Environment sprawl in Microsoft 365: default, developer, Teams and trial environments explained for governance leads
Thirty-seven environments. Nobody created most of them on purpose. This is what each type is, how it came to exist, and what a governance lead should ask about it — with the one policy change that stops the count growing.

A Power Platform environment is a container: a security boundary, an optional Dataverse database, a region, and a set of apps, flows and connections. A tenant starts with one. A mature tenant has dozens, and most of them were created by a licence, a Teams button or a trial rather than by a decision.
The types
| Type | How it appears | What accumulates there |
|---|---|---|
| Default | Created with the tenant; every licensed user can make in it | Everything built by someone who did not choose an environment — the bulk of shadow IT |
| Developer | Created automatically for each user who signs up for the developer plan | Personal experiments, and occasionally the only copy of something that became important |
| Teams (Dataverse for Teams) | Created when someone adds a Power App to a Teams channel | Departmental apps with real data and no administrator watching |
| Trial | Created by anyone starting a trial; expires in 30 days unless converted | Premium connectors, unlicensed, and the occasional production process |
| Sandbox | Created deliberately for test and UAT | Copies of production data, and the sharing that came with them |
| Production | Created deliberately | The estate you meant to have |
The questions per environment
- Who created it, and are they still here?
- Does it have a Dataverse database, and if so what data is in it?
- How many apps and flows does it contain, and how many of those were modified in the last year?
- Which premium connectors are in use, and under which licences?
- Who has the System Administrator role in it?
- Is anything in it referenced from another environment?
The default environment
It deserves its own paragraph because it is where most of the risk is. Every licensed user can build there; every app built there is one click from being shared with *Everyone*. Rename it so it does not look like the natural place to build, set a DLP policy that keeps premium and business data out of it, and inventory it more often than the rest.
The one policy that stops the count growing
In the admin center, restrict environment creation — trial and production — to administrators. Developer environments can be left, or restricted too. This does not remove the thirty-seven you have; it means the thirty-eighth is a request rather than a surprise.
Keep reading

How to inventory an entire Microsoft 365 tenant's Power Platform estate in an afternoon
Every environment, every Power App, every Power Automate flow, every connection — the estate is all there, spread across four admin APIs that each refuse to describe the whole. Here is how to bring it into one list, and what to do about the parts Microsoft will not tell you.

Premium connector exposure: how to find out what your Power Platform licences actually cover
A licence review starts with one question the admin center does not answer directly: which apps and flows use premium connectors, who runs them, and in which environments? Here is how to build the list, and the three exposures that appear in almost every tenant.

The Power Platform Center of Excellence Starter Kit and Power Insights: what each does best
Microsoft's CoE Starter Kit is the reference toolkit for a Power Platform Center of Excellence, and many tenants run it well. Power Insights covers some of the same ground and none of some of it. This is a plain account of which does what, written for the administrator who has to decide whether they need one, the other, or both.