Category
stayInformed
Severity
normal
Major change
False
Last modified
2026-08-19 17:18:24
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
—
Action by (AI)
2026-09-14 00:00:00
Services
Power Platform
Tags
Admin impact
Master tags
Admin, Security
Roadmap IDs
One-line summary
Wildcard (*) support in Power Pages Web API field configuration ends September 14, 2026; specify columns explicitly to ensure continued access and avoid HTTP 403 errors.
Similar updates
More like thisMC1188232 Power Automate - Information regarding the end of support for Document Automation Toolkit
MC1197917 Power Platform admin center – Review security role descriptions and definitions
MC1194585 Power Platform – Power Platform Environment Settings app
MC1190074 Power Pages - Enhance governance for non-production site visibility
MC1189685 Power Platform - Improved security for column-level audit events in Microsoft Purview
MC1189695 Power Apps – Upcoming changes to license consumption experience
Details
Body (from Message Center)
Starting on September 14, 2026, Wildcard (*) in the Web API field configuration will have reached end of support.
How does this affect me?
After September 14, 2026, support for the Wildcard value (*) in the Web API field configuration will be removed in phases over the following weeks.
The Wildcard (*) configuration exposes all columns in a Dataverse table through the Power Pages Web API. To improve security and align with least-privilege access principles, Power Pages now requires an explicit list of columns to be specified in the Webapi//fields site setting. This change helps prevent unintended exposure of additional columns and provides greater control over data accessible through the Web API. For more details, please refer to Power Pages portals Web API overview.
What action do I need to take?
If your websites currently use the wildcard value (*) in any Webapi//fields site setting, please perform the below steps:
Please contact Microsoft support if you need further assistance.
How does this affect me?
After September 14, 2026, support for the Wildcard value (*) in the Web API field configuration will be removed in phases over the following weeks.
The Wildcard (*) configuration exposes all columns in a Dataverse table through the Power Pages Web API. To improve security and align with least-privilege access principles, Power Pages now requires an explicit list of columns to be specified in the Webapi/
What action do I need to take?
If your websites currently use the wildcard value (*) in any Webapi/
- Review the tables exposed through the Power Pages Web API.
- Replace the Wildcard value (*) with an explicit comma-separated list of columns that should be accessible.
- Validate your website's functionality after updating the configuration.
Please contact Microsoft support if you need further assistance.
Raw JSON (for debugging)
Expand/collapse the full payload below.
Show/hide raw
{
"snapshot_item": {
"action_required_by": null,
"ai_action_required_by": "2026-09-14T00:00:00Z",
"ai_actions": [
"Review tables exposed via Power Pages Web API.",
"Replace wildcard (*) with explicit columns list in Webapi/\u003ctable\u003e/fields.",
"Validate website functionality after configuration update."
],
"ai_master_tags": [
"Admin",
"Security"
],
"ai_model": "gpt-4.1",
"ai_summary": "Wildcard (*) support in Power Pages Web API field configuration ends September 14, 2026; specify columns explicitly to ensure continued access and avoid HTTP 403 errors.",
"ai_topics": [
"Power Platform"
],
"category": "stayInformed",
"details_map": {},
"id": "MC1457694",
"importance": 3,
"is_major_change": false,
"last_modified": "2026-08-19T17:18:24Z",
"ms_products": [
"Power Platform"
],
"platforms": null,
"roadmap_ids": [],
"services": [
"Power Platform"
],
"severity": "normal",
"tags": [
"Admin impact"
],
"title": "Power Pages- Information regarding the end of support for Wildcard (*) in the Web API field configuration"
}
}