Overview of the Security Workspace
Overview of the Security Workspace
The Security Workspace in Power Pages provides a centralized location for monitoring, configuring, and managing website security. It helps administrators protect websites from vulnerabilities, control user access, configure authentication methods, and implement advanced security policies.
Using the Security Workspace, organizations can strengthen website protection through security scans, permissions management, Web Application Firewall (WAF) configuration, identity provider integration, and advanced security settings.
What is the Security Workspace?
The Security Workspace serves as the primary security management hub for Power Pages websites. It provides tools and settings required to protect data, manage user access, and ensure compliance with organizational security requirements.
Run Security Scans
Power Pages includes security scanning capabilities that help identify vulnerabilities and security risks within your website.
- Detect security vulnerabilities.
- Identify configuration issues.
- Review security recommendations.
- Strengthen website protection.
- Reduce exposure to potential threats.
Running regular security scans helps maintain a secure environment for both administrators and website visitors.
Web Roles
Web Roles control access to site content and Dataverse data. Administrators can create and manage web roles to grant users appropriate access based on business requirements.
- Create custom web roles.
- Assign users to specific roles.
- Control page access.
- Manage table permissions.
- Implement role-based security.
Page Permissions
Page Permissions determine who can access content within the Power Pages website.
- Allow public access to pages.
- Restrict access to authenticated users.
- Restrict access based on web roles.
- Protect sensitive business information.
- Control visibility of website content.
Table Permissions
Table Permissions control access to Microsoft Dataverse records used by the website.
| Permission Type | Purpose |
|---|---|
| Create | Allow users to create records. |
| Read | Allow users to view records. |
| Write | Allow users to update records. |
| Delete | Allow users to remove records. |
| Append / Append To | Manage record relationships. |
Web Application Firewall (WAF)
Web Application Firewall helps protect Power Pages websites from common web-based attacks and vulnerabilities.
- SQL Injection Protection.
- Cross-Site Scripting (XSS) Protection.
- Threat Detection and Prevention.
- Traffic Filtering.
- Security Monitoring.
Identity Providers
Identity Providers allow users to authenticate using trusted external identity platforms.
- Microsoft Entra ID
- OpenID Connect Providers
- Custom Authentication Providers
Site Visibility
Site Visibility controls who can access the website.
- Public Website Access.
- Private Website Access.
- Authenticated User Access.
- Restricted Business Portals.
Advanced Security Settings
Advanced Settings provide additional control over website security and browser behavior.
- Content Security Policy (CSP).
- Cross-Origin Resource Sharing (CORS).
- HTTP Security Headers.
- Cookie Configuration.
- Browser Permissions.
- Advanced Security Policies.
Benefits of the Security Workspace
- Centralized security management.
- Improved website protection.
- Role-based access control.
- Secure authentication methods.
- Advanced threat prevention.
- Compliance with security standards.
Best Practices
- Run security scans regularly.
- Use least-privilege access principles.
- Review web roles periodically.
- Enable Web Application Firewall.
- Configure secure identity providers.
- Apply Content Security Policies.
- Monitor website activity and security alerts.
Summary
The Security Workspace provides a comprehensive set of tools for protecting Power Pages websites. From security scans and role-based permissions to WAF protection, authentication management, and advanced security configurations, it helps organizations maintain secure, compliant, and reliable digital experiences.