Documentation
Everything here is written for the person installing and running the tool, not for developers reading the codebase. Use the search box in the sidebar or jump straight to a section.
Getting started
- What is PowerToolBox PowerToolBox is a free Windows desktop app that audits Power Automate flows for security, governance, and compliance risks.
- System requirements What you need to run PowerToolBox: Windows 10 or 11, an Entra ID app registration for connected mode, and nothing else.
- Install and first run Download, extract, and run PowerToolBox, then configure your first tenant connection.
- Quickstart: your first audit Go from download to a first exported audit report in about ten minutes.
Connecting your tenant
- Entra app registration Create the Entra ID app registration PowerToolBox needs, with the right permissions, consent, and credentials.
- Certificate vs client secret Both work with PowerToolBox. Certificate authentication is recommended; here is why and how to set it up.
- API permissions The application permissions the PowerToolBox connection wizard lists, what they are for, and why consent matters.
- Multiple tenants Audit more than one tenant: one app registration per tenant, and how switching works in 1.2.0.
Auditing
- Running an audit How to run a PowerToolBox audit against live Power Platform environments.
- Audit rules overview All 20 audit rules by category, and how to toggle categories or override rule severity.
- Security rules The four Security rules: hardcoded secrets, tenant isolation, direct connections, and PAD patching.
- Exfiltration rules The three Exfiltration rules that detect data leaving the tenant via email, HTTP, and anonymous links.
- Governance rules The seven Governance rules covering DLP, ownership, sharing, licensing, and environment hygiene.
- Operational rules The three Operational rules covering error handling, failure notification, and auto-shutdown risk.
- Compliance rules The Compliance rule covering flow run history retention.
- AI rules The two AI rules covering unclassified AI connectors and Copilot privilege.
- Scoring explained How PowerToolBox turns findings into a 0–100 risk score and an action level for each flow.
Reports
- Report formats The five export formats PowerToolBox produces from the findings grid: JSON, CSV, Markdown, HTML, and Excel.
- Reading the HTML report What the self-contained HTML report shows and how to triage findings with it.
How-to guides
- Document your flows Generate interactive HTML documentation for Power Automate flows from local exports or a connected environment.
- Export and share findings Export Flow Auditor findings to JSON, CSV, Markdown, HTML, or Excel, and copy single findings into tickets or chat.
- Choose a sign-in method The six authentication methods in the connection wizard, which ones work in 1.2.0, and what each one needs.
- Configure AI resolutions How AI resolutions work in demo mode, and how to point PowerToolBox at a real OpenAI or Azure OpenAI endpoint.
- Use the toolbox shell Tabs, sidebar, command palette, keyboard shortcuts, themes, the AI panel, and community plugins in the PowerToolBox shell.
- Update or uninstall Update PowerToolBox by replacing the app folder, and remove it cleanly, including settings, connections, and caches.
Knowledge base
- SmartScreen blocks the app Why Windows SmartScreen warns on first launch of PowerToolBox, how to check the download is genuine, and how to run the app safely.
- Sign-in errors 401 and 403 Fix 401 Unauthorized and 403 Forbidden sign-in errors in PowerToolBox, plus certificate not found and stale token cache problems.
- 429 throttling and empty environment lists What to do when Power Platform APIs return 429 Too Many Requests during a scan, or when the environment dropdown in Flow Auditor stays empty.
- Known limitations in 1.2.0 Current behavior in PowerToolBox 1.2.0: which audit rules over-report or stay silent, how environment typing affects scores, and which features are previews.
- Find logs and diagnostic data Where PowerToolBox writes its log files, what the correlation ID in an error dialog means, and what to attach when you open a support ticket.
Licensing
- Licensing overview PowerToolBox is free while in early access. How licensing works today, and the paid model planned for later.
Reference
- Configuration reference Every PowerToolBox setting: where configuration lives, the sections the app reads, defaults, and valid values.
- Troubleshooting Fixes for common PowerToolBox problems: startup failures, sign-in errors, scan issues, missing reports, and where to find logs.
- Frequently asked questions Answers to common questions about installing, connecting, and running PowerToolBox.