Skip to main content

Getting Started with Power Platform Protection: Installation and Configuration

This article provides the high-level workflow for configuring the Druva Cloud Platform to back up Microsoft Power Platform data.

To ensure a successful deployment, the process is divided into two primary phases: Initial App Setup and Tenant Environment Authorization.


Phase 1: App Deployment and Encryption

The first phase involves establishing the connection between Druva and your Microsoft 365 tenant. This ensures that the data pipeline is authenticated and encrypted.

Key Tasks:

  1. Installing the Druva Power platform app in the Druva Cloud Platform.

  2. Authorizing Global Admin credentials.

  3. Enabling AWS KMS or BYOK encryption.

📝NOTE: Scheduled backups and discovery will not function without a completed encryption configuration.

Detailed Instructions: Proceed to App Deployment and Encryption


Phase 2: Tenant Environment Authorization

The second phase allows the Druva Service Principal to "see" and "read" your Power Platform data. This requires specific configurations outside of the Druva console.

Key Tasks:

  1. Create or update an Entra ID security group and add the Druva Power Platform application as a member.

  2. In the Power BI Admin portal, authorize that security group to use Fabric public APIs and read-only Power BI admin APIs (least-privilege discovery without tenant-wide admin rights).

  3. Add the Druva service principal to each Power BI workspace with Contributor access so report files and related content are backed up—not only metadata.

Tasks 1 and 2 are required for discovery to start. Task 3 is required for full content protection; without it, backups can still run but may include metadata only.

Detailed Instructions: Proceed to Tenant Environment Authorization.


Did this answer your question?