Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CoE Starter Kit - Feature]: Update Kit to respond to new Power Platform Admin Role PIM feature #8016

Closed
Jenefer-Monroe opened this issue Apr 8, 2024 · 5 comments
Assignees
Labels
coe-starter-kit CoE Starter Kit issues enhancement New feature or request

Comments

@Jenefer-Monroe
Copy link
Collaborator

Jenefer-Monroe commented Apr 8, 2024

Regarding the upcoming change to the Power Platform Admin Role to be dynamic - (aka PPAdmin PIM feature)

The basics of that change is that people in these admin roles will no longer be added to all envts as Sys Admin SR.
This will break our kit as it exists in that new envts will get inventoried, as the role still works to get information via things like the Power Platform admin pages and connectors, however when you try to access the data in those envts via the Dataverse connector, it will not have access.

The feature:

Manage admin roles with Microsoft Entra Privileged Identity Management:

The limitation:

Known Limitations
image

The existing workaround

There are existing steps to elevate the user and hence be added.

However these are not in a form that the kit can consume yet. The product team is actively working to unblock us but we are not yet able to do this elevation for you.

Describe the solution you'd like

Product team adding to the Power Platform V2 connector at which point we will consume.

@Jenefer-Monroe Jenefer-Monroe added enhancement New feature or request coe-starter-kit CoE Starter Kit issues labels Apr 8, 2024
@Jenefer-Monroe Jenefer-Monroe self-assigned this Apr 8, 2024
@RajeevPentyala RajeevPentyala moved this to Todo ✏️ in CoE Starter Kit Apr 8, 2024
@Jenefer-Monroe Jenefer-Monroe moved this from Todo ✏️ to Blocked ❌ in CoE Starter Kit Apr 8, 2024
@Jenefer-Monroe
Copy link
Collaborator Author

Have a workaround documented : #8119
But cannot ship with the kit until the connector and its action are GA, including the sovereign clouds

@Jenefer-Monroe
Copy link
Collaborator Author

Due to the intermittent failures seen with this call, we've written this into the Driver flow such that it will retry and then let you know about the failure, without stopping the Driver flow from completing.
This way you can ensure you have permissions in needed environments.

image
image

@Jenefer-Monroe
Copy link
Collaborator Author

Jenefer-Monroe commented Jul 6, 2024

@Jenefer-Monroe
Copy link
Collaborator Author

An early release of the August bits are available for testing.
Please see our Preview Builds

Please test for us! But do not install these in your production environment but rather in a test envt to get us feedback.

Here are the August release candidate solutions.
Core 4.33.14
Gov 3.24.1
Nurture 3.18.1

And the PBIT files
Production CoE Dashboard August 2024
Governance Dashboard August 2024

It contains all the changes targeting August: https://github.com/orgs/microsoft/projects/195/views/59

Including these two very impactful changes:
#8016 - Update Kit to respond to new Power Platform Admin Role PIM feature
#8482 - Integrate new audit log methodology into the kit for API reduction. Please see issue for setup instructions.

@Jenefer-Monroe
Copy link
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
coe-starter-kit CoE Starter Kit issues enhancement New feature or request
Projects
Status: Done
Development

No branches or pull requests

1 participant