Power Pages Web API Wildcard Configuration End of Support
Share on LinkedIn!
#SimpleSharepoint #PowerPlatform #PowerPages #Dataverse #ITGovernance #EnterpriseIT #Compliance #MicrosoftUpdates
Field Access Rules and Dataverse Column Governance
The Power Pages Web API wildcard configuration is ending support soon, forcing organizations to update Dataverse column access rules.
Microsoft is removing support for the wildcard value (*) in the Webapi/<table_name>/fields site setting. Previously, using a wildcard allowed public API calls to access every column on a connected Dataverse table. Starting September 14, 2026, Microsoft is eliminating wildcard support to enforce least-privilege security. After this date, API calls using wildcard settings will fail until explicitly configured.
Security Exposure Risks and Deprecation Details
Continuing to rely on wildcard settings introduces security gaps and integration failures:
- Over-exposed Dataverse tables: Wildcard parameters expose every table column—including sensitive fields not intended for public views.
- Phased removal rollout: Newly created Power Pages sites lost wildcard support in August 2026, with complete enforcement landing on September 14, 2026.
- Service disruption: Power Pages Web API requests for tables still using
*will return errors once enforcement reaches your tenant.
Remediation Steps for IT and Application Teams
To avoid breaking portal integrations, development teams should follow three key action items:
- Audit site settings: Review
Webapi/<table_name>/fieldsentries in the Power Pages Management app to identify active wildcard settings. - Define explicit column lists: Replace
*values with comma-separated logical names of only the required Dataverse columns. - Test API endpoints: Validate fetch and AJAX calls against the new column parameters before September 14.
How our team helps you prepare:
- Web API Configuration Audit: We locate hidden wildcard settings across all active Power Pages portals before enforcement hits.
- Column-Level Allowlist Mapping: We map your portal code to define exact column permissions without breaking site functionality.
- Power Platform Governance: We align your site security settings with current Microsoft compliance standards.
Managing older Power Pages portals with legacy API setups? We can help audit your site settings and update column configurations.



