Microsoft 365Incident TeardownsRetrospectives

38 Million Records Exposed by Power Apps Portals (Aug 2021): Low-Code, High Risk

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations, including American Airlines, Ford, J.B. Hunt, Indiana's COVID-19 contact tracing program, New York City's Metropolitan Transportation Authority and Microsoft itself.

What was exposed

Data included COVID-19 vaccination appointments, contact tracing information, Social Security numbers, employee IDs, names and email addresses — depending on the portal.

How it happened

Power Apps portals (now Power Pages) let organizations build public-facing websites on top of Microsoft Dataverse data. Portals could expose data through OData APIs. At the time, table permissions — which control who can see data through those APIs — were not enabled by default for lists. If a builder enabled the OData feed without configuring table permissions, data meant for authenticated users or internal use was accessible anonymously.

Microsoft's response

Microsoft changed the default so table permissions were enforced, released a tool to help customers check their portals, and notified affected customers.

Why it mattered

Low-code platforms let business users build applications quickly — often without security review. The exposure wasn't a vulnerability; it was a configuration that was easy to get wrong and hard to notice.

Lessons in hindsight

  • Citizen developers need guard rails. Defaults matter more when builders aren't security experts.
  • Inventory low-code apps, especially public-facing ones.
  • Data loss prevention policies in Power Platform can restrict which connectors and data sources apps can combine.
  • Security reviews for public portals should be mandatory.

In hindsight

Power Platform governance became a significant part of Microsoft 365 security, and the same concerns have grown with Copilot Studio agents built by business users.

power apps data exposurePower Apps portals exposure2021

More on this story