top of page

Solving Cross-Tenant Microsoft Dataverse Connection Issues in Power Automate Using Tenant Isolation Configuration

Jun 12
3 min read

Updated: Jun 17


Video for a quick reference:



The Problem That Had Me Scratching My Head

Here was the setup: my organization (let's call us Tenant A) needed to talk to a Dataverse environment sitting in another company's tenant (Tenant B). Pretty standard stuff these days. We had the service account from Tenant B, the permissions looked right, and everything seemed ready to go.


But Power Automate had other plans.


Instead of playing nice, it threw back this gem:

"Failed to retrieve token for resource. Message = Parameter=Token not found."

Wait, what? Token not found?

The credentials were fine. So why was Power Automate acting like someone forgot to bring tickets to the concert?


The Rabbit Hole I Went Down

Like any good troubleshooter, I did the usual rounds:


✅ Checked Dataverse permissions – looked good

✅ Verified security roles – all set

✅ Confirmed Power Automate licensing – no issues there

✅ Tested connection references – seemed fine

✅ Double-checked Environment Credentials


The connector couldn't load tables, couldn't pull dynamic content, and basically just sat there giving me the silent treatment. Well, the error-message version of the silent treatment.


The Real Culprit (That Nobody Talks About)

After way too much time digging through settings I'd normally ignore, I finally found the problem: Tenant Isolation.


I know, right? It's one of those features that sounds good in theory (security!) but can blindside you when you're trying to do legitimate cross-company integrations.


Here's what was happening: Tenant Isolation is basically a bouncer at the door. When it's enabled without proper exceptions, it blocks any cross-tenant Dataverse connections. Doesn't matter if you have the right password, the right permissions, or the right everything else. The bouncer just says "sorry, you're not on the list" and slams the door.


How I Fixed It (And How You Can Too)

Once I figured out the real issue, the fix was surprisingly straightforward. No complicated PowerShell scripts or hacky workarounds needed.


Step 1: Open Power Platform Admin Center

Navigate to:

Security → Identity and Access → Tenant Isolation

Step 2: Review Current Restrictions


Step 3: Configure Tenant Allow List

Add the target tenant ID to the approved list.


Step 4: Enable Required Access

Allow:

  • Inbound access from the target tenant

  • Outbound access to the target tenant

  • Both Inbound and Outbound access to the target tenant


Step 5: Save and Apply Changes

Allow sufficient time for policy propagation.


Step 6: Recreate the Dataverse Connection

After policy changes are applied:

  1. Remove the existing Dataverse connection.

  2. Create a new connection.

  3. Authenticate using the target tenant account.

  4. Verify that tables and metadata load successfully.


What I Wish I'd Known From the Start

Look, I get it. When something's not connecting, we all immediately jump to permissions, roles, and licensing. That's where problems usually live. But if you're working across tenants, do yourself a favor and check Tenant Isolation first. It might save you hours of head-scratching.


And please, don't just disable Tenant Isolation entirely because you're frustrated. That's like removing your front door because you lost your keys. Just add the specific tenants you actually need to work with to your allow list. Keep things secure while still getting the job done.


The Bottom Line

Cross-tenant integrations aren't going anywhere. We're all connecting with partners, suppliers, and customers more than ever. The good news is that Power Platform can handle it just fine – you just need to know where the hidden switches are.


So next time Power Automate gives you that "Token not found" nonsense when you're trying to connect to another tenant's Dataverse, skip the hour of permission-checking and go straight to Tenant Isolation.


Thank you for your attention!

Comments


bottom of page