Skip to main content

Power Platform Quick Assessment Tool

Open Source Risk Assessment Tool for Power Platform

With citizen developers' widespread adoption of Microsoft Power Platform, security teams are challenged to evaluate the risks and vulnerabilities created by these business users.

To assess your risk exposure, Kanopy Security developed "Power Platform Quick Assessment Tool", a lightweight, open-source assessment tool that you can easily run locally/on-premise.
Its purpose is to provide a quick and informative view of your Power Platform environments - development and production - and help you understand the size of your attack surface and prominent security issues.
Receive an easily shareable report with stats on your environments, components, and connectors and insights into vulnerabilities.

If you need help with this tool, please contact us at support@kanopysecurity.com.

Requirements

  • Python 3.9 or later - only needed if you don't use the Quick start below.
  • A web browser on the same machine - the tool opens a Microsoft sign-in page to authenticate.

The following Power Platform privileges are required for the tool to run:

  • Power Platform administrator (or a global administrator).
  • Explicit "system administrator" privileges for each of the environments that are scanned.

Quick start

The easiest way to run the tool is with uv. You don't need Python installed: uv uses a compatible Python if you have one, and downloads one if you don't.

Windows

Open PowerShell and install uv (already have uv? You can skip this step):

winget install --id=astral-sh.uv -e
No winget? Use the official installer instead
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Close PowerShell, open a new one, and run the tool:

uvx power-platform-security-assessment@latest

macOS

Open Terminal and install uv (already have uv? You can skip this step):

brew install uv
No Homebrew? Use the official installer instead
curl -LsSf https://astral.sh/uv/install.sh | sh

Close Terminal, open a new one, and run the tool:

uvx power-platform-security-assessment@latest

Linux

Install uv (already have uv? You can skip this step), then run the tool:

curl -LsSf https://astral.sh/uv/install.sh | sh
# open a new terminal, then:
uvx power-platform-security-assessment@latest

A browser window opens where you pick the Microsoft account to use. When the scan finishes, the report is saved as power_platform_scan_report.html in the folder you ran the command from.

@latest makes sure you run the newest version, even if you ran the tool before.

Other ways to install

If you prefer not to use uv, or your organization doesn't allow it, you can install the tool with pipx or pip (requires Python 3.9 or later). If your Python is older, install a current version from python.org.

On Windows, if python is not found, use py instead (e.g. py -m venv venv).

Using pipx

pipx installs the package in an isolated environment and makes it available globally (works on all platforms).

First, install pipx following the official installation guide, including the pipx ensurepath step, then open a new terminal.

Then install the tool:

pipx install power-platform-security-assessment

Using uv

# Create virtual environment
uv venv

# Install the package
uv pip install power-platform-security-assessment

Using pip

# Create virtual environment
python -m venv venv

# Activate virtual environment
source venv/bin/activate      # macOS/Linux
venv\Scripts\activate         # Windows (Command Prompt)
venv\Scripts\Activate.ps1     # Windows (PowerShell)

# Install the package
pip install power-platform-security-assessment

Usage

If installed with pipx

Run the security assessment tool directly:

power-platform-security-assessment

If installed with pip or uv

First activate your virtual environment, then run the tool:

# If installed with uv
source .venv/bin/activate      # macOS/Linux
.venv\Scripts\activate         # Windows (Command Prompt)
.venv\Scripts\Activate.ps1     # Windows (PowerShell)

# If installed with pip
source venv/bin/activate       # macOS/Linux
venv\Scripts\activate          # Windows (Command Prompt)
venv\Scripts\Activate.ps1      # Windows (PowerShell)

# Run the tool
power-platform-security-assessment

The tool opens a browser window where you pick (or sign in to) the Microsoft account to use, scans your environments, and saves the report as power_platform_scan_report.html in the current directory.

Available Arguments

  • --debug: Enables debug mode with additional logging.

License

This project is licensed under the MIT License. See the LICENSE file for details.

Metadata

Release files for power-platform-security-assessment 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for power-platform-security-assessment 0.3.0
File Size Uploaded
power_platform_security_assessment-0.3.0.tar.gz 34.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for power-platform-security-assessment 0.3.0
File Interpreter ABI Platform
power_platform_security_assessment-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 82.4 kB

Release files / power_platform_security_assessment-0.3.0.tar.gz

Download URL power_platform_security_assessment-0.3.0.tar.gz
Size 34.5 kB
Tags Source
SHA-256 checksum
How to use checksums
b0f84c3c6fa2475c62fcb7263c50b565a5a5e7d62fc784c2e5c47bc03723f0ec
BLAKE2b-256 checksum
How to use checksums
38d2880ffc01dbd28dd9fcd9a52f48386ea78fb532cff8dc6c036f9a5c632236
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.17

Release files / power_platform_security_assessment-0.3.0-py3-none-any.whl

Download URL power_platform_security_assessment-0.3.0-py3-none-any.whl
Size 47.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d227a0ac1a1ed69958dfb3aed136ec07ec6e05f189c80a5796c8a3914844b783
BLAKE2b-256 checksum
How to use checksums
74fd8f9eb8c7b19a400bad1e1b137ba5edc012c5fdfa3393efc3bda203669278
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.17

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page