Customer self-service portals
Order status, invoices, support cases, renewals and document downloads — the questions your inbox answers one at a time, answered by a site instead.
Power Pages development
The people who need your data most often work outside your tenant — customers checking an order, partners submitting a claim, applicants tracking a permit. We build the external-facing site they sign in to: Power Pages on your Dataverse tables, locked down with web roles and table permissions, for a fixed fee in a typical 2–4 weeks.
Representative dashboard — sample data
What we build
Every build below shares one trait: the primary user does not have a seat in your Microsoft 365 tenant.
Order status, invoices, support cases, renewals and document downloads — the questions your inbox answers one at a time, answered by a site instead.
Dealers, subcontractors, brokers and suppliers submitting orders, certificates of insurance or warranty claims into your systems, each seeing only their own records.
Permit applications, grant requests, event registration, RFP submissions — multi-step forms that write straight into your data, with save-and-resume for anonymous or signed-in visitors.
Relational tables, columns, choices and relationships designed for the portal and reusable everywhere else — not a second copy of your data that quietly drifts out of date.
External identity, anonymous access, and row-level rules that decide exactly which record each visitor can read, edit or never see — designed first, then tested as a hostile user would.
Your typography and colors applied through the design studio, keyboard-operable and screen-reader-friendly, and genuinely usable on the phone most external visitors will arrive with.
How it works
In a free consultation we establish who signs in, what each of them may see, and which Dataverse tables the portal reads and writes. You get a written scope with a fixed fee and a delivery date.
Pages, lists and multi-step forms take shape alongside the web roles and table permissions that guard them, with your team reviewing the site from a real external browser session, not a shared screen.
We test every role for over-exposure, wire the custom domain and certificate, publish, and stay on for 30 days of hypercare while your first real customers and partners arrive.
Power Pages is Microsoft's low-code platform for building secure websites aimed at people who are not employees, and Microsoft's Power Pages documentation (opens in new tab) frames it exactly that way: business-facing sites that surface Dataverse data to customers, partners and the general public. That external audience is what shapes the whole engagement. An internal app can lean on your tenant for identity and assume a degree of trust; a portal cannot assume either.
A finished engagement hands over a live site on your custom domain, the Dataverse tables and relationships behind it, the web roles and table permissions that govern access, authentication configured for your audience, branding applied in the design studio, the solution files under source control, and admin documentation covering how to add a role or edit a page. Timeline runs 2–4 weeks for most portals, the fee is fixed in your written scope, and 30 days of hypercare follow go-live.
The failure mode of a portal project is not an ugly page. It is a signed-in customer who can change a query string and read someone else's invoice. Power Pages guards against that with two stacked layers: web roles, which group external users (including a role for anonymous visitors), and table permissions (opens in new tab), which grant each role read, write, create, append or delete rights on a specific Dataverse table — scoped globally, to the contact's own records, to their account, or through a defined relationship.
We design that model before building pages, because retrofitting row-level access onto a finished site is how portals leak. Then we test it the way an attacker would: signed in as one contact, requesting another contact's record directly. Sign-in itself is configured to match the audience, whether that is Microsoft Entra External ID for business-to-consumer registration, local accounts, or a standards-based OpenID Connect or SAML provider your partners already use.
These two get confused constantly, and picking wrong is expensive in licensing and rework. The distinction is simply who the software is for.
| Consideration | Power Pages site | Power Apps app |
|---|---|---|
| Primary user | Customers, partners, applicants, the general public — people outside your organization | Your own staff, already licensed in your Microsoft 365 tenant |
| How they sign in | Anonymous browsing, self-registration, or external identity via Entra External ID, OpenID Connect or SAML | Their existing work account, with tenant conditional access applied |
| Access control model | Web roles plus Dataverse table permissions, scoped by contact, account or relationship | Dataverse security roles and business units, or SharePoint list permissions |
| Licensing shape | Per site, with capacity for authenticated and anonymous visitors | Per user, per app or per Power Platform plan for named staff |
| Typical build | Self-service portal, partner hub, public application or registration site | Inspection tool, case manager, quote builder, internal request app |
| Search engines can see it | Yes on public pages — indexable content is a design consideration | No; the app sits entirely behind tenant sign-in |
Many organizations end up running both on one Dataverse instance: staff work a case in an app while the customer watches its progress on the portal. If the tool you actually need is the internal one, our custom Power Apps built for your business workflows page covers canvas and model-driven builds for licensed staff, and it is the better starting point.
The clearest fit is an organization already on Microsoft 365 that fields the same external questions all day — where is my order, can you resend that certificate, has my application been reviewed — and answers them by hand from a shared mailbox. Manufacturers with dealer networks, contractors with subcontractor compliance packets, membership bodies, and public-sector teams taking applications all land here. If your external users are few and the process is simple, a form and a mailbox may still be the honest answer; we will say so during scoping rather than sell you a portal.
Portals rarely ship alone. What happens after a submission — routing it, approving it, notifying someone, generating a document — usually belongs in Power Automate approval and notification workflows running behind the site. Files that a portal collects or publishes often need a governed home, which is where a properly structured SharePoint document management setup earns its place. And once the portal accumulates real usage and submission data in Dataverse, a fixed-fee Power BI dashboard turns it into the adoption and cycle-time reporting leadership asks for. We are based in Orange County, CA and serve all US states remotely.
Related services
The internal counterpart: canvas and model-driven apps for your own licensed staff, on the same Dataverse tables.
Routing, approvals, notifications and document generation triggered by what your external users submit.
Governed libraries and intranets for the documents a portal publishes, collects, or hands back to staff.
FAQ
Power Pages builds secure external websites — customer portals, partner hubs, public self-service — for people outside your organization who sign in or browse anonymously. Power Apps builds internal apps for licensed staff. Both sit on Dataverse, so the same records can serve employees and customers through two very different front doors.
Access comes from two layers. Web roles group your external users, and table permissions grant each role read, write, create, or delete rights on specific Dataverse tables and their related records. Anonymous visitors get their own role. We configure and test both layers against real scenarios before any portal goes live.
Yes. Power Pages supports Microsoft Entra External ID for business-to-consumer sign-in, alongside local accounts and identity providers reached through OpenID Connect or SAML. We pick the mix that matches your audience, configure the sign-up and password-reset journeys, and test them from outside your tenant.
The build is a fixed fee quoted after a free consultation, based on pages, tables, security roles, and integrations. Running cost is separate: Microsoft licenses Power Pages per site, with capacity for authenticated or anonymous users. We size that with you during scoping so the monthly bill holds no surprises.
Most projects run two to four weeks: data model and security design first, then pages, forms, and lists, then branding, content, and testing with real external users on real devices. Thirty days of hypercare follow go-live, so the issues that only surface under genuine traffic are covered.
Often, yes. Power Automate handles what happens after a submission: routing, approvals, notifications, and document generation. SharePoint stores the files a portal collects when Dataverse file columns are not the right home. Neither is required on day one; we scope them only where the workflow genuinely needs them.
Book a free consultation
Tell us what you’re trying to fix — a report, an approval process, an intranet, a Copilot rollout. We scope it as a fixed-fee project, you approve, and a senior engineer delivers in 2–4 weeks.
The fastest way to reach us is the form — tell us the task and we’ll reply within one business day.