Check User Access

    You can check the permissions of users in environments, including permissions to associated security groups, teams, security roles, Power Apps, and flows to gain insights on the activity and security compliance of specific users.

    To check the access, complete the following steps:

    1. Select the environments you want to check the users’ access in. The selected environments should be in the same tenant.

    2. Click Check user access on the ribbon to go to the Check user access page.

    3. On the page, specify users to check by display names. You can check access for a maximum of 10 users at a time.

    4. Click Check to view the checking results. You can view the following information listed:

      • User display name

      • User principal name

      • User type – The user type of the specified user, including Member or Guest.

      • Environments – The environment that the user has access to.

      • Environment permissions – The permissions in the environment that the user has.

      • Security group – The security group in the environment. You can check if the user is in the security group from With membership or Without membership.

      • Security roles – The number of security roles the user has. You can click the number to open the Manage security roles panel to view the detailed security roles the user has and update them.

      • Environment teams – The environment teams that the user is in. You can click the number to open the Manage environment teams panel to view the team details and update the users’ team membership.

      • App permissions – The permissions the user has on Power Apps in the environment. Click the number to view or update the details.

      • Flow permissions – The permissions the user has on Power Automate flows in the environment. Click the number to view or update the details.

    Apart from managing permissions in the permission details panels, you can also perform the following operations on the searched results, including:

    - Remove permissions – To remove specific permissions from users, complete the following steps: 1. Select a result of user access and click **Remove** on the ribbon to open the **Remove permissions** panel. 2. Select the permissions to remove. 3. Click **Remove**, and the process will start to remove the specified permissions. > ***Note**: The creator role cannot be removed. If the selected user does not have any of the permissions specified to remove, the action will be skipped. - Remove and reassign – To remove specific permissions from a user and reassign the permissions to another user, complete the following steps: 1. Select a result of user access and click **Remove and reassign** to open the **Remove and reassign** panel. 2. Select the permissions to remove and reassign. 3. Specify users to reassign the permissions to. 4. Click **Apply**, and the process will start to remove and reassign the specified permissions. - Export the checked results – Click **Export** on the ribbon, and the process will start to export the results. Click **process center** in the popup window or click **View all** in the **Process center** (![Icon: Process center](/en/enpower/power-platform-management/environments/images/image354.png "Icon: Process center")) window to navigate to the **Process center**. After the process is finished, click the **Download** (![Button: Download](/en/enpower/power-platform-management/environments/images/image355.png "Button: Download")) button to download your exported report.