Skip to main content

Microsoft Power Platform Enterprise Guide (2026)

Power Apps + Power Automate + Power BI + Copilot Studio + Power Pages with governance baked in — from EPC Group, the firm whose founder authored Power BI’s Microsoft Press book and led the original Project Crescent beta team.

Microsoft Power Platform is the low-code platform combining Power Apps, Power Automate, Power BI, Copilot Studio, and Power Pages. Enterprises adopt it at scale but typically without governance from day one — producing app sprawl, license waste, security gaps, and audit findings. EPC Group delivers enterprise-grade Power Platform adoption with a Center of Excellence, environment strategy, DLP policy stack, ALM, license-reclaim cadence, and Copilot Studio security framework baked in from week one.

Microsoft Power Platform — Power Apps, Power Automate, Power BI, Copilot Studio, Power Pages — is Microsoft's low-code platform. Enterprises adopt at scale but typically without governance, producing app sprawl, license waste, and security gaps. EPC Group delivers enterprise adoption with a Center of Excellence, DLP, ALM, and Copilot Studio security baked in from day one.

Key Facts

  • Power Platform = five products: Power Apps (canvas + model-driven), Power Automate (cloud flows + RPA), Power BI (semantic models + Fabric integration), Copilot Studio (AI agents), Power Pages (low-code customer portals).
  • Microsoft's Power Platform Center of Excellence (CoE) Starter Kit is the inventory and operations foundation EPC Group installs in week one of every CoE engagement.
  • License waste in mature Power Platform deployments typically runs $200,000 to $800,000 per year in a 10,000-employee enterprise — enough to fund the entire CoE program from reclaim.
  • Default environment sprawl is the largest single source of audit risk — every Microsoft 365 licensed user is a maker in the default environment unless policy says otherwise.
  • Copilot Studio agents grounded on over-permissioned SharePoint content re-expose data the user could technically see but never knew existed — a governance imperative addressed through Microsoft Purview sensitivity labels enforced before grounding.
  • DLP policies classify connectors as Business or Non-Business per environment and are the single most consequential governance lever on the platform.
  • EPC Group has delivered 1,500+ Power BI deployments and our founder authored the Microsoft Press Power BI book — Power Platform is in our DNA, not an adjacency.
  • The EPC Group Power Platform Accelerator runs five phases — Assess, CoE Foundation, ALM and Governance, Maker Enablement, Operate — anchored to The EPC Group Lifecycle.

The five Power Platform pillars, explained for the enterprise

Most Microsoft marketing covers Power Platform pillar-by-pillar in isolation. The enterprise lens is different — you need to understand what each pillar is, how enterprises actually adopt it at scale, and where governance has to be designed in from day one to prevent the patterns that produce audit findings two years later.

Power Apps

Canvas + model-driven apps

What it is

Power Apps is the low-code application surface. Canvas apps are pixel-precise, mobile-first form and workflow interfaces sitting on top of any connector (Dataverse, SQL, SharePoint, Salesforce, custom REST APIs). Model-driven apps are Dataverse-native, generate their UI from the data model, and behave like a configured Dynamics 365 experience — relationship-driven, business-process-flow capable, and security-role aware.

Enterprise adoption pattern

Power Apps has quietly replaced legacy InfoPath, Microsoft Access front-ends, departmental Lotus Notes apps, and most one-off Excel macros built between 1998 and 2020. Enterprises typically run 200 to 2,000 active Power Apps across 30 to 100 environments by year three of serious adoption — a scale where governance stops being optional.

Governance watch-out

Canvas apps are easy to build and easy to abandon. Without a Center of Excellence catalog plus an environment strategy, you will find 40% of apps have a single user, 25% have no users in the trailing 90 days, and a long tail of orphaned apps holding open per-app licenses no one is auditing.

Power Automate

Cloud flows + desktop flows (RPA)

What it is

Power Automate is the workflow and robotic process automation engine. Cloud flows are server-side, triggered by connector events (a SharePoint item created, a Dataverse row updated, a button pressed, a schedule, an HTTP webhook, an Outlook email arriving). Desktop flows run on a Windows machine — attended (with a signed-in user) or unattended (headless, on a Power Automate machine group) — and are the modern successor to legacy WinAutomation, UiPath-style, and Blue Prism robotic automations.

Enterprise adoption pattern

Power Automate adoption typically follows three waves — a citizen-developer wave automating personal Outlook and SharePoint chores, an IT-led wave consolidating point integrations the integration team never had time for, and an RPA wave migrating legacy bots off of UiPath or Automation Anywhere onto unattended desktop flows for total cost reasons.

Governance watch-out

Unattended desktop flows running under a service account with broad permissions are a security risk no one models until an audit. Cloud flows using HTTP-with-Azure-AD against your own APIs need API-permissions review. And shared connection references mean one connector credential, used by 90 flows, becomes a single point of catastrophic failure when it expires.

Power BI

Semantic model + reports + Fabric integration

What it is

Power BI is the enterprise analytics surface — semantic models (formerly datasets), reports, dashboards, paginated reports, and the operational integration with Microsoft Fabric (OneLake, Direct Lake mode, Lakehouses, Warehouses, Real-Time Intelligence). Power BI workspaces are governed by Premium capacity (or Fabric F-SKU capacity) for enterprise scale, Pro for departmental publishing, and PPU (Premium Per User) for individual workloads that need Premium features without committing to capacity.

Enterprise adoption pattern

EPC Group has delivered 1,500+ Power BI deployments and our founder Errin O'Connor was on the original Power BI Beta Team (Project Crescent) and authored the Microsoft Press Power BI book. The enterprise pattern in 2026 is certified semantic models exposed to Microsoft 365 Copilot and Copilot Studio agents for AI grounding, paired with row-level security and Microsoft Purview sensitivity labels propagated end-to-end.

Governance watch-out

Power BI is the workload where governance pays back fastest. Uncertified semantic models duplicate metric definitions, drift apart, and turn every executive review into a meeting about whose number is right. The fix is a CoE-managed certified-dataset program, RLS that is tested before deploy, and a workspace topology that separates development, test, and production.

Copilot Studio

AI agents + custom Copilots + Microsoft 365 Copilot extensions

What it is

Copilot Studio is the low-code authoring environment for AI agents — formerly Power Virtual Agents, repositioned in 2024 and substantially expanded through 2025 and 2026. You build conversational topics, ground agents on enterprise knowledge sources (SharePoint sites, Dataverse, public web, custom connectors), define actions (Power Automate flows, Dataverse plug-ins, REST APIs), and deploy to Teams, Microsoft 365 Copilot, a website, or as an agent invoked from a Power App.

Enterprise adoption pattern

The pattern that wins is Copilot Studio agents grounded on sensitivity-labelled SharePoint content, scoped to a single business unit per agent, and audit-logged through Microsoft Purview. HR policy assistants, IT help-desk triage agents, sales playbook coaches, and field-service knowledge agents are the common first-three production use cases.

Governance watch-out

Grounding an agent on a SharePoint site that contains over-permissioned content means the agent will quote, summarize, and re-expose anything the user has access to — including content the user never knew they could see. The governance imperative is Microsoft Purview labels enforced before grounding, not after.

Power Pages

Low-code customer-facing portals

What it is

Power Pages (formerly Power Apps Portals, originally Adxstudio Portals from the Dynamics era) is the low-code platform for external-facing websites and authenticated customer portals. Pages binds to Dataverse for content and identity, supports anonymous and authenticated experiences (Azure AD B2C, custom identity providers, Microsoft Entra External ID), and is the right surface for partner portals, member portals, citizen-services portals, and patient-facing experiences that need to read and write to the same Dataverse tables your internal Power Apps and Dynamics 365 use.

Enterprise adoption pattern

Government agencies running citizen-services portals, healthcare networks running patient-engagement portals, financial institutions running broker-dealer self-service, and manufacturers running supplier and dealer portals — these are the four anchor patterns. Power Pages wins versus a custom React build when the data already lives in Dataverse and the team owns Power Platform skills.

Governance watch-out

Power Pages publishes to the public internet. Table-level and column-level permissions in Dataverse, web-role-based access controls in Pages, web application firewall integration, and a security review before go-live are non-negotiable. We have seen Power Pages sites shipped without WAF protection and without a documented permission model — both are remediable, but both should never reach production.

The sprawl problem — what happens without governance from day one

Every enterprise Power Platform deployment we have inherited from another firm — and many we have stood up ourselves before our governance frameworks matured — shares the same six symptoms. They are not failures of the platform. They are failures of governance design.

Shadow apps in the default environment

Root cause

The default environment is provisioned to every Microsoft 365 licensed user. Without policy, everyone with a license can build, share, and run Power Apps and flows in the default environment — there is no organizational visibility and no governance hook.

Cost when unfixed

Auditors cannot find what they cannot see. Sensitive data flows through unmanaged connectors. Apps cannot be migrated to managed environments without coordinated maker outreach.

Untracked Power Automate flows

Root cause

Flows are owned by the maker who built them, run on their connection references, and break the moment that maker leaves the company. No central inventory, no ownership succession, no business-criticality tagging.

Cost when unfixed

A finance close stalls because a flow built three years ago by a developer who left the company in 2024 stopped triggering. Hours of incident response. Sometimes days of manual workaround.

License waste — per-app and per-user

Root cause

Per-app licenses get assigned to onboarded employees and never reclaimed when they change roles or leave. Per-user licenses get assigned to pilot makers who never built anything and were forgotten.

Cost when unfixed

In a 10,000-employee enterprise, license waste typically runs $200,000 to $800,000 per year — enough to fund the entire CoE program from reclaimed budget.

No ALM — production changes made in production

Root cause

Most maker journeys never include managed solutions or pipelines. Apps and flows live as unmanaged components in production environments. Changes are made directly to production with no source control, no dev-test-prod separation, no rollback story.

Cost when unfixed

A Friday afternoon change to a critical app breaks for half the user base. There is no version to roll back to. The maker rebuilds from memory. The next audit finding writes itself.

Abandoned apps blocking environments

Root cause

Environments accumulate apps, flows, and connection references nobody owns. The cleanup work to delete is greater than the cost of doing nothing — so nothing happens.

Cost when unfixed

Environment storage thresholds are hit. New projects cannot provision into the right environments. The platform becomes a roach motel — workloads check in but never leave.

Copilot Studio agents grounded on over-permissioned content

Root cause

A maker builds a Copilot Studio agent grounded on a SharePoint site that contains content the user can technically read but never knew existed. The agent surfaces, quotes, and summarizes that content on demand.

Cost when unfixed

A confidential M&A document is summarized in a chat response. A salary band is quoted in plain English. A risk register is exposed to a user who should never have had cause to look for it.

The Power Platform Center of Excellence — the antidote to sprawl

A Power Platform Center of Excellence is not a downloaded kit or a Wednesday-afternoon working group. It is an operating model. EPC Group’s CoE engagement combines the Microsoft Power Platform CoE Starter Kit with the opinions, integrations, and operating disciplines that turn the kit into a working enterprise function — anchored to the Govern stage of The EPC Group Lifecycle.

Microsoft CoE Starter Kit

What it does — The Microsoft-published Center of Excellence Starter Kit is a Power Platform solution that inventories every environment, app, flow, maker, and connection reference across the tenant. It provides admin apps, audit-log analytics, communications kits, and a nurture program for makers.

EPC Group deliverable — EPC Group installs, configures, customizes, and operationalizes the CoE Starter Kit — including the inventory pipelines, admin command center, the developer compliance flow, and the audit-log telemetry. We extend it to integrate with your CMDB, ServiceNow, and Microsoft Purview so the CoE is the single source of truth for the platform.

Environment strategy

What it does — An environment strategy decides how many environments exist, who can create in which, what the dev-test-prod topology looks like, and whether business units get dedicated environments. Decisions made here are hard to reverse — environments cannot be merged.

EPC Group deliverable — Our reference environment topology — default locked down, per-business-unit dedicated production environments, one shared dev plus one shared test, named sandbox environments for accelerated prototyping, and a citizen-developer training environment per region. Documented, codified into a managed CoE solution, and operated through Power Platform Pipelines.

Data Loss Prevention (DLP) policies

What it does — DLP policies classify every connector as Business, Non-Business, or Blocked, and prevent flows or apps from spanning the Business and Non-Business categories. DLP is enforced at the environment level (with tenant-level baseline policies) and is the single most consequential governance lever on the platform.

EPC Group deliverable — EPC Group designs the DLP policy stack — a tenant-wide baseline that blocks the connectors no one should ever use (anonymous social, unsanctioned consumer storage, unapproved AI providers), business-unit overlays for vertical-specific needs, and a sensitivity-aware variant tied to Microsoft Purview labels. Policies are exception-managed through a CoE intake.

Application Lifecycle Management (ALM) and Power Platform Pipelines

What it does — ALM is the discipline of managed solutions, source-controlled customizations, dev-test-prod pipelines, and approval-gated promotion. Power Platform Pipelines is the native Microsoft surface; Azure DevOps Pipelines and GitHub Actions remain the enterprise standard for complex deployments.

EPC Group deliverable — EPC Group stands up the pipeline — managed solutions for everything that reaches production, source control on every solution component, automated solution checker and PR-gated validation, deployment to test and production through Power Platform Pipelines or Azure DevOps, and rollback procedures documented before the first release.

License audit and reclaim

What it does — License audit identifies inactive makers consuming per-user licenses, unused per-app licenses assigned to people who never opened the app, Copilot Studio capacity allocated to agents that never went live, and Power Automate process licenses sitting against deactivated flows.

EPC Group deliverable — A quarterly license-true-up engagement — EPC Group runs the inventory, segments makers by activity, surfaces reclaimable licenses with evidence, and produces a board-ready report that the CFO can sign. Typical first-year reclaim funds the entire CoE engagement.

Champion program and named makers

What it does — A champion program recruits, trains, certifies, and supports a named cohort of makers across the business. Citizen developers without an enablement structure become a liability — citizen developers inside a champion program become the platform's growth engine.

EPC Group deliverable — EPC Group builds the champion curriculum, runs the certification gate, instruments the champion telemetry (apps shipped, flows automated, value tracked), and operates the champion community of practice. Pairs with the Enable stage of the EPC Group Lifecycle and our data literacy and adoption practice.

Copilot Studio and AI agents — the governance imperative

Copilot Studio is the workload where governance most has to be designed in, not bolted on. An agent grounded on a SharePoint site will quote, summarize, and re-expose anything the grounded content contains — including content the requesting user could technically read but never knew existed. The risk is not the agent. The risk is the over-permissioned content the agent is grounded on.

EPC Group’s Copilot Studio governance framework operationalizes five controls. Sensitivity-aware grounding — Microsoft Purview labels enforced before grounding, so Confidential content is excluded from agents that should not surface it. Purview labels propagated to outputs — so the sensitivity of the source content survives into the agent response and any downstream sharing. Audit logging — every agent interaction is captured in the unified audit log and surfaced to the SOC and compliance teams. Conversational topic discipline — agents are scoped to a single business domain, with topics reviewed before deploy. Response governance — content moderation, response quality testing, and named human escalation paths for any response the agent cannot confidently produce.

This framework is one of the reasons EPC Group is a Microsoft Solutions Partner for Data and AI as well as Business Applications — Copilot Studio sits at the intersection of both, and governance has to span both. Compliance frameworks supported include HIPAA, SOC 2, FedRAMP, FINRA, CMMC, GxP.

Power Platform licensing patterns — which SKU for which workload

Power Platform licensing is consequential and consequential decisions deserve a model. EPC Group’s license audit and reclaim practice has saved Fortune 500 clients millions in license waste — the foundation is matching the right SKU to the right workload from the start.

Power Apps — per-app

License model — Per-app license — entitles a user to run two custom apps and access one Power Pages site. Priced per user per app. Best when individual departments need a small number of apps with broad user reach.

When to use — A field-service inspection app rolled out to 800 inspectors, used twice a week. Per-app is cheaper than per-user at this concentration.

Power Apps — per-user

License model — Per-user license — entitles a user to run unlimited custom apps and access unlimited Power Pages sites. Best when the same maker community is building and using many apps.

When to use — A 2,500-person operations team where every individual touches 6 to 10 Power Apps across their workday. Per-user is cheaper at this concentration.

Power Automate — per-flow

License model — Per-flow license (sometimes called per-process) — entitles a specific flow to be used by unlimited users, regardless of their individual Power Automate license. Best for high-leverage workflows touching the entire workforce.

When to use — A new-hire onboarding flow that orchestrates 14 downstream provisioning steps and is triggered for every new joiner. One license, unlimited triggers.

Power Automate — per-user

License model — Per-user license — entitles a single user to run unlimited cloud flows. Standard for power users and makers building broad personal automations.

When to use — A finance analyst running 60 personal cloud flows, including attended desktop flows reconciling spreadsheets. Per-user is the right model.

Copilot Studio capacity

License model — Copilot Studio capacity is purchased in message packs (10,000 message capacity per pack as of mid-2026 reference, verify current SKUs). Capacity is consumed by agent interactions across all deployed surfaces (Teams, Microsoft 365 Copilot, websites, embedded).

When to use — Forecast agent message volume conservatively — pilots routinely exceed plan once usage compounds. Buy a baseline capacity, monitor through the Copilot Studio analytics, and true up monthly.

Power Pages

License model — Anonymous-user capacity (per 100 anonymous monthly users) and authenticated-user capacity (per authenticated monthly user) are separate SKUs. Authenticated users include B2C identities, B2B guests, and Entra External ID identities.

When to use — A patient-engagement portal authenticating 50,000 patients per month is licensed differently from a marketing landing page seeing 200,000 anonymous monthly visitors. Model both axes during architecture.

Power BI — Pro, PPU, Premium, Fabric F-SKU

License model — Power BI Pro is the standard publishing license. Premium Per User adds Premium features to individual users. Premium Capacity (P-SKU, being deprecated through 2025–2026 in favor of Fabric) and Fabric F-SKU capacity are the enterprise-scale models. Direct Lake mode against OneLake requires a Fabric F-SKU.

When to use — PPU for an analytics team of 30 needing XMLA endpoints without buying capacity. Fabric F-SKU for any deployment integrating Lakehouses, Warehouses, or Real-Time Intelligence.

Microsoft SKU names, capacities, and pricing change. The structural decisions above are durable — the precise SKU you select against each model should be verified through Microsoft licensing as of your purchase date. EPC Group’s license audit engagement includes a current-SKU review and a roadmap to consolidate.

The EPC Group Power Platform Accelerator — five phases

The Accelerator is the fixed-fee, senior-architect-led engagement that takes an enterprise from Power Platform sprawl to governed Power Platform productivity. It is anchored to The EPC Group Lifecycle and runs in five sequential phases.

1

Phase 1 — Assess

2–4 weeks

Tenant inventory (all environments, apps, flows, agents, makers, connection references), license audit, DLP policy audit, risk-ranked findings, and a costed roadmap for the remaining four phases.

Lifecycle stage: Assess

2

Phase 2 — CoE Foundation

4–8 weeks

CoE Starter Kit deployed and extended, environment topology stood up, DLP policy stack implemented (tenant baseline plus business-unit overlays), CoE admin command center live, communications kit launched to all existing makers.

Lifecycle stage: Govern

3

Phase 3 — ALM and Governance

6–10 weeks

Power Platform Pipelines (or Azure DevOps) stood up, managed-solution standard ratified, all production workloads moved to managed solutions, solution checker integrated into PR gates, Copilot Studio governance framework (grounding policies, Purview integration, audit logging) operational.

Lifecycle stage: Modernize

4

Phase 4 — Maker Enablement

Continuous from week 12 onward

Champion program launched with a recruited and certified cohort, training curriculum live (canvas, model-driven, Power Automate, Copilot Studio), nurture programs auto-running through the CoE Starter Kit, community of practice operating, value-tracking on shipped workloads.

Lifecycle stage: Enable

5

Phase 5 — Operate

Steady-state, with quarterly accelerators

24/7 managed CoE operations — inventory continuously refreshed, DLP exception management, quarterly license true-up, capacity-management for Copilot Studio and Fabric, semi-annual platform-architecture review, named senior-architect escalation for incidents and audits.

Lifecycle stage: Operate

Pricing band

The EPC Group Power Platform Accelerator runs $200,000 to $700,000 depending on user count, workload depth, the number of business units in scope, the size of the existing Power Platform footprint, and the regulatory environment.

Common bands — a 2,500-user enterprise with a clean tenant and one business unit sponsor lands near the $200,000 floor. A 25,000-user enterprise with multi-tenant complexity, an inherited deployment of several thousand apps and flows, and HIPAA or FINRA regulatory scope lands near the $700,000 ceiling. Most engagements land in the $325,000 to $475,000 band.

Quarterly license-audit accelerators (steady-state) typically run $40,000 to $80,000 and often pay for themselves three to ten times over through license reclaim. Managed CoE operations are priced to the platform footprint.

Why EPC Group on Power Platform

Nearly three decades of Microsoft consulting leadership, the original Power BI beta team, the Microsoft Press Power BI book, 1,500+ Power BI deployments, 70+ Fortune 500 clients, and 216+ M&A tenant consolidations spanning 1.83 million users. Power Platform is in our DNA.

11,000+
Microsoft engagements
1,500+
Power BI deployments
70+
Fortune 500 served
1.83 million
M&A users migrated

Microsoft Press author — Power BI

Founder Errin O'Connor authored the Microsoft Press Power BI book and was on the original Power BI Beta Team — Project Crescent. Nearly three decades of Microsoft consulting leadership inform every Power Platform engagement we run.

1,500+ Power BI deployments

Power BI is the anchor workload of the Power Platform for most enterprises. EPC Group has delivered 1,500+ Power BI deployments across Fortune 500, regulated industries, and global mid-market — including the semantic-model certification programs that make AI grounding safe.

Microsoft Solutions Partner — 6 designations

EPC Group holds 6 Microsoft Solutions Partner designations spanning Data and AI, Modern Work, Security, Infrastructure, Digital and App Innovation, and Business Applications — the full surface area of the Power Platform stack.

70+ Fortune 500 enterprises served

EPC Group has served 70+ Fortune 500 enterprises and led 216+ M&A tenant consolidations spanning 1.83 million users — including the Power Platform consolidations that surface when two CoEs collide post-deal.

Related EPC Group Microsoft hubs

Frequently asked questions

What is the difference between Power Apps, Power Automate, and Power BI — and when do I use each?

Power Apps is for building applications — canvas apps for pixel-precise mobile and web experiences, model-driven apps for Dataverse-native business applications. Power Automate is for workflows and robotic process automation — cloud flows for server-side workflows and integrations, desktop flows for attended and unattended RPA. Power BI is for analytics — semantic models, reports, dashboards, and the operational integration with Microsoft Fabric. The simplest decision frame is interface (Power Apps) versus orchestration (Power Automate) versus insight (Power BI). Most enterprise scenarios use all three — a Power App for data capture, a Power Automate flow for downstream orchestration, and a Power BI report for the operational view. The Power Platform thesis is that they are designed to compose, not to be picked individually.

When do I need Copilot Studio — and how does it differ from Microsoft 365 Copilot?

Microsoft 365 Copilot is the off-the-shelf productivity Copilot embedded in Word, Excel, PowerPoint, Outlook, Teams, and the broader M365 surface. It is licensed per user and grounded on the user's own data through the Microsoft Graph. Copilot Studio is the low-code authoring environment for building custom agents — your own Copilots — grounded on enterprise knowledge sources you choose, with conversational topics, actions, and a defined scope. You need Copilot Studio when an off-the-shelf experience does not cover the use case — an HR policy assistant grounded on your handbook, an IT triage agent grounded on your knowledge base, a sales playbook coach grounded on your win-loss library, or a field-service knowledge agent that can also kick off a Dataverse update. The right pattern in 2026 is M365 Copilot for individual productivity, Copilot Studio agents for scoped business processes, and both surfaced through the Microsoft 365 Copilot chat where it makes sense.

Is the Microsoft CoE Starter Kit enough on its own — or do we still need a consulting engagement?

The CoE Starter Kit is excellent — it is the foundation EPC Group installs in week one of every Power Platform Center of Excellence engagement. It is not enough on its own for an enterprise tenant for three reasons. First, the Starter Kit is an inventory and operations toolkit — it does not make the governance decisions for you. Decisions about environment topology, DLP policy stack, ALM standards, license-reclaim cadence, and Copilot Studio guardrails are decisions, not downloads. Second, the Starter Kit ships unopinionated; an enterprise needs an opinion. Third, operationalizing the Starter Kit — integrating it with your CMDB, your ServiceNow, your Purview, your audit-log pipeline, your DLP exception process — is consulting work, not configuration work. EPC Group brings the opinions, the integrations, and the operating model. Microsoft brings the kit.

How should we structure DLP policies for Power Platform connectors?

The recommended baseline is a three-tier stack. Tier one is a tenant-wide DLP policy that blocks connectors that should never be used anywhere in the enterprise — anonymous social, unsanctioned consumer storage, unapproved AI providers, custom connectors not yet through security review. Tier two is environment-scoped policies that classify approved connectors as Business or Non-Business per environment — production environments are strict, sandbox environments are permissive but isolated. Tier three is sensitivity-aware overlays that integrate with Microsoft Purview labels so that flows handling Highly Confidential data cannot use connectors below a defined trust threshold. Exceptions are managed through the CoE intake — a maker requests, the CoE reviews, and either grants a scoped exception or designs an alternative. Without this structure, DLP becomes either too loose to govern anything or too strict to ship anything.

When does Power Pages make sense versus a SharePoint site or a custom React build?

Power Pages wins when three things are true — your data already lives in Dataverse or you are about to put it there, you need authenticated external access with the security model that includes Azure AD B2C or Entra External ID, and you want to leverage the Power Platform skills your team already has. SharePoint sites are the right surface for internal collaboration and content publishing — they are not the right surface for external customer, partner, or citizen-facing portals. A custom React build is the right answer when the experience needs to be a marketing site at internet scale, when there is heavy non-Dataverse data integration, or when the design fidelity Power Pages can deliver is not enough. We have shipped patient-engagement portals, partner self-service portals, supplier portals, and citizen-services portals on Power Pages — and we have also told clients the right answer was Next.js on Vercel when the Power Pages fit was wrong. Pick on fit, not on platform allegiance.

What are the ALM and Power Platform Pipelines best practices for an enterprise?

The non-negotiables — every workload that reaches production is in a managed solution, no exceptions; source control on every solution component (Git, with the solution exported and unpacked on every commit); a dev-test-prod environment topology where production environments are deploy-only and no maker authoring happens there; Power Platform Pipelines or Azure DevOps Pipelines orchestrating promotion with approval gates at each stage; the Power Platform Solution Checker run on every pull request with critical findings blocking merge; rollback procedures documented and rehearsed before the first production deploy; and Copilot Studio agents under the same managed-solution discipline as Power Apps and Power Automate flows. Where teams typically fall down is the gap between dev and test — they have a dev environment, they deploy directly to production, they call that ALM. It is not. Test exists to validate that what worked in dev still works against production-shaped configuration before users see it.

What is the realistic return on a Power Platform license audit?

In a 10,000-employee enterprise with a mature Power Platform deployment — 100+ active makers, 500+ active apps, 2,000+ active flows — license waste typically runs $200,000 to $800,000 per year. The reclaim splits roughly evenly across per-app licenses assigned to people who no longer use the app, per-user licenses assigned to pilot makers who never built anything, Copilot Studio capacity allocated to agents that never went live, and Power Automate process licenses sitting against deactivated flows. The first audit usually finds the largest reclaim because nothing has been cleaned up. Subsequent quarterly audits find smaller reclaims but prevent the waste from accumulating again. The pattern is the same one EPC Group has seen across 70+ Fortune 500 engagements — the first audit funds the entire CoE program from reclaimed budget, and the steady-state quarterly audits keep the platform in net-positive ROI.

How do Power Platform and Microsoft Fabric integrate — and what does it mean for our analytics architecture?

Microsoft Fabric is the unified analytics platform — OneLake as the single multi-cloud storage tier, Lakehouses and Warehouses for structured analytics, Real-Time Intelligence for streaming, Data Factory for orchestration, and Power BI as the native consumption surface. Power Platform integrates with Fabric at multiple points. Dataverse data is replicated to OneLake through the Dataverse Link to Fabric feature, with no ETL required — Dataverse becomes a first-class analytical source. Power BI semantic models running in Direct Lake mode against OneLake deliver Power BI Premium performance without the import refresh cycle. Copilot Studio agents can be grounded on Fabric Lakehouse content for analytics-aware Q and A. And Power Automate flows can trigger Fabric pipelines and read from Fabric Warehouses for operational-analytical loops. The architectural shift this drives is that the analytics estate (Fabric) and the operational estate (Dataverse, Power Apps, Power Automate) are no longer separate worlds — they share a storage tier (OneLake) and a semantic layer (Power BI). EPC Group designs both sides of that integration through our Power BI, Fabric, and Power Platform CoE practices working together.

Ready to govern your Power Platform?

Book a strategy call with an EPC Group senior architect. We will walk your current Power Platform footprint, identify the highest-leverage governance moves, and scope the right Accelerator engagement for your tenant.

contact@epcgroup.net · 888-381-9725 · www.epcgroup.net

AI assistant — not human