How to Manage Access for Power Automate and SharePoint
Question details
An administrator needs to securely share support responsibilities for Power Apps, Power Automate flows, and SharePoint sites with a team of engineers without compromising security.

- Product
- Microsoft Power Platform and SharePoint
- Device & OS
- not provided
- Scenario
- Delegating administrative and support access for automated workflows and document solutions to approximately ten engineers.
- Observed behavior
- The administrator is considering configuring multiple MFA phone numbers on a single shared account or using an Entra ID group to manage access.
Ensure you have Global Administrator or Privileged Role Administrator rights in Microsoft Entra ID (formerly Azure AD) to create groups and assign roles.
Implement Group-Based Access via Microsoft Entra ID
Using an Entra ID group is the most secure and scalable method for granting multiple engineers access without sharing credentials.
Avoid sharing a single service account and adding multiple MFA phone numbers. This violates security best practices, compromises the principle of least privilege, and prevents accurate auditing of administrative actions. Instead, group-based access combined with delegated environment roles ensures secure, manageable administration.
Log in to the Microsoft Entra admin center. Navigate to 'Groups' > 'All groups', click 'New group', select 'Security' as the group type, and name it appropriately for your engineering team.
In the group's properties, go to 'Members', click 'Add members', search for the ten engineers who need support access, and add them to the security group.
Navigate to the Power Platform Admin Center. Select your target environment, click 'Settings' > 'Users + permissions' > 'Security roles', and assign the appropriate role (such as Environment Admin or System Customizer) directly to the Entra ID security group.

Configure Co-ownership for Specific Power Automate Flows
If you only need engineers to support and edit specific flows rather than having full environment access, you can add the Entra ID group as a co-owner.
Assign SharePoint Permissions via Groups
Grant the engineering team access to the necessary SharePoint sites used by your document solutions.
Manage Your Documents Seamlessly with WPS Office
While configuring complex Power Platform permissions requires the Microsoft ecosystem, you can handle your daily document creation, editing, and sharing needs efficiently with WPS Office. It provides a lightweight, intuitive, and highly compatible alternative for individuals and teams managing everyday office files.
- 1. Download the Application: Visit the official WPS Office website to download the free installation package for your operating system.
- 2. Install and Launch: Run the installer, complete the quick setup process, and open the application.
- 3. Open Microsoft Formats: Drag and drop your existing .docx, .xlsx, and .pptx files into the workspace to edit them immediately without losing formatting.

Frequently Asked Questions
Is it safe to use a shared service account with multiple MFA phone numbers?
No. Sharing credentials or relying on a single service account with multiple MFA methods violates the principle of least privilege. It prevents accurate auditing of who performed specific actions and significantly increases the risk of a security breach.
Can I assign SharePoint site permissions directly to an Entra ID group?
Yes. You can add an Entra ID security group directly to your SharePoint site's Owners, Members, or Visitors group to manage access for multiple users at once, bypassing the need to manage individual user permissions.
What is the recommended way to get Microsoft Power Platform support for complex setups?
For advanced questions regarding service-account design, least-privilege administration, and environment roles, it is highly recommended to consult the official Microsoft Power Platform Community. Specialists there can provide environment-specific guidance.




