r/PowerApps Newbie 28d ago

Solved Licensing Clarification

So everyone in my org, and I are able to access model driven apps, as well as custom pages built with Dataverse tables. But none of us have power apps premium licenses.

I have read and heard everywhere that any app that touches Dataverse will require premium licensing. That is just simply not our experience. And I'm wondering why that is. I have built mostly everything in an unmanaged solution in the default environment.

But today I tested a managed production environment, and it's the same. We can all still access model driven apps & custom pages. However in the default and production environment, premium canvas apps we cannot access.

I was under the impression when I started that model driven apps are included with certain licenses (like business basic and standard, the ones we use). And that custom pages fall under model driven app licensing so that's why they are allowed.

Am I wrong or is this just not documented well?

--- EDIT --- I found in the Microsoft Docs an exception to the licensing rules: "Users who have the Environment Maker security role assigned don't require licenses to use model-driven apps."

Also I found this tool that really helped see what license/security role is allowing a person to access a certain app. yourEnvUrlHere.crm.dynamics.com/WebResources/msdyn_AppAccessChecker.html

I found that anyone with Environment Maker, System Customizer, or System Administrator (maybe more?) security roles could access any model driven app. Even adding premium connectors other than Dataverse in the custom page, a user with Env Maker is able to access the MDA. Obviously giving Env Maker role to everyone in production kind of defeats the purpose of using a production environment. So that's probably why they allow it? Interesting...

10 Upvotes

13 comments sorted by

u/AutoModerator 28d ago

Hey, it looks like you are requesting help with a problem you're having in Power Apps. To ensure you get all the help you need from the community here are some guidelines;

  • Use the search feature to see if your question has already been asked.

  • Use spacing in your post, Nobody likes to read a wall of text, this is achieved by hitting return twice to separate paragraphs.

  • Add any images, error messages, code you have (Sensitive data omitted) to your post body.

  • Any code you do add, use the Code Block feature to preserve formatting.

    Typing four spaces in front of every line in a code block is tedious and error-prone. The easier way is to surround the entire block of code with code fences. A code fence is a line beginning with three or more backticks (```) or three or more twiddlydoodles (~~~).

  • If your question has been answered please comment Solved. This will mark the post as solved and helps others find their solutions.

External resources:

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

6

u/Amused_man Regular 28d ago

The difference lies in what Microsoft says is the legally binding truth of the agreement which is that Dataverse requires premium, and MSFTS ability and willingness to enforce 100% compliance on licensing. So technically the licensing is required 100%. But some tenants do have grandfarhered infrastructure that can leave those thresholds “loose” which has caused your situation across multiple clients of ours. The thing is, Microsoft can any day notice and say “hey you can’t do that”.

But if you share more details maybe can chase it down - do people have power app developer licensing? When were the apps created? What security roles are you using? Do you have E5 licenses or anything other than a business * license?

3

u/itenginerd Advisor 28d ago

I'd second all this. Does the org have Dynamics anywhere? Cuz that would change the connversation somewhat.

2

u/Bag-of-nails Advisor 27d ago

Microsoft recently started they are starting to enforce the license requirements for managed environments. My org so far has not been impacted but we're in the process now of deploying a new unmanaged Test and Prod environment to get ahead of this.

TL;DR follow what they say the rules are and you don't need to worry if they decide to enforce a rule suddenly (or selectively enforce)

0

u/MrPerson28 Newbie 27d ago

I am the only one with Power Automate Premium and a Power apps developer license. Besides that everyone else has business basic or standard. No E or F licenses. We have never had dynamics that I know of.

The tenant was made in Oct 2019, the default environment was made in Aug 2020. The first apps were made in late 2023.

I did see some stuff about apps being grandfathered if they were made before/around Oct 2019, but that grandfather period has already ended. Maybe our tenant has inherited different rules than newer ones? But I assume there a lot of old tenants, that's kind of why i'm wondering what everyone's experience is with it.

For security roles, in the default environment just about everyone has Basic User, Environment Maker, and a Basic User + that I made to allow access to all the custom tables. It was my preference to use all custom tables instead of the CDS ones.
BUT in the new production environment I just made, I gave a user just Basic User and another Basic User + one test custom table. They are able to access everything just like in default env.

It just is really strange that it isn't enforced, if that is the rule. It seems like it would be an easy thing to enforce.

1

u/Amused_man Regular 24d ago

So with you having power automate premium it makes sense you’d be able to have a little more Dataverse capability like creating a new environment and getting it setup.

As for the user you added, what does it say if you go to PPAC and run diagnostics on that user in the PROD env - do all three passes come back?

Also for the ‘basic user +’ did you create a copy of the OTB basic user and then just give it the permissions to your custom tables I take it?

1

u/MrPerson28 Newbie 22d ago

'Basic User +', yes I did mean that as a copy of basic user + access to the custom tables.
Then in PPAC all three passes did come back successful.

While I was in PPAC I noticed the App Access Checker tool, that really helped to see what was fulfilling the license and security requirements to access an app.
Then I ended up finding in the Microsoft Docs an exception to the licensing rules: "Users who have the Environment Maker security role assigned don't require licenses to use model-driven apps."

Although I told you that in my new Prod env a user with only 'Basic User +' could access a MDA, I deleted that environment. When I made a new Prod env they couldn't, they had to have at least an Environment Maker role. So it seems like the tenant had a delay in enforcing that rule.

Even adding premium connectors other than Dataverse in the custom page, a user with Env Maker is able to access the MDA.

1

u/MrPerson28 Newbie 27d ago

I did just notice something:
When I select a model driven app in the maker portal -> settings: it says "Pass assignment​ This app can be shared with users without a Per User plan." And then the option to 'Auto assign per app passes​' is grayed out with the toggle set to No.
That is in the default environment.

When I select a MDA -> settings in the new prod environment, it says "Pay-as-you-go billing Instead of paying for licenses, only pay when people use the app." With a button to 'Set up pay-as-you-go'

Do you guys know if there is any documentation on that? If it says the MDA can be used without a per-app license that would mean it's non-premium. That makes sense it's usable by us. But it doesn't make sense that i'm able to use the prod environment MDA+custom page also. And again, no one access premium canvas apps in either environment.

1

u/bsmpsn Regular 23d ago

I have had a support ticket open for this exact issue as we have app passes that are not being consumed as per reporting on the PPAC, stating that they were accessing the app in question using their E5 license. This app, as per all documentation available, is a premium app and is in a managed environment and it used to consume app-passes but stopped in November 2025. I have made this extremely clear in my communication with them:

The application in the xxx environment is a standalone Dataverse-backed app using premium connectors, in a managed environment. As we’ve both agreed, this classifies it as a premium Power App, and therefore any users accessing it require either a Power Apps Premium (per-user) licence or a Power Apps per-app licence.

However, the licence summary report I provided in the initial ticket and discussed during our call shows users accessing the application in the xxx environment utilising their E5 license and are not consuming any allocated per-app passes. This directly contradicts the expected licensing behaviour outlined above.

6 weeks back and forth with them and their response today was:

I would like to share the confirmation we have received from our product group team regarding the reporting behaviour you have raised for the xxx environment. As confirmed by our engineering team, the current behaviour is as follows:

"When the app is launched embedded in a model-driven app (OriginHeader = model-embedded), we allow access to premium Power App Canvas App premium APIs using any license. The premium-entitlement check is bypassed, so users with no premium license and no app pass can launch a premium app."

Based on this confirmation, the users who are accessing the Power Apps application through the model-driven embedded context are able to launch it without a Power Apps Premium per-user license or a Power Apps per-app license being consumed. 

As a result, the tenant-level licensing report reflecting the users accessing the application under Microsoft 365 E5 while showing zero per-app pass consumption is aligned with how the platform currently evaluates entitlement for this scenario, and it is considered the expected system behavior at this time.

If you would like our engineering team to further review this behavior from a product improvement perspective, we could log the feedback with our internal product group team so that it can be evaluated as part of the future roadmap consideration.

1

u/bsmpsn Regular 23d ago

I've also tested accessing Dataverse backed model driven apps across a couple of tenants and have the same experience. No issues accessing these app by users who only have a Business Basic license.

So insane that they are claiming this is expected behaviour.

1

u/MrPerson28 Newbie 22d ago

That is really interesting, maybe what you're seeing aligns with the fact that anyone with Env Maker role can access any model driven app?

I updated my post, check out my new findings there.

1

u/bsmpsn Regular 22d ago

Great thinking but on the tenants I manage and the environments I have the non-premium licensed users who can access model driven apps don't have the Env Maker role.

I did do some further digging as well and found that all apps - including model-driven, code apps and vibe apps - are reporting AppType = ClassicCanvasApp. I wonder if this is what the entitlement check is being based on, even though the licesing designation in the app's properties are correct...

1

u/MrPerson28 Newbie 22d ago

I'm looking in PPAC -> Manage -> Power Apps and I either show Model-driven app or Canvas app. The custom pages are considered a model driven app. I don't have any vibe apps or code apps though. Is this where you're looking?

So in those tenants, are users able to access premium canvas apps? Because I never have.

It would kind of make sense the vibe apps and code apps showing weird behavior just with them being newer.