Security 18 September 2026 2 min read

Power Pages Security Selfcheck: 5 Checks, 15 Minutes

Five free Power Pages security checks you can run in fifteen minutes, no tools or budget required: anonymous API access, Site Checker, table permissions, and more.

Five checks. Fifteen minutes. No tools, no budget, no ticket to your partner. That is all it takes to find out whether your Power Pages site has a data exposure problem.

Five checks. Fifteen minutes. No tools, no budget.

Open a private browser window, not logged in, and call yoursite/_api/contacts. JSON instead of an error means fix your table permissions now. Then run Site Checker from the Power Pages admin center, it flags the misconfigurations behind most recent incidents.

The two that take thirty seconds.

Filter your table permissions for Global scope. Every entry needs a reason, "it didn't work with Contact scope" is not a reason, it is the finding. Then check what the Anonymous Users web role is actually allowed to do, most audits find at least one permission nobody can explain.

Every entry needs a reason.

Last, check whether open registration is enabled, and what a fresh account can see the moment it signs itself up. Anonymous exposure makes the headlines, this is the same leak with one extra step.

Anyone can register. Then read.

That is the fifteen minute version. My full Power Pages security audit runs more than fifty checks across permissions, web roles, site settings, identity configuration, and custom code, fixed fee, fixed scope, written report.

Run the five above first. They are free, and they catch the worst of it.

The full audit runs fifty-plus checks.
Tino Rabe

Tino Rabe

Power Pages Spezialist · Former Microsoft MVP

Power Pages specialist, former Microsoft MVP. I help companies build secure customer portals: architecture workshop, weekly coaching, security audits.

When was your portal last independently reviewed?

Fixed-fee security audit, or just talk it through first.

Book a call