Tenant Isolation, Cross-Tenant B2B & DLP Policy Chains
Tenant Isolation, B2B Federation & DLP Hierarchies
By default, Power Platform connectors allow authenticated users to connect to other Microsoft Entra tenants if they possess guest credentials. In highly regulated enterprises, this introduces the risk of cross-tenant exfiltration.
Tenant Isolation Architecture
Enabling Tenant Isolation closes all inbound and outbound cross-tenant connections at the cloud gateway. Connections to external tenants are rejected unless an explicit Tenant Isolation Rule is registered for a trusted partner tenant ID:
- Inbound Rule: Allows users or apps from an external partner tenant to connect to this tenant's Dataverse and Power Platform resources.
- Outbound Rule: Allows makers in this tenant to create connections targeting resources located inside the partner tenant.
Granular Connector Action Control & Endpoint Filtering
Standard Data Loss Prevention (DLP) classifies connectors into Business, Non-Business, and Blocked. Modern DLP introduces sub-connector controls:
- Connector Action Control: Disables specific hazardous actions within an allowed connector (e.g., allowing
Send an email (V2)in Office 365 Outlook while blockingForward an email). - HTTP Endpoint Filtering: Restricts generic HTTP connectors strictly to an approved whitelist of enterprise corporate URLs and API domains (e.g.,
https://api.contoso.com/*).
Enable Tenant Isolation to block unauthorized data sharing across corporate boundaries while configuring explicit inbound/outbound rules for approved partner tenants.