|
| 1 | +--- |
| 2 | +title: "Details about different security roles required to administer Power Apps portals with specific actions. | MicrosoftDocs" |
| 3 | +description: "Learn about the available security roles, admin roles, and other permissions that are required to administer Power Apps portals." |
| 4 | +author: neerajnandwana-msft |
| 5 | +ms.service: powerapps |
| 6 | +ms.topic: conceptual |
| 7 | +ms.custom: |
| 8 | +ms.date: 11/03/2020 |
| 9 | +ms.author: nenandw |
| 10 | +ms.reviewer: tapanm |
| 11 | +--- |
| 12 | + |
| 13 | +# Roles required for portal administration |
| 14 | + |
| 15 | +Power Apps portals has different kinds of administrative tasks that can be done by the members of different roles. The admin and security roles required to do these tasks vary depending on the impact area. |
| 16 | + |
| 17 | +For example, some tasks may require the user to be a member of admin roles in [Microsoft 365](https://docs.microsoft.com/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide&preserve-view=true), and others may need membership to security roles in [Power Platform environment](https://docs.microsoft.com/power-platform/admin/database-security). |
| 18 | + |
| 19 | +In this article, you'll learn about the roles and permissions required to do different administrative tasks for portals. |
| 20 | + |
| 21 | +## Required roles and permissions |
| 22 | + |
| 23 | +The following table lists different administrative tasks for portals, and the roles required to do that task. The listed tasks can be done through the membership of the roles listed as required. |
| 24 | + |
| 25 | +| Task | Required roles | |
| 26 | +| - | - | |
| 27 | +| [Create portal](..\create-portal.md) | Any one of the following roles and permissions: <ul> <li> [Permissions to register an app](https://docs.microsoft.com/azure/active-directory/develop/howto-create-service-principal-portal#permissions-required-for-registering-an-app) in the Azure Active Directory, and any one of the following roles with **Access Mode** set to **Read-Write** under **Client Access License (CAL) Information** for the [user record](https://docs.microsoft.com/power-platform/admin/create-users-assign-online-security-roles#create-a-read-write-user-account) in Power Platform environment: <ul> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> </ul> **Note**: Creating a portal is allowed with these roles only if Global administrator hasn't [disabled portal creation](../create-portal.md#disable-portal-creation-in-a-tenant) in a tenant.</li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 28 | +| [Download public key of a portal](get-public-key.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 29 | +| [Import metadata translation](import-metadata-translation.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 30 | +| [View portal error logs](view-portal-error-log.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 31 | +| [Reset a portal](reset-portal.md) | [Portal app owner](#portal-app-owner) and any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 32 | +| [Convert a portal from trial to production](portal-lifecycle.md#convert-a-portal-from-trial-to-production) | [Portal app owner](#portal-app-owner) and any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 33 | +| [Convert an existing portal to a capacity-based model](portal-lifecycle.md#convert-an-existing-portal-to-a-capacity-based-model) | [Portal app owner](#portal-app-owner) and any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 34 | +| [Add a custom ___domain name](add-custom-___domain.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 35 | +| [Connect to a Common Data Service environment using a portal](manage-auth-key.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 36 | +| [Change the Dynamics 365 instance of a portal](change-dynamics-instance.md) | Any one of the following roles: <ul> <li> [Portal owner](#portal-owner) </li> <li> [System customizer](#system-customizer) </li> <li> [System administrator](#system-administrator) </li> <li> [Dynamics 365 administrator](#dynamics-365-administrator) </li> <li> [Power Platform administrator](#power-platform-administrator) </li> <li> [Global administrator](#global-administrator) </li> </ul> | |
| 37 | + |
| 38 | +## Manage membership of the required roles |
| 39 | + |
| 40 | +This section explains about managing the membership of the required roles listed above for different kinds of administrative tasks in Power Apps portals. |
| 41 | + |
| 42 | +### Portal app owner |
| 43 | + |
| 44 | +Portal app owner is a user who owns [portal application registration](https://docs.microsoft.com/azure/active-directory/develop/quickstart-register-ap) in the [Azure portal](https://portal.azure.com) |
| 45 | + |
| 46 | +To add an app owner for the portal app in Azure portal: |
| 47 | + |
| 48 | +1. Sign in to the [Azure portal](https://portal.azure.com). |
| 49 | + |
| 50 | +1. Search for and select **Azure Active Directory**. |
| 51 | + |
| 52 | +1. Under **Manage**, select **App registrations**. |
| 53 | + |
| 54 | +1. Select the Power Apps portals app from the list of available applications. |
| 55 | + |
| 56 | +1. Under **Manage**, select **Owners**. |
| 57 | + |
| 58 | +1. Select **Add owners**. |
| 59 | + |
| 60 | +1. Select a user. |
| 61 | + |
| 62 | +1. Select **Select**. |
| 63 | + |
| 64 | +The user is added as an owner of the portal app. |
| 65 | + |
| 66 | +### Portal owner |
| 67 | + |
| 68 | +Portal owner is the user that created the Power Apps portal. This role can't be managed, and can't be changed. |
| 69 | + |
| 70 | +### System customizer |
| 71 | + |
| 72 | +System customizer is a Power Platform security role. This role has full permissions to customize Power Platform environment. |
| 73 | + |
| 74 | +To assign a user the System administrator Power Platform role, read [Configure user security to resources in an environment](https://docs.microsoft.com/power-platform/admin/database-security). |
| 75 | + |
| 76 | +### System administrator |
| 77 | + |
| 78 | +System administrator is a Power Platform security role. This role has full permissions to customize and administrator Power Platform environment. |
| 79 | + |
| 80 | +To assign a user the System administrator Power Platform role, read [Configure user security to resources in an environment](https://docs.microsoft.com/power-platform/admin/database-security). |
| 81 | + |
| 82 | +### Dynamics 365 administrator |
| 83 | + |
| 84 | +Dynamics 365 administrator is a Power Platform service admin role. This role can do admin functions on Power Platform because they have the system admin role. |
| 85 | + |
| 86 | +To assign a user the Dynamics 365 administrator role, read [Assign a service admin role to a user](https://docs.microsoft.com/power-platform/admin/use-service-admin-role-manage-tenant#assign-a-service-admin-role-to-a-user). |
| 87 | + |
| 88 | +### Power Platform administrator |
| 89 | + |
| 90 | +Power Platform administrator is a Power Platform service admin role. This role can do admin functions on Power Platform because they have the system admin role. |
| 91 | + |
| 92 | +To assign a user the Power Platform administrator role, read [Assign a service admin role to a user](https://docs.microsoft.com/power-platform/admin/use-service-admin-role-manage-tenant#assign-a-service-admin-role-to-a-user). |
| 93 | + |
| 94 | +### Global administrator |
| 95 | + |
| 96 | +Global administrator is a Microsoft 365 admin role. A person who purchases the Microsoft business subscription is a global administrator. A global administrator has unlimited control over products in the subscription and access to most data. |
| 97 | + |
| 98 | +To assign a user the global administrator role, read [Assign admin roles in Microsoft 365](https://docs.microsoft.com/microsoft-365/admin/add-users/assign-admin-roles?view=o365-worldwide&preserve-view=true). |
| 99 | + |
| 100 | +More information: [About admin roles in Microsoft 365](https://docs.microsoft.com/microsoft-365/admin/add-users/about-admin-roles?view=o365-worldwide&preserve-view=true) |
| 101 | + |
| 102 | +### See also |
| 103 | + |
| 104 | +- [Portal admin center](admin-overview.md) |
| 105 | +- [Portal Management app](../configure/configure-portal.md) |
| 106 | +- [Portal site settings](../configure/configure-site-settings.md) |
0 commit comments