Blog
Practical Power Platform governance and migration
Written for the administrator who has to answer the question this week: what is in the tenant, who owns it, what it depends on, and how to move it without breaking it.

How to inventory an entire Microsoft 365 tenant's Power Platform estate in an afternoon
Every environment, every Power App, every Power Automate flow, every connection — the estate is all there, spread across four admin APIs that each refuse to describe the whole. Here is how to bring it into one list, and what to do about the parts Microsoft will not tell you.

The Power Platform Center of Excellence Starter Kit and Power Insights: what each does best
Microsoft's CoE Starter Kit is the reference toolkit for a Power Platform Center of Excellence, and many tenants run it well. Power Insights covers some of the same ground and none of some of it. This is a plain account of which does what, written for the administrator who has to decide whether they need one, the other, or both.

Power Apps migration planning: the dependency checklist nobody gives you
Moving a Power App between environments or tenants is rarely hard because of the app. It is hard because of the eleven things the app quietly depends on, none of which appear in the export dialog. This is the list, in the order they bite.

"Who owns this flow?" — resolving SYSTEM, team and departed owners in Power Automate
Half the flows in a mature tenant show no owner at all in the Flow API. They are not orphans — they belong to SYSTEM, to a team, or to a person who has left — and each of those needs a different action. Here is where the real owner lives and how to read it.

Premium connector exposure: how to find out what your Power Platform licences actually cover
A licence review starts with one question the admin center does not answer directly: which apps and flows use premium connectors, who runs them, and in which environments? Here is how to build the list, and the three exposures that appear in almost every tenant.

Why "no solution" is the most expensive answer in a Power Platform migration
Three hundred flows, none of them in a solution, all of them needed in the new tenant. Recreating them by hand is not a plan. Here is what the platform allows an administrator to do about it, and where the limits are.

Sharing a Power App or flow with yourself as an admin — legitimately
Being a Power Platform Administrator lets you list every flow in the tenant. It does not let you open one. Before a migration or an incident, that gap has to be closed — here is how it is done through the admin surfaces, and how to leave an audit trail while doing it.

Desktop flows are part of your estate too — inventorying Power Automate for desktop from Dataverse
The finance team has eighty desktop flows running month-end. None of them are in your flow count, because the API you are counting with cannot see them. They are in Dataverse, and here is how to bring them into the inventory before they surprise a migration.

Hard-coded URLs inside canvas apps: finding every SharePoint and Power BI reference before you move
The app imports cleanly. Every screen opens. And the document library link on screen four still points at the old tenant, because it was typed into a formula in 2022. Here is how to find those before the users do.

Environment sprawl in Microsoft 365: default, developer, Teams and trial environments explained for governance leads
Thirty-seven environments. Nobody created most of them on purpose. This is what each type is, how it came to exist, and what a governance lead should ask about it — with the one policy change that stops the count growing.

Reading a Dataverse solution from the outside: solutioncomponents, ObjectTypeCodes and why flow names come back as GUIDs
The solution has 400 components and the API describes them as type 10080, type 29 and a list of GUIDs. Here is how to turn that into a table with names on it — including the two ids every cloud flow carries and the one that actually matches.

A read-only governance model: why your Power Platform assessment tool should not need write access to your tenant
The tool that tells you what is in your tenant should not be able to change it. This is the case for a read-only governance model — the permissions it needs, the ones it must not have, and how to tell the difference on a consent screen.
Governance
- 2026-09-15How to inventory an entire Microsoft 365 tenant's Power Platform estate in an afternoon8 min
- 2026-09-01Premium connector exposure: how to find out what your Power Platform licences actually cover6 min
- 2026-08-10Environment sprawl in Microsoft 365: default, developer, Teams and trial environments explained for governance leads7 min