How to Assign Custom Power Platform Security Roles with PowerShell
Question details
The user wants to know how to add a user to a Power Platform environment and assign a custom security role using PowerShell, specifically without utilizing a security group.

- Product
- Power Platform
- Device & OS
- not provided
- Scenario
- Automating user provisioning and custom environment role assignments in Power Platform.
- Observed behavior
- The standard PowerShell commands do not seem to readily support assigning custom Dataverse security roles, prompting the need for a specific script or alternative method.
Ensure you have the required System Administrator privileges in the target Power Platform environment and have the Power Apps Administration PowerShell modules installed.
Use Power Platform Admin Center for Custom Roles
Because native PowerShell commands are limited to built-in roles, using the Power Platform Admin Center is the recommended and most reliable method for assigning custom Dataverse roles.
The Set-AdminPowerAppEnvironmentRoleAssignment command is generally limited to built-in environment roles (like Environment Maker and Environment Admin). For custom security roles, direct assignment through the admin interface or Dataverse role-assignment tools is required.
Log in to the Power Platform Admin Center and click on 'Environments' in the left navigation pane.
Select the specific environment where you need to assign the role, then click on 'Settings' on the top ribbon.
Expand the 'Users + permissions' menu and select 'Users'.
Select the target user from the list, click on 'Manage security roles', check the box next to your custom Dataverse security role, and click 'Save'.

Assign Built-in Roles using PowerShell
If you can utilize standard built-in roles instead of custom ones, you can successfully automate the assignment using PowerShell.
Draft IT Documentation Easily with WPS Office
Managing Power Platform roles requires specific Microsoft admin tools, but when it comes to documenting your IT procedures, drafting PowerShell scripts, or managing deployment schedules, WPS Office offers a powerful, lightweight, and completely free alternative to Microsoft Office.
- 1. Download and Install: Visit the official WPS website to download and install the free suite on your computer.
- 2. Document Admin Procedures: Open WPS Writer to create step-by-step IT guidelines, PowerShell command references, and architecture documents.
- 3. Share Securely: Export your finished documentation to PDF format to share securely with your IT team and stakeholders.

Frequently Asked Questions
Can I use Set-AdminPowerAppEnvironmentRoleAssignment for custom Dataverse roles?
No, this specific PowerShell command is generally restricted to assigning built-in environment roles such as Environment Maker and Environment Admin. Custom roles require alternative methods.
Do I have to use a security group to assign roles in Power Platform?
No, while security groups are recommended for scalable administration, you can assign custom security roles directly to individual users via the Power Platform Admin Center.
Where can I find advanced PowerShell scripts for Power Platform administration?
The Microsoft Power Platform Community is an excellent resource for discovering custom REST API scripts and community-developed modules to handle tasks beyond standard cmdlets.




