PROCESS 12 October 2025 14 min read

Power Pages External Identity: The Complete Onboarding Process

Step-by-step process documentation: how to onboard new portal users with Entra External ID in Power Pages, with minimal internal effort and setup time.

1. Introduction and Objectives

Objective

This documentation describes the process for onboarding new portal users in Power Pages with external identity management (Entra External ID). The focus is on the task distribution between internal business departments and external portal users.

Key Message

The internal business department performs activities exclusively in Dataverse. All interaction with the external identity provider is completed entirely by the portal user themselves.

Internal Effort

2
Steps

Time Required

~1
Minute per user

Systems (internal)

Dataverse
+ Power Pages

Entra External ID

No
Interaction

2. Role Distribution and Responsibilities

Internal Business Department

  • Create contact record in Dataverse
  • Initiate invitation via Power Pages Admin
  • No direct access to Entra External ID

Portal User (Self-Service)

  • Receive invitation email
  • Register in Entra External ID
  • Set password and MFA
  • Access portal independently

Internal Business Department (Dataverse) — Step by Step

Step Activity System
1 Create contact record Dataverse
2 Initiate invitation Power Pages

Note: No direct interaction with Entra External ID required.

External Portal User (Entra External ID) — Step by Step

Step Activity System
1 Open invitation link Email Client
2 Define password Entra External ID
3 Activate account Entra External ID
4 Perform initial login Power Pages

Note: Completely independent completion without internal support.

Important

The business department has no activities in the external identity provider. Every touchpoint with Entra External ID — from setting a password to activating the account — happens on the portal user's side.

3. Detailed Process: Internal Business Department

Two steps, both performed in Microsoft systems the business department already knows. No portal login, no identity provider console, no password handling.

1

Create Contact Record

Required Data
  • Email address (required, unique)
  • First name (required)
  • Last name (required)
  • Status: Active
System

Microsoft Dataverse (Model-Driven App or Power Pages Admin)

Time Required

Approx. 30 seconds

2

Initiate Invitation

Process

The invitation function is triggered via Power Pages Admin for the created contact. The system automatically generates a unique redemption code and sends an email to the registered email address.

System Process

Power Pages creates an invitation record in Dataverse and sends a preconfigured email template.

Time Required

Approx. 5 seconds (button click)

Completion of Internal Activities

After completing these two steps, all business department activities are finished. Every further process step occurs automatically or is performed by the portal user.

4. Detailed Process: Portal User (Independent)

Important

All following steps are completed independently by the portal user. The internal business department has no tasks in this section of the process.

1

Receive Invitation Email

The portal user automatically receives an email with a unique invitation link. Default validity: 7 days. After expiration, the business department can resend the invitation using the identical process as the initial send.

2

Validate Redemption Code

By clicking the link, the portal user is redirected to Power Pages. The system validates the redemption code and, upon successful validation, redirects to Entra External ID.

3

Register in Entra External ID

The portal user is redirected to the sign-up page of the external identity provider. There, they enter and confirm a self-selected password and, depending on configuration, any additional profile data.

4

Account Activation

After successful registration, Entra External ID creates an active user account. The link to the Dataverse contact is established via the email address as the shared identifier.

5

Authentication and Portal Access

After completing registration, the portal user is automatically redirected to the Power Pages portal and authenticated. From this point, full portal access is available.

Result

The portal user is now fully registered and can independently log into the portal in the future using their credentials (email + password). Password management, including resets, is handled exclusively through Entra External ID — the business department has no access to passwords at any point.

5. Frequently Asked Questions (FAQ)

Is interaction with Entra External ID required by the business department?
No. The business department performs activities exclusively in Dataverse and Power Pages Admin. All interaction with the external identity provider is completed independently by the portal user.
Does the business department need to manage or reset passwords?
No. Password management is handled entirely by Entra External ID. Portal users can independently perform password resets. The business department has no access to passwords.
What is the validity period of an invitation?
Default validity: 7 days. This is a configurable setting, so the actual duration can be adjusted in the Power Pages settings. After expiration, the invitation can be resent — an identical process to the initial sending.
Is bulk creation of portal users possible?
Yes. Via Power Automate, contact records and invitations can be created automatically from lists (for example Excel or CSV exports). This significantly reduces manual effort for larger user groups such as an entire customer or partner rollout.
How is a portal user deactivated?
The contact record in Dataverse is set to status "Inactive". Authentication via Entra External ID is then no longer possible, even though the external identity itself still exists. Reactivation happens by changing the status back to "Active".
What happens if email delivery fails?
The invitation can be resent via the Power Pages Admin interface. The most common cause is a spam filter at the recipient's end — instruct the portal user to check their spam or junk folder before troubleshooting further.

Need Help with User Onboarding?

Get expert guidance on setting up efficient user onboarding processes for your Power Pages portal.

Book Consultation
Tino Rabe

Tino Rabe

Power Pages Spezialist · Former Microsoft MVP

Power Pages specialist, former Microsoft MVP. I help companies build secure customer portals: architecture workshop, weekly coaching, security audits.

When was your portal last independently reviewed?

Fixed-fee security audit, or just talk it through first.

Book a call