Solving Cross-Tenant Microsoft Dataverse Connection Issues in Power Automate Using Tenant Isolation Configuration
Updated: Jun 17

Video for a quick reference:
The Problem That Had Me Scratching My Head
Here was the setup: my organization (let's call us Tenant A) needed to talk to a Dataverse environment sitting in another company's tenant (Tenant B). Pretty standard stuff these days. We had the service account from Tenant B, the permissions looked right, and everything seemed ready to go.
But Power Automate had other plans.
Instead of playing nice, it threw back this gem:
"Failed to retrieve token for resource. Message = Parameter=Token not found."
Wait, what? Token not found?
The credentials were fine. So why was Power Automate acting like someone forgot to bring tickets to the concert?
The Rabbit Hole I Went Down
Like any good troubleshooter, I did the usual rounds:
✅ Checked Dataverse permissions – looked good
✅ Verified security roles – all set
✅ Confirmed Power Automate licensing – no issues there
✅ Tested connection references – seemed fine
✅ Double-checked Environment Credentials
The connector couldn't load tables, couldn't pull dynamic content, and basically just sat there giving me the silent treatment. Well, the error-message version of the silent treatment.
The Real Culprit (That Nobody Talks About)
After way too much time digging through settings I'd normally ignore, I finally found the problem: Tenant Isolation.
I know, right? It's one of those features that sounds good in theory (security!) but can blindside you when you're trying to do legitimate cross-company integrations.
Here's what was happening: Tenant Isolation is basically a bouncer at the door. When it's enabled without proper exceptions, it blocks any cross-tenant Dataverse connections. Doesn't matter if you have the right password, the right permissions, or the right everything else. The bouncer just says "sorry, you're not on the list" and slams the door.
How I Fixed It (And How You Can Too)
Once I figured out the real issue, the fix was surprisingly straightforward. No complicated PowerShell scripts or hacky workarounds needed.
Step 1: Open Power Platform Admin Center
Navigate to:
Security → Identity and Access → Tenant Isolation
Step 2: Review Current Restrictions
Step 3: Configure Tenant Allow List
Add the target tenant ID to the approved list.
Step 4: Enable Required Access
Allow:
Inbound access from the target tenant
Outbound access to the target tenant
Both Inbound and Outbound access to the target tenant
Step 5: Save and Apply Changes
Allow sufficient time for policy propagation.
Step 6: Recreate the Dataverse Connection
After policy changes are applied:
Remove the existing Dataverse connection.
Create a new connection.
Authenticate using the target tenant account.
Verify that tables and metadata load successfully.
What I Wish I'd Known From the Start
Look, I get it. When something's not connecting, we all immediately jump to permissions, roles, and licensing. That's where problems usually live. But if you're working across tenants, do yourself a favor and check Tenant Isolation first. It might save you hours of head-scratching.
And please, don't just disable Tenant Isolation entirely because you're frustrated. That's like removing your front door because you lost your keys. Just add the specific tenants you actually need to work with to your allow list. Keep things secure while still getting the job done.
The Bottom Line
Cross-tenant integrations aren't going anywhere. We're all connecting with partners, suppliers, and customers more than ever. The good news is that Power Platform can handle it just fine – you just need to know where the hidden switches are.
So next time Power Automate gives you that "Token not found" nonsense when you're trying to connect to another tenant's Dataverse, skip the hour of permission-checking and go straight to Tenant Isolation.
Thank you for your attention!


Comments