Overview
Microsoft Power Apps enables organizations to build and embed custom business applications on their websites without extensive coding. These embedded apps render interactive forms, data views, dashboards, and workflow interfaces powered by Microsoft's Power Platform cloud infrastructure. Power Apps embeds are typically found on enterprise portals, internal tools exposed to external users, and customer-facing service interfaces.
What This Script Does
Power Apps embeds load from Microsoft's cloud infrastructure and render custom application interfaces within the host page.
- Scripts loaded: Power Apps embeds load via iframes from
apps.powerapps.comormake.powerapps.com, pulling the app's configuration and UI components from Microsoft's servers - Application rendering: The embedded app renders form controls (text inputs, dropdowns, date pickers, file uploads), data tables, galleries, and custom UI components defined by the app creator
- Cookies set:
- Authentication cookies on
login.microsoftonline.comfor Microsoft Entra ID (Azure AD) sign-in when the app requires authenticated access - Session cookies to maintain the app's state, user context, and data connections during the interaction
- Authentication cookies on
- Data connections: Power Apps connect to backend data sources (SharePoint, Dataverse, SQL Server, custom APIs) through Power Platform connectors. Data flows between the browser, Microsoft's servers, and the connected data sources.
- No tracking: Power Apps does not set advertising or analytics cookies. Its scripts serve the application interface and data connectivity.
Consent & Compliance
Microsoft Power Apps falls under the functional consent category.
Under GDPR and ePrivacy, embedded Power Apps provide functional application capabilities. Authentication and session cookies are strictly necessary for delivering the requested application experience under the ePrivacy Directive's exemption. The data processing through Power Platform connectors must comply with GDPR requirements, but the embedding mechanism itself does not introduce non-essential tracking.
Under CCPA/CPRA, data entered into Power Apps forms and processed through backend connectors constitutes personal information governed by the site operator's privacy practices. Microsoft acts as a data processor under its Power Platform terms.
Should You Block This Without Consent?
No. Power Apps embeds provide functional application interfaces that users interact with intentionally. Blocking them would remove the application functionality from the page. The cookies set are limited to authentication and session management required for the app to function.
Is Microsoft Power Apps GDPR compliant?
Microsoft Power Apps typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Microsoft Power Apps can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Microsoft Power Apps, not on Microsoft Power Apps itself.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
powerapps.comFunctionalpowerapps.com is a functional domain operated by Microsoft Power Apps, used to run site features like chat, video, embeds, and preferences.
apps.powerapps.comFunctionalapps.powerapps.com is a functional domain operated by Microsoft Power Apps, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Other Microsoft Products
Related Vendors

Manage consent for Microsoft Power Apps
ConsentStack automatically detects and manages Microsoft Power Apps trackers so your site stays compliant with global privacy regulations.