you're right. I think when you said many companies treat them as like
625
00:53:53,940 --> 00:54:01,540
one click solution, click, I switched it on. Now I'm fine. Many people or many companies do that,
626
00:54:01,540 --> 00:54:06,260
which is in case of powerful, I've owned kind of not enough. I don't want to say it's wrong,
627
00:54:06,260 --> 00:54:12,660
but it's not enough. But the name is misleading also. So data loss prevention, that sounds like a
628
00:54:12,660 --> 00:54:19,380
prevention or a policy that, yeah, it kind of prevents data loss. It's not wrong, but it's not what
629
00:54:19,380 --> 00:54:24,900
people expect because the word data loss prevention or DLP, the approvision is used in different
630
00:54:24,900 --> 00:54:31,140
contexts, the contexts for different things. We have Azure DLP's and N365 DLP's and Teams DLP's,
631
00:54:31,460 --> 00:54:35,940
and they all work in kind of the same way, but in the power platform, they work differently. Yeah.
632
00:54:35,940 --> 00:54:46,020
So data loss prevention policies are policies that define which connectors can be used in one solution.
633
00:54:46,020 --> 00:54:50,260
So that means can I build an app with a SharePoint connector and an Instagram connector?
634
00:54:50,260 --> 00:54:59,780
Usually yes, if I have my DLP set up to explicitly forbid that, then no. So it's more or less like
635
00:55:00,740 --> 00:55:04,900
like a regulation which connectors can be used together and which can be not.
636
00:55:04,900 --> 00:55:12,180
Additionally, which connectors are blocked overall. And those DLP's are for every environment. So I
637
00:55:12,180 --> 00:55:16,740
can build one for every environment. So I can, I have a little bit of granular, lary-tip
638
00:55:16,740 --> 00:55:21,060
to define which environment can be used for which connectors.
639
00:55:21,060 --> 00:55:29,140
This is nice. There are so many issues with it. I don't want to open that topic now.
640
00:55:29,140 --> 00:55:37,300
But I want to say when you use premium licenses and manage environments, you have the advanced
641
00:55:37,300 --> 00:55:44,820
connector policies. And these are really cool because they offer you a lot more freedom and
642
00:55:44,820 --> 00:55:51,860
granularity to really define what is allowed and what not. Once again, I don't want to get
643
00:55:51,860 --> 00:55:58,260
in too deep, but DLP's are one of the main pillars of governance and security absolutely.
644
00:55:58,260 --> 00:56:04,500
I think, now let's see. We have tenant security. There's tenant settings. Then you have the environments.
645
00:56:04,500 --> 00:56:12,180
You have DLP's, then roles and responsibilities. And I think that are the big four.
646
00:56:12,180 --> 00:56:19,860
So the basics. That is not everything governance and security is about. But those are the big four
647
00:56:19,860 --> 00:56:27,380
pillars that you should have at least a vague idea of what they are, what this does and how to use it.
648
00:56:28,340 --> 00:56:34,980
There are the tools that you need to have in your toolbox or in your pocket to make it a little
649
00:56:34,980 --> 00:56:43,860
bit more. And maybe the first one is the hidden one. That is the, let's say the knowledge that
650
00:56:43,860 --> 00:56:50,420
the default is always bad. And I don't mean default environment, but I mean default settings.
651
00:56:50,420 --> 00:56:56,260
That is something where I'm sometimes a little bit, I argue with Microsoft sometimes,
652
00:56:56,980 --> 00:57:01,700
because they deliver their products and their platforms. And especially with a local platform,
653
00:57:01,700 --> 00:57:07,780
like power platform, they want every user or almost every user to have access to use their product.
654
00:57:07,780 --> 00:57:12,580
Right. If you, if you develop a product and you give it to users, you want them to use it.
655
00:57:12,580 --> 00:57:20,180
The problem is if everyone has access, then all the people who don't know what they do or they
656
00:57:20,180 --> 00:57:25,060
don't want to do it, they also have access and that is the security gap. So access for everyone is
657
00:57:25,060 --> 00:57:32,980
just a no-no insecurity. And quite often people don't see this right now. I work a lot with dynamics
658
00:57:32,980 --> 00:57:38,900
customers and what dynamics customers do is they focus on dynamics. And they don't even know that
659
00:57:38,900 --> 00:57:44,980
if they have a dynamics license, there is a whole power platform underneath that is just as open as
660
00:57:44,980 --> 00:57:52,660
it is. No DLP, no environments, everyone has access and every administrator who is is like, oh my god,
661
00:57:52,660 --> 00:58:02,420
now, never. And that is something. So if you use Microsoft products, then even if it's a platform
662
00:58:02,420 --> 00:58:05,620
as a source and not a software as a source and there is a difference from the very beginning,
663
00:58:05,620 --> 00:58:12,260
you know that you have some effort to do in terms of setting up and securing it according to
664
00:58:12,260 --> 00:58:18,020
your business needs. It's not like, switch it on, everything is fine, like DLP, as you just mentioned,
665
00:58:18,740 --> 00:58:24,820
that is maybe the fifth key knowledge card for governance and security in the Microsoft universe.
666
00:58:24,820 --> 00:58:31,300
Microsoft gives you lots of great opportunities and cool tools, but you have to check them out and
667
00:58:31,300 --> 00:58:35,220
understand them and set them up according to your needs. Otherwise, it can get risky.
668
00:58:35,220 --> 00:58:44,980
Okay. I have in every session a rapid fire round, so I give a short question and you give a short
669
00:58:44,980 --> 00:58:50,900
answer. So, um, once sentence describe good power platform governance for you.
670
00:58:50,900 --> 00:59:02,820
Clarity and intention. Okay. The biggest mistake make us do on the power platform.
671
00:59:02,820 --> 00:59:08,340
Assuming that it's easy. The biggest mistake that IT does on the power platform?
672
00:59:08,340 --> 00:59:13,860
Ignoring it because it's just low code. What's the best coach in Cologne?
673
00:59:14,260 --> 00:59:26,020
Best coach. A coach. Oh, tricky. Zion. Okay. One governance topic that gets too far to a little attention.
674
00:59:26,020 --> 00:59:31,460
The whole government stop it gets to his attention.
675
00:59:31,460 --> 00:59:36,980
What did you think?
676
00:59:39,140 --> 00:59:43,700
Yeah, either one of the small words, shadow IT or blocked innovation.
677
00:59:43,700 --> 00:59:56,100
Ah. Um, shadow IT. Okay. If such a analysis comes to you and say, Michael,
678
00:59:56,100 --> 01:00:01,620
you get all the resources and money you need to make a feature on the power platform governance.
679
01:00:01,620 --> 01:00:05,940
What feature will you develop? I would decline that offer.
680
01:00:08,180 --> 01:00:15,140
And maybe, maybe I can give a reason for that because what I'm good at is working on specific
681
01:00:15,140 --> 01:00:20,340
solutions with people and finding out their needs and their setup. I help them
682
01:00:20,340 --> 01:00:25,220
become the experts for their own work environment and for their own work.
683
01:00:25,220 --> 01:00:31,700
And I'm not someone who develops features. Others can do that. Maybe I will take the resource and
684
01:00:31,700 --> 01:00:37,220
give that to someone else, but help them figure out what they want to do and why. That's, that's a point.
685
01:00:37,940 --> 01:00:44,980
Yeah. So, yeah. Um, then, uh, who shall I invite next and what questions should I ask?
686
01:00:44,980 --> 01:00:50,260
I have a good, good, good names, uh, a few good names, but I don't know who's
687
01:00:50,260 --> 01:00:56,980
been in your show recently. So I would have to check that. But, um, from the top of my head,
688
01:00:56,980 --> 01:01:03,060
I'm thinking about my brilliant UK colleagues, like Simon Owen or, um, Craig White, for example.
689
01:01:03,060 --> 01:01:11,220
Um, and someone who is a real power platform hero that I hardly see someone in the community is
690
01:01:11,220 --> 01:01:18,260
native to Adolf. Okay. And he is just great. He's from the UK as well. Um, never met him before, I think,
691
01:01:18,260 --> 01:01:25,540
but he is great. And I'm just living on his, um, on his blog post recently because he is really
692
01:01:25,540 --> 01:01:31,940
good at ALM. The whole, the whole guitar pipeline thingy. That is something where I learn a lot right now.
693
01:01:32,900 --> 01:01:39,460
Yeah. So, yeah. I can thank you so much for being here. I think this was an excellent talk.
694
01:01:39,460 --> 01:01:42,980
Yeah. We have a lot of, yeah, we have the big five.
695
01:01:42,980 --> 01:01:52,020
Uh, done. Yeah. And I think, yeah, this was, was really great. I think that we have a lot,
696
01:01:52,020 --> 01:01:57,700
a lot, we have good takeaways. And we have, uh, also, I think the reframing for the governance,
697
01:01:57,700 --> 01:02:04,580
it's really, really cool. And yeah, so thank you for, for staying here. The hour with me and on the
698
01:02:04,580 --> 01:02:11,060
podcast. Yeah. Thanks for having me. It was fun. Let's do it again sometime. Yeah. Yeah. I'm open.
699
01:02:11,060 --> 01:02:16,260
I'm open. So then we can do the security part. Oh, yeah. That's another story.
700
01:02:16,260 --> 01:02:26,260
[BLANK_AUDIO]
Founder of m365.fm, m365.show and m365con.net
Mirko Peters is a Microsoft 365 expert, content creator, and founder of m365.fm, a platform dedicated to sharing practical insights on modern workplace technologies. His work focuses on Microsoft 365 governance, security, collaboration, and real-world implementation strategies.
Through his podcast and written content, Mirko provides hands-on guidance for IT professionals, architects, and business leaders navigating the complexities of Microsoft 365. He is known for translating complex topics into clear, actionable advice, often highlighting common mistakes and overlooked risks in real-world environments.
With a strong emphasis on community contribution and knowledge sharing, Mirko is actively building a platform that connects experts, shares experiences, and helps organizations get the most out of their Microsoft 365 investments.
Uninvited Governance Evangelist
Michael Roth has been working as a consultant since 2011 and moved into the IT and Microsoft ecosystem around 2015. With a background in Microsoft 365, collaboration technologies, and organizational consulting, he developed a holistic perspective on how technology, governance, security, and people need to work together to create sustainable digital solutions.
Today, he specializes in Power Platform Governance, Administration, Security, and organizational enablement. His work focuses not only on the technical architecture of the platform, but also on establishing scalable governance models, security concepts, operational processes, and adoption strategies that empower organizations without losing control.
Coming from both a technical and consulting background, Michael combines strategic thinking with hands-on platform expertise. He is particularly passionate about enabling citizen development in a secure and sustainable way, helping organizations balance innovation, compliance, and real business value.