Power Platform Quick Assessment Tool
Open Source Risk Assessment Tool for Power Platform
With citizen developers' widespread adoption of Microsoft Power Platform, security teams are challenged to evaluate the risks and vulnerabilities created by these business users.
To assess your risk exposure, Kanopy Security developed "Power Platform Quick Assessment Tool", a lightweight, open-source assessment tool that you can
easily run locally/on-premise.
Its purpose is to provide a quick and informative view of your Power Platform
environments - development and production - and help you understand the size of your attack surface and prominent
security issues.
Receive an easily shareable report with stats on your environments, components, and connectors and insights into
vulnerabilities.
If you need help with this tool, please contact us at support@kanopysecurity.com.
Requirements
- Python 3.9 or later - only needed if you don't use the Quick start below.
- A web browser on the same machine - the tool opens a Microsoft sign-in page to authenticate.
The following Power Platform privileges are required for the tool to run:
- Power Platform administrator (or a global administrator).
- Explicit "system administrator" privileges for each of the environments that are scanned.
Quick start
The easiest way to run the tool is with uv. You don't need Python installed: uv uses a compatible Python if you have one, and downloads one if you don't.
Windows
Open PowerShell and install uv (already have uv? You can skip this step):
winget install --id=astral-sh.uv -e
No winget? Use the official installer instead
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
Close PowerShell, open a new one, and run the tool:
uvx power-platform-security-assessment@latest
macOS
Open Terminal and install uv (already have uv? You can skip this step):
brew install uv
No Homebrew? Use the official installer instead
curl -LsSf https://astral.sh/uv/install.sh | sh
Close Terminal, open a new one, and run the tool:
uvx power-platform-security-assessment@latest
Linux
Install uv (already have uv? You can skip this step), then run the tool:
curl -LsSf https://astral.sh/uv/install.sh | sh
# open a new terminal, then:
uvx power-platform-security-assessment@latest
A browser window opens where you pick the Microsoft account to use. When the scan finishes, the report is saved
as power_platform_scan_report.html in the folder you ran the command from.
@latestmakes sure you run the newest version, even if you ran the tool before.
Other ways to install
If you prefer not to use uv, or your organization doesn't allow it, you can install the tool with pipx or pip (requires Python 3.9 or later). If your Python is older, install a current version from python.org.
On Windows, if
pythonis not found, usepyinstead (e.g.py -m venv venv).
Using pipx
pipx installs the package in an isolated environment and makes it available globally (works on all platforms).
First, install pipx following the official installation guide,
including the pipx ensurepath step, then open a new terminal.
Then install the tool:
pipx install power-platform-security-assessment
Using uv
# Create virtual environment
uv venv
# Install the package
uv pip install power-platform-security-assessment
Using pip
# Create virtual environment
python -m venv venv
# Activate virtual environment
source venv/bin/activate # macOS/Linux
venv\Scripts\activate # Windows (Command Prompt)
venv\Scripts\Activate.ps1 # Windows (PowerShell)
# Install the package
pip install power-platform-security-assessment
Usage
If installed with pipx
Run the security assessment tool directly:
power-platform-security-assessment
If installed with pip or uv
First activate your virtual environment, then run the tool:
# If installed with uv
source .venv/bin/activate # macOS/Linux
.venv\Scripts\activate # Windows (Command Prompt)
.venv\Scripts\Activate.ps1 # Windows (PowerShell)
# If installed with pip
source venv/bin/activate # macOS/Linux
venv\Scripts\activate # Windows (Command Prompt)
venv\Scripts\Activate.ps1 # Windows (PowerShell)
# Run the tool
power-platform-security-assessment
The tool opens a browser window where you pick (or sign in to) the Microsoft account to use, scans your environments,
and saves the report as power_platform_scan_report.html in the current directory.
Available Arguments
--debug: Enables debug mode with additional logging.
License
This project is licensed under the MIT License. See the LICENSE file for details.
Metadata
Release files for power-platform-security-assessment 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| power_platform_security_assessment-0.3.0.tar.gz | 34.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| power_platform_security_assessment-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 82.4 kB
Release files / power_platform_security_assessment-0.3.0.tar.gz
| Download URL | power_platform_security_assessment-0.3.0.tar.gz |
|---|---|
| Size | 34.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b0f84c3c6fa2475c62fcb7263c50b565a5a5e7d62fc784c2e5c47bc03723f0ec
|
|
BLAKE2b-256 checksum How to use checksums |
38d2880ffc01dbd28dd9fcd9a52f48386ea78fb532cff8dc6c036f9a5c632236
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.17
|
Release files / power_platform_security_assessment-0.3.0-py3-none-any.whl
| Download URL | power_platform_security_assessment-0.3.0-py3-none-any.whl |
|---|---|
| Size | 47.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d227a0ac1a1ed69958dfb3aed136ec07ec6e05f189c80a5796c8a3914844b783
|
|
BLAKE2b-256 checksum How to use checksums |
74fd8f9eb8c7b19a400bad1e1b137ba5edc012c5fdfa3393efc3bda203669278
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.10.17
|