logo
search
Security Policy Errors

How to Stop Automatic Security Role Assignment in Power Platform

Aamir Naveed AkramAamir Naveed Akram Sep 28, 2026 869 views

Question details

The user wants to stop new users from automatically receiving the Environment Maker and Basic User security roles in a Microsoft Power Platform default environment.

How to Stop Automatic Security Role Assignment in Power Platform
Product
Microsoft Power Platform
Device & OS
not provided
Scenario
Managing user access and security role restrictions within the Power Platform default environment.
Observed behavior
New users are automatically assigned the Environment Maker and Basic User roles upon entering the default environment.
Before you start

Ensure you have global administrator or Power Platform administrator privileges before attempting to review or modify tenant-level environment security settings.

Solution 1Recommended

Review Tenant Settings and Consult Administration

Since automatic role assignments in the default environment are often governed by built-in tenant behavior or specific Entra ID configurations, reaching out to your administrator or the official community is the necessary approach.

By design, Microsoft automatically grants the Environment Maker and Basic User roles to all licensed users in the default environment so they can create personal productivity apps. Disabling this requires advanced administrative intervention.

1
Contact Power Platform Administrator

Reach out to your organization's IT or Power Platform administrator to request a review of the current default user access policies.

2
Check Power Platform Admin Center

Administrators should access the Power Platform admin center to verify if any automated governance flows or Entra ID (Azure AD) security group assignments are aggressively auto-assigning these roles.

3
Post in Power Platform Community

If you are the administrator and the default behavior persists against your configuration, post your specific environment setup details in the official Microsoft Power Platform Community Forum for expert guidance.

Review Tenant Settings and Consult Administration
Default Environment Limitations: Microsoft strictly controls the default environment's base permissions. Standard methods of removing roles from users may be automatically reverted by the system unless properly configured via PowerShell cmdlets or tenant-level governance policies.
Free Microsoft Office alternative

Simplify Your Document Workflow with WPS Office

Managing complex administrative settings and permissions in Microsoft environments can be overwhelming. If you are looking for a free, lightweight, and user-friendly alternative for your everyday document, spreadsheet, and presentation tasks, try WPS Office. It provides an intuitive experience without the hassle of complicated tenant setups.

Fully compatible with Microsoft Office formats like .docx, .xlsx, and .pptx.Lightweight application that runs smoothly even on older devices.Familiar user interface requiring zero learning curve for new users.Completely free alternative to expensive subscription-based office suites.
QA img-9

Frequently Asked Questions

Why do users automatically get roles in the Power Platform default environment?

By design, Microsoft grants all licensed users in a tenant the Environment Maker and Basic User roles in the default environment so they have the baseline permissions to create and run personal productivity apps and automated flows.

Can I completely delete the default environment in Power Platform?

No, the default environment cannot be deleted, backed up, or restored. It is a permanent fixture tied directly to your Microsoft 365 tenant.

How do I restrict who can create apps in the default environment?

Power Platform administrators can use specific PowerShell cmdlets or manage tenant-level settings in the Power Platform Admin Center to restrict maker capabilities, effectively overriding the default Environment Maker role assignment for designated users.