Detecting Low-Code Data Exposure: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.
Signals worth watching
- New Power Pages sites published or switched to public visibility.
- Changes to table permissions or site authentication settings.
- Apps or flows shared with "Everyone" or very large groups.
- Flows sending data to external connectors or HTTP endpoints.
- Data policy (DLP) changes in the Power Platform admin center.
- High volumes of anonymous requests to portal APIs.
Where the data lives
- Microsoft Purview audit log for Power Platform and Dataverse activity (Dataverse auditing must be enabled for data-level events).
- Power Platform admin center analytics and Managed Environments insights.
- Defender for Cloud Apps for Power Platform activity.
- Web application logs for Power Pages sites.
A starting approach
Monitor for data policy changes and environment setting changes in the unified audit log (Power Platform admin activities appear with the PowerPlatform or Dataverse workloads). Alert on any change to DLP policies, since weakening them can expose data through new connectors.
For Power Pages, enable diagnostic logging and review anonymous API access patterns for portals that expose Dataverse data.
Response
- Restrict access to the portal or app immediately (switch to private, disable the API).
- Review which data was reachable and whether it was accessed.
- Contact the app owner and correct permissions.
- Strengthen defaults with Managed Environments and data policies.
- 38 Million Records Exposed by Power Apps Portals (Aug 2021): Low-Code, High Risk Incident Teardowns
- How to Govern Power Platform Environments, Portals and Data Policies How-To & Hardening
- CIO Brief: Citizen Developers Need Guardrails CIO Briefings