← Evidence

Governance · Power Platform

Microsoft changed the Power Platform governance playbook. Has your tenant caught up?

Microsoft's governance tools haven't changed much. How it says to use them has. The environment is now the governance boundary, rules are enforced centrally, and makers are routed away from the default environment from the start.

Risk & governanceOctober 20266 min read
Microsoft changed the Power Platform governance playbook. Has your tenant caught up?

Key takeaways

  • Microsoft's April 2026 Power Platform Administration & Governance whitepaper puts Managed Environments, environment routing and environment groups at the center of the governance model.
  • Environment groups now enforce rules across every environment in the group. Local administrators can't override them. A governance zone is no longer something you describe in a deck; the platform enforces it.
  • The Power Platform admin center has taken over the core jobs of the CoE Starter Kit, which Microsoft no longer actively maintains.
  • Governance now covers agents: identity through Microsoft Entra Agent ID, connector control through advanced connector policies, and inventory across the tenant.
  • Our recommendation: govern by what something can do, not by how many people use it.
Managed Environments, environment routing and environment groups have been arriving for several years. Microsoft's April 2026 Power Platform Administration & Governance whitepaper now puts them at the center: the environment is the governance boundary, rules are enforced centrally, and makers are routed away from the default environment from the start. If your tenant still relies mainly on data policies, a crowded default environment and custom governance processes, your operating model is out of date.

Zones can now be enforced

Most Power Platform teams have used governance zones for years. What's different is that the platform now enforces them. Environment groups let administrators organize Managed Environments and apply common rules across them. When a rule is published at group level, that setting is locked in every environment in the group. Local environment administrators can't override it.
Microsoft currently documents 24 environment group rules, covering app and agent sharing, backup retention, solution checker enforcement, generative AI settings and usage insights, among others. That makes a three-zone model straightforward to run:
  • Zone 1: Personal productivity. Makers work in personal developer environments created through routing. Sharing and connector access are tightly controlled.
  • Zone 2: Team development. Trained makers build for teams or departments, with IT oversight, stronger controls and a defined route into managed deployment.
  • Zone 3: Enterprise development. Business-critical solutions, built and run with the strongest security, application lifecycle and compliance controls.

The names matter less than the principle. A zone used to be something you described in a deck. Now it's something the platform enforces.

The admin center replaces the CoE Starter Kit

Microsoft no longer actively maintains the CoE Starter Kit. It still works, but its core jobs (Inventory, Usage, Monitor and Actions) now live in the Power Platform admin center. You don't need to switch the kit off tomorrow. But design your future state around the admin center, not the kit.
For the backlog already sitting in the default environment, Microsoft's Move apps from the default environment feature can move eligible canvas apps and SharePoint forms into Managed Environments. Two caveats. The release plan listed general availability for September 2026, but the documentation still labels it preview. And during preview it only moves apps and forms that don't use shared connectors or resources. Administrators still have to add users to the destination environment and reshare each app.
It helps with cleanup. It doesn't replace governance.

Governance now covers agents

Inventory shows agents alongside apps and flows across the tenant. Connector inventory, in preview, shows which connectors and operations each of them uses. Knowing an agent exists is the start. Administrators also need to know what it can access, what it can do and who is responsible for it.
  • Identity. New Copilot Studio agents automatically receive a Microsoft Entra Agent ID, so agents fall under normal identity governance rather than sitting outside it. Existing agents on app registrations keep working; Microsoft says they will be migrated later.
  • Connectors. Advanced connector policies replace the Business, Non-Business and Blocked classification with an allowlist. Administrators can control certified connectors action by action, and block entire MCP servers.
  • The gap. Custom and HTTP connectors aren't yet covered by advanced connector policies, so classic data policies still have a role during the transition.

Where agents belong

Agents fit the same zone model. A personal agent used by its maker is one thing. An agent shared across a department is another. An agent that serves customers or takes business actions on its own is a third.
We'd add one criterion: autonomy. An agent that takes consequential actions without a person approving each step warrants enterprise controls, even if only a few people use it. That's Relatio's recommendation, not a Microsoft rule. Usage count is a measure of exposure; autonomy is a measure of consequence, and consequence is what governance exists to catch.

Govern by what something can do, not by how many people use it.

Three things to do now

1. Turn on environment routing

If makers still build in the shared default environment, start here. Routing gives each maker a personal developer environment instead, which can be managed and placed in an environment group with the right rules. Governance then happens at the point of creation, not in a cleanup project later.

2. Name who approves a move between zones

The platform can enforce a rule. It can't decide who accepts the risk of moving a solution from personal to team or enterprise use. Name a person or role, not a committee or "IT", and agree what evidence they need before they approve.

3. Decide who acts on what governance finds

Inventory tells you what exists, where it lives and who owns it. Someone still has to act on it.
  • When an owner leaves, who takes on the orphaned agent?
  • When an app uses a connector that no longer fits policy, who contacts the maker?
  • When an agent moves from personal productivity into a business process, who decides its governance has to change?
These are organizational questions. No tool answers them for you.

The platform enforces. You decide.

The platform can now enforce more of your governance model than it ever could. You still have to decide what that model is, and who owns the decisions within it. If your governance model predates environment routing, environment groups or the current agent controls, it's time to review it.

Sources

  1. 1
    Microsoft, April 2026. Power Platform Administration & Governance whitepaper. Used for: the environment-as-boundary governance model and the centrality of Managed Environments, environment routing and environment groups.

    learn.microsoft.com/power-platform/admin/governance-whitepaper

  2. 2
    Microsoft Learn. Environment groups. Used for: group-level rule enforcement, local administrator override behavior, and the 24 documented environment group rules.

    learn.microsoft.com/power-platform/admin/environment-groups

  3. 3
    Microsoft Learn, January 2026. Implement a zoned governance strategy. Used for: the three-zone model (personal productivity, team development, enterprise development).

    learn.microsoft.com/power-platform/guidance/adoption/zoned-governance

  4. 4
    Microsoft Learn, May 2026. Develop a tenant environment strategy. Used for: environment routing and the move away from the shared default environment.

    learn.microsoft.com/power-platform/guidance/adoption/environment-strategy

  5. 5
    Microsoft Learn. CoE Starter Kit transition. Used for: Microsoft no longer actively maintaining the CoE Starter Kit, and its core jobs moving into the Power Platform admin center.

    learn.microsoft.com/power-platform/guidance/coe/starter-kit-transition

  6. 6
    Microsoft Learn, 2026 release wave 1. Move apps out of the default environment. Used for: the move feature's scope, preview status and its caveats (shared connectors, resharing, user assignment).

    learn.microsoft.com/power-platform/admin/move-apps-default-environment

  7. 7
    Microsoft Security Blog, May 1, 2026. Microsoft Agent 365, now generally available. Used for: agent identity governance context.

    microsoft.com/security/blog

  8. 8
    Microsoft Learn. Manage Entra Agent IDs. Used for: automatic Entra Agent ID assignment for new Copilot Studio agents and the planned migration of existing agents.

    learn.microsoft.com/entra/agent-id

  9. 9
    Power Platform Blog, June 2026. What's new in Power Platform: June 2026. Used for: connector inventory (preview) and agent inventory across the tenant.

    powerplatform.microsoft.com/blog

  10. 10
    Microsoft Learn, 2026 release wave 1. Automate governance with Agentic Center of Enablement. Used for: advanced connector policies, action-level control, MCP server blocking, and the custom/HTTP connector gap.

    learn.microsoft.com/power-platform/admin/agentic-coe

Start a conversation

One question, no obligation.

What are you trying to decide? If Relatio isn't the right fit, we'll say so.