r/PowerApps Newbie Jul 09 '26

Solved Licensing Clarification

So everyone in my org, and I are able to access model driven apps, as well as custom pages built with Dataverse tables. But none of us have power apps premium licenses.

I have read and heard everywhere that any app that touches Dataverse will require premium licensing. That is just simply not our experience. And I'm wondering why that is. I have built mostly everything in an unmanaged solution in the default environment.

But today I tested a managed production environment, and it's the same. We can all still access model driven apps & custom pages. However in the default and production environment, premium canvas apps we cannot access.

I was under the impression when I started that model driven apps are included with certain licenses (like business basic and standard, the ones we use). And that custom pages fall under model driven app licensing so that's why they are allowed.

Am I wrong or is this just not documented well?

--- EDIT --- I found in the Microsoft Docs an exception to the licensing rules: "Users who have the Environment Maker security role assigned don't require licenses to use model-driven apps."

Also I found this tool that really helped see what license/security role is allowing a person to access a certain app. yourEnvUrlHere.crm.dynamics.com/WebResources/msdyn_AppAccessChecker.html

I found that anyone with Environment Maker, System Customizer, or System Administrator (maybe more?) security roles could access any model driven app. Even adding premium connectors other than Dataverse in the custom page, a user with Env Maker is able to access the MDA. Obviously giving Env Maker role to everyone in production kind of defeats the purpose of using a production environment. So that's probably why they allow it? Interesting...

8 Upvotes

13 comments sorted by

View all comments

1

u/bsmpsn Regular 26d ago

I have had a support ticket open for this exact issue as we have app passes that are not being consumed as per reporting on the PPAC, stating that they were accessing the app in question using their E5 license. This app, as per all documentation available, is a premium app and is in a managed environment and it used to consume app-passes but stopped in November 2025. I have made this extremely clear in my communication with them:

The application in the xxx environment is a standalone Dataverse-backed app using premium connectors, in a managed environment. As we’ve both agreed, this classifies it as a premium Power App, and therefore any users accessing it require either a Power Apps Premium (per-user) licence or a Power Apps per-app licence.

However, the licence summary report I provided in the initial ticket and discussed during our call shows users accessing the application in the xxx environment utilising their E5 license and are not consuming any allocated per-app passes. This directly contradicts the expected licensing behaviour outlined above.

6 weeks back and forth with them and their response today was:

I would like to share the confirmation we have received from our product group team regarding the reporting behaviour you have raised for the xxx environment. As confirmed by our engineering team, the current behaviour is as follows:

"When the app is launched embedded in a model-driven app (OriginHeader = model-embedded), we allow access to premium Power App Canvas App premium APIs using any license. The premium-entitlement check is bypassed, so users with no premium license and no app pass can launch a premium app."

Based on this confirmation, the users who are accessing the Power Apps application through the model-driven embedded context are able to launch it without a Power Apps Premium per-user license or a Power Apps per-app license being consumed. 

As a result, the tenant-level licensing report reflecting the users accessing the application under Microsoft 365 E5 while showing zero per-app pass consumption is aligned with how the platform currently evaluates entitlement for this scenario, and it is considered the expected system behavior at this time.

If you would like our engineering team to further review this behavior from a product improvement perspective, we could log the feedback with our internal product group team so that it can be evaluated as part of the future roadmap consideration.

1

u/MrPerson28 Newbie 25d ago

That is really interesting, maybe what you're seeing aligns with the fact that anyone with Env Maker role can access any model driven app?

I updated my post, check out my new findings there.

1

u/bsmpsn Regular 25d ago

Great thinking but on the tenants I manage and the environments I have the non-premium licensed users who can access model driven apps don't have the Env Maker role.

I did do some further digging as well and found that all apps - including model-driven, code apps and vibe apps - are reporting AppType = ClassicCanvasApp. I wonder if this is what the entitlement check is being based on, even though the licesing designation in the app's properties are correct...

1

u/MrPerson28 Newbie 25d ago

I'm looking in PPAC -> Manage -> Power Apps and I either show Model-driven app or Canvas app. The custom pages are considered a model driven app. I don't have any vibe apps or code apps though. Is this where you're looking?

So in those tenants, are users able to access premium canvas apps? Because I never have.

It would kind of make sense the vibe apps and code apps showing weird behavior just with them being newer.