generated: '2026-09-06' method: searched source: >- https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview, https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/query/page-results, https://learn.microsoft.com/en-us/power-platform/admin/programmability-authentication-v2, https://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy, https://www.microsoft.com/en-us/trust-center/product-overview (all fetched 2026-09-06) description: >- Standards and compliance claims for the Microsoft Power Platform API surface, each with the evidence that supports it. Entries marked conforms:false are recorded as honest absences. conformance: - id: odata-v4 name: OData Version 4.0 (OASIS) conforms: true evidence: >- The Dataverse Web API "implements OData v4" per https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview. The surface exposes the OData system query options ($select, $filter, $orderby, $top, $expand, $count), the OData annotations @odata.etag / @odata.nextLink / @odata.count, an OData-shaped error object, /$batch, and a CSDL $metadata service document at {org}.api.crm.dynamics.com/api/data/v9.2/$metadata. domain_standard: true signature: >- OData $metadata (CSDL) service document plus @odata.* instance annotations in every payload - the contract declares the standard rather than a marketing page claiming it. spec_location: openapi/microsoft-power-platform-records-api-openapi.yml (paths carry $select/$filter/$orderby/$top/$expand/$count query parameters) note: >- The $metadata document itself is per-environment and requires a tenant bearer token, so it could not be fetched anonymously in this pass. - id: oauth2 name: OAuth 2.0 conforms: true evidence: >- Both API families authenticate exclusively with Microsoft Entra ID OAuth 2.0 bearer tokens; https://learn.microsoft.com/en-us/power-platform/admin/programmability-authentication-v2 documents the user and service (client credentials) flows. api.powerplatform.com returned WWW-Authenticate Bearer error="invalid_token" on an anonymous probe 2026-09-06. - id: oidc name: OpenID Connect conforms: true evidence: >- Identity is Microsoft Entra ID, whose OIDC discovery document is published at https://login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration. No Power Platform host serves its own openid-configuration - see well-known/. - id: rfc7232-conditional-requests name: HTTP Conditional Requests (ETag / If-Match / If-None-Match) conforms: true evidence: https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/perform-conditional-operations-using-web-api - id: rfc9116-security-txt name: security.txt conforms: true evidence: https://www.microsoft.com/.well-known/security.txt returned HTTP 200 on 2026-09-06 with Contact, Policy, Acknowledgments, Encryption and Expires fields. - id: rfc9457-problem-details name: Problem Details for HTTP APIs conforms: false evidence: >- Dataverse returns the OData v4 error object under application/json, not application/problem+json. See errors/microsoft-power-platform-problem-types.yml. - id: idempotency-key name: Idempotency-Key header (draft-ietf-httpapi-idempotency-key) conforms: false evidence: >- No Idempotency-Key header is documented on either API family. Replay protection is ETag conditional requests, which cover update/delete/upsert but not POST create - recorded as idempotency.coverage partial in conventions/. - id: rfc9239-ratelimit-headers name: RateLimit header fields for HTTP conforms: false evidence: >- Throttling is signalled with 429 + Retry-After and two vendor headers (x-ms-ratelimit-burst-remaining-xrm-requests, x-ms-ratelimit-time-remaining-xrm-requests), not the standard RateLimit-* fields. - id: openapi name: OpenAPI Specification conforms: partial evidence: >- Microsoft publishes a Swagger 2.0 contract for the Microsoft.PowerPlatform Azure Resource Manager provider (enterprise policies, accounts, private link) in Azure/azure-rest-api-specs - saved verbatim to openapi/_original/microsoft-power-platform-enterprise-policies-openapi.json. Neither the Dataverse Web API nor api.powerplatform.com publishes a downloadable OpenAPI document; the REST reference on Microsoft Learn is rendered documentation. Power Platform custom connectors, by contrast, are DEFINED with OpenAPI 2.0, so the platform consumes the standard even where it does not publish one for itself. consumer_note: https://learn.microsoft.com/en-us/connectors/custom-connectors/ - id: mcp name: Model Context Protocol conforms: true evidence: >- First-party Dataverse MCP server, remote endpoint https://{org}.crm.dynamics.com/api/mcp and stdio proxy npx -y @microsoft/dataverse mcp. See mcp/. status: preview - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json probed on eight Power Platform hosts on 2026-09-06; every response was a 404, a 401, or an HTML SPA shell. No agent card is served. compliance: published: true source: https://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy authoritative_index: https://www.microsoft.com/en-us/trust-center/product-overview evidence_portal: https://servicetrust.microsoft.com/ programs: - id: gdpr name: EU General Data Protection Regulation evidence: >- Microsoft publishes per-feature Data Subject Rights response procedures for Power Apps, Dataverse and Power Automate, and GDPR guidance on the Service Trust Portal (https://servicetrust.microsoft.com/ViewPage/GDPRGetStarted). - id: encryption-at-rest name: Encryption at rest (SQL Server Transparent Data Encryption) evidence: >- "All environments of the Dataverse database use SQL Server Transparent Data Encryption (TDE)"; customer-managed keys are supported through the Power Platform admin center. - id: encryption-in-transit name: TLS 1.2 or higher required on all public endpoints evidence: >- "Currently, TLS 1.2 (or higher) is required for accessing the server endpoints." Confirmed by probe: make.powerapps.com, learn.microsoft.com and api.bap.microsoft.com all negotiated TLSv1.3 (security/microsoft-power-platform-domain-security.yml). - id: data-residency name: Geo-scoped data residency evidence: >- Environments are targeted at a geo and data does not move outside that geo except for documented legal/support cases. Current geo list published in the Trust Center. - id: us-government name: US Government cloud availability (GCC / GCC High) evidence: >- https://learn.microsoft.com/en-us/power-platform/admin/powerapps-us-government (HTTP 200); Power Platform CLI is supported in GCC and GCC High via the pac auth --cloud parameter. note: >- Microsoft's named certification and attestation set (ISO 27001, SOC 1/2/3, FedRAMP, HIPAA, PCI DSS and the rest) is not enumerated on the Power Platform compliance page - that page routes to the Microsoft Trust Center and the Service Trust Portal as the authoritative source, and the Service Trust Portal requires sign-in to download the reports themselves. Individual certificate names are therefore NOT asserted here; the two evidence URLs above are what was actually verified.