Add FAQ: CoE environment access control and maker group auto-enrollment #10800
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Users frequently misconfigure CoE environment security by conflating environment security groups (controls environment access) with maker M365 groups (used for app sharing and communications). This leads to unauthorized environment access when the
Admin | Add Maker to Groupflow auto-enrolls discovered makers.Documentation Added
FAQ: CoE Environment Access Control and Visibility
File:
CenterofExcellenceResources/FAQ-EnvironmentAccessControl.mdAddresses three common questions:
Admin | Add Maker to Groupflow that automatically adds users to M365 group when inventory discovers them as makersKey sections:
Issue Response Template
File:
docs/ISSUE-RESPONSE-EnvironmentAccessControl.mdQuick reference for maintainers responding to similar issues.
Documentation Index
File:
docs/README.mdAdded references under "Administration" and "Issue Response Templates" sections.
Technical Context
The
AdminAddMakertoGroupflow (Core Components) triggers when new records are added to theadmin_Makertable. It uses thePower Platform Maker Group IDenvironment variable to add users to an M365 group via the Office 365 Groups connector. This is intended behavior for maker identification but often misconfigured as an environment security group, granting unintended access.Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.