Overview
Microsoft Power Apps enables organizations to build and embed custom business applications on their websites without extensive coding. These embedded apps render interactive forms, data views, dashboards, and workflow interfaces powered by Microsoft's Power Platform cloud infrastructure. Power Apps embeds are typically found on enterprise portals, internal tools exposed to external users, and customer-facing service interfaces.
What This Script Does
Power Apps embeds load from Microsoft's cloud infrastructure and render custom application interfaces within the host page.
- Scripts loaded: Power Apps embeds load via iframes from
apps.powerapps.comormake.powerapps.com, pulling the app's configuration and UI components from Microsoft's servers - Application rendering: The embedded app renders form controls (text inputs, dropdowns, date pickers, file uploads), data tables, galleries, and custom UI components defined by the app creator
- Cookies set:
- Authentication cookies on
login.microsoftonline.comfor Microsoft Entra ID (Azure AD) sign-in when the app requires authenticated access - Session cookies to maintain the app's state, user context, and data connections during the interaction
- Authentication cookies on
- Data connections: Power Apps connect to backend data sources (SharePoint, Dataverse, SQL Server, custom APIs) through Power Platform connectors. Data flows between the browser, Microsoft's servers, and the connected data sources.
- No tracking: Power Apps does not set advertising or analytics cookies. Its scripts serve the application interface and data connectivity.
Consent & Compliance
Microsoft Power Apps falls under the functional consent category.
Under GDPR and ePrivacy, embedded Power Apps provide functional application capabilities. Authentication and session cookies are strictly necessary for delivering the requested application experience under the ePrivacy Directive's exemption. The data processing through Power Platform connectors must comply with GDPR requirements, but the embedding mechanism itself does not introduce non-essential tracking.
Under CCPA/CPRA, data entered into Power Apps forms and processed through backend connectors constitutes personal information governed by the site operator's privacy practices. Microsoft acts as a data processor under its Power Platform terms.
Should You Block This Without Consent?
No. Power Apps embeds provide functional application interfaces that users interact with intentionally. Blocking them would remove the application functionality from the page. The cookies set are limited to authentication and session management required for the app to function.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
powerapps.comFunctionalapps.powerapps.comFunctionalFrequently Asked Questions
Does Microsoft Power Apps require cookie consent?
No. Power Apps embeds provide functional application interfaces — forms, data views, and workflow controls — that users interact with intentionally. Authentication and session cookies are strictly necessary for the app to function under ePrivacy's exemption. No advertising or behavioral tracking cookies are set.
What cookies does Microsoft Power Apps set?
Power Apps sets authentication cookies on login.microsoftonline.com for Microsoft Entra ID sign-in when the app requires authenticated access, plus session cookies to maintain application state during the interaction. Apps load via iframes from apps.powerapps.com or make.powerapps.com with no advertising scripts embedded.
How does ConsentStack categorize Microsoft Power Apps?
ConsentStack classifies Power Apps as functional. Because its cookies are limited to authentication and session management for a user-requested application, ConsentStack does not gate Power Apps behind a consent prompt. The application iframe loads without restriction, keeping embedded business tools operational for all site visitors.
Other Microsoft Products
Related Vendors
Manage consent for Microsoft Power Apps
ConsentStack automatically detects and manages Microsoft Power Apps trackers so your site stays compliant with global privacy regulations.