Find the security gaps in your Power Platform tenant before someone else does.

PowerToolBox scans Power Automate flows across your environments, flags hardcoded secrets, DLP bypasses, orphaned flows, and exfiltration risks, then scores each flow so you know what to fix first.

Download for Windows See how it works

Placeholder for a screenshot of the PowerToolBox audit results grid, listing flows with their findings and risk scores.
The audit results grid. Placeholder — real screenshot coming.

What it finds

Twenty rules, each one mapped to a specific way a flow can hurt you. The full rule reference, with fixes, lives in the docs.

Security

  • SEC-01 Hardcoded Secret Finds credentials and secrets embedded directly in a flow definition.
  • CON-04 Tenant Isolation Bypass Flags flows that authenticate to external services with a raw authorization header, stepping around tenant isolation.
  • SEC-04 Direct Connection Usage Catches flows using direct connections instead of managed connection references.
  • RPA-01 PAD Not Patched Flags desktop flows, whose machine patch level has to be verified by hand.

Exfiltration

  • EXF-02 Email Exfiltration Finds flows that send email to domains outside your organization.
  • EXF-03 HTTP Exfiltration Risk Finds flows that post data to external URLs over HTTP.
  • EXF-04 Anonymous File Sharing Catches creation of anonymous sharing links anyone can open.

Governance

  • DLP-01 Child Flow DLP Bypass Detects DLP policies bypassed by moving work into a child flow.
  • OWN-01 Orphaned Flow Finds flows with no valid owner, which break silently when the original account is gone.
  • OWN-03 Admin Account Ownership Flags production flows owned by admin-pattern accounts.
  • HYG-02 Default Environment Usage Lists flows living in the Default environment, where governance is weakest.
  • PERM-01 Flow Over-Sharing Finds flows shared more broadly than they need to be.
  • CON-02 Premium Connector Unlicensed Flags premium connectors in use without a matching license.
  • DLP-04 Unclassified Connector Finds connectors that no DLP policy classifies at all.

Operational

  • RES-01 Missing Try-Catch Pattern Finds flows with no try-catch error handling, so failures pass unnoticed.
  • RES-03 Missing Error Notification Finds flows that never notify anyone when a run fails.
  • PER-10 Auto-Shutdown Risk Flags flows whose repeated failures can trigger automatic shutdown.

Compliance

  • LOG-03 Run History Retention Prompts a check of how long run history is kept.

AI

  • AI-03 AI Connector Unclassified Finds AI connectors missing from DLP classification.
  • AI-04 Copilot Excessive Privilege Flags Copilot agents wired to high-privilege connectors.

How it works

  1. Connect — sign in with Microsoft Entra ID, certificate or client secret. Credentials stay on your machine.
  2. Discover — enumerate environments and flows through the Power Platform Admin APIs and Dataverse.
  3. Audit — twenty rules inspect each flow definition: actions, connectors, and inputs.
  4. Report — export JSON, CSV, Markdown, HTML, or Excel with a 0–100 risk score per flow.

Read the details, including what the scores mean →

Screenshots

Placeholder for a screenshot of the audit results grid.
Audit results grid (placeholder)
Placeholder for a screenshot of the exported HTML report.
Exported HTML report (placeholder)
Placeholder for a screenshot of the connection setup wizard.
Connection setup (placeholder)

These are marked placeholders. They get replaced with real captures of the app before launch marketing.

  • Windows 10/11
  • Self-contained .NET 8 executable
  • Runs locally — no audit data leaves your machine
  • Free while in early access

Latest news

All news →