Copyright i3solutions. All Rights Reserved.
Email aski3@i3solutions.com, Phone 703.652.8966
Privacy Policy | Sitemap
Where should an Excel-to-web application be hosted, and how does that choice affect scalability and security?
You have approved the rebuild, and the first decision that is expensive to reverse is where the application runs. Hosting sets the ceiling on how far the converted application scales and the floor on how secure it can be made, unlike the conversion technique, which can be changed later. Four destinations are realistic: a Power Apps application on Microsoft Dataverse, a Power Pages site when the audience is outside your organization, a custom web application on Azure App Service backed by Azure SQL, or a third-party Excel-to-web platform such as Caspio or SpreadsheetWeb. The choice is decided by four inputs, in this order: who the users are, what regulates the data, how complex the calculation logic is, and how much the application has to integrate with systems of record. The first two settle most cases on their own: an audience outside your tenant takes Power Apps off the list, and a federal or export-control boundary takes every commercial multi-tenant platform off it before cost is discussed. i3solutions converts macro-heavy Excel workbooks either to Power Apps canvas or model-driven applications on Dataverse, or to a custom web application on Azure App Service backed by Azure SQL.
This page covers the hosting decision specifically. If you are earlier in the process and still deciding whether the spreadsheet should become an application at all, start with Excel to web application development.
What you are actually escaping
The published limits are rarely what forces the move. Microsoft documents a worksheet size of “1,048,576 rows by 16,384 columns” and a cell capacity of “32,767 characters,” and most business workbooks are nowhere near either. The concurrency limit is closer to the real problem: under the legacy shared workbook feature, 256 users can open the file at the same time, and long before that number the file has become a queue.
What actually forces the rebuild is governance. A spreadsheet has no server-side authorization model, no per-field audit trail, no controlled release path, and no way to prove to an assessor which version produced a number that appeared in a report. Those four gaps are the ones a hosting decision either closes or leaves open, which is why the hosting question deserves more attention than the conversion technique.
The four destinations, side by side
| Power Apps on Dataverse | Power Pages | Custom app on Azure App Service | Third-party Excel-to-web platform | |
|---|---|---|---|---|
| Audience it is built for | Internal, licensed users | External audiences, authenticated or anonymous | Any audience you design for | Any audience, typically unlimited by plan |
| How you pay | Per user per month | Per website, in user capacity packs | Azure consumption plus build cost | Per tenant per month by plan tier |
| Data store | Dataverse | Dataverse | Your choice, commonly Azure SQL | The vendor’s platform |
| Calculation complexity ceiling | Moderate, formula and flow based | Moderate, same platform | Effectively none, it is code | Bounded by the workbook engine |
| Network isolation options | Virtual network support via Managed Environments | Azure Front Door and IP restriction | VNet integration or a dedicated App Service environment | Vendor dependent, sometimes self-hosted |
| Where it fits best | Internal line-of-business processes on governed data | Portals, submissions, supplier and customer facing forms | Heavy calculation logic, deep integration, strict isolation | Wide audiences on lower-sensitivity data, fast time to live |
Option 1: Power Apps on Dataverse
When every user is inside your tenant and already licensed, this is the destination the other three have to beat. Microsoft hosts the application and its data. The security model is table and column level rather than file level, and the governance controls are the same ones your Power Platform administrators already operate.
The economics are per seat. Power Apps Premium lists at $20.00 user/month, paid yearly, and entitles the assigned user to unlimited Power Apps and Power Pages, with a $12.00 user/month tier at a 2,000-seat minimum. Storage accrues per license at 250 MB database and 2 GB file, and the Dataverse Database Capacity add-on lists at $40.00 GB/month, paid yearly. All four figures were read on that page on 2026-09-11. Microsoft Learn’s Power Apps overview, read the same day, is direct about the requirement: “You need a license to play the apps you make with Power Apps.” That single sentence is what rules this option out for wide external audiences and rules it in for a bounded internal team.
i3solutions selects Dataverse over SharePoint as the primary relational store when a client needs scalable high-volume transactional data, and holds application secrets in Azure Key Vault. A SharePoint list is a tempting destination for a converted workbook because it looks like a table, and it is the wrong destination for anything with real transaction volume or relational depth. The failure pattern is consistent enough to plan around: the pilot behaves, and then the joins the workbook used to do in its formulas have to be done in the application instead of in the store, so each additional related list adds another round trip and the slowdown lands in year two rather than in the pilot. The choice of store is part of the hosting decision, not a detail underneath it.
Option 2: Power Pages, when the users are outside your organization
Microsoft describes Power Pages as “a secure, enterprise-grade, low-code software as a service (SaaS) platform for creating, hosting, and administering modern external-facing business websites,” built on the same Dataverse data your internal apps use. If the converted spreadsheet is a submission form for suppliers, a rate calculator for customers, or an intake process for people who do not have accounts in your tenant, this is the destination that fits.
The pricing model changes shape, which is the point. Power Pages authenticated users are sold at $200.00 per website for 100 users/site/month, paid yearly, in capacity packs of 100. Anonymous users are $75.00 per website for 500 users/site/month, paid yearly, in capacity packs of 500. The authenticated plan carries 2 GB database capacity and 16 GB file capacity, the anonymous plan 0.5 GB database capacity and 4 GB file capacity, and Dataverse database and file capacity entitlements for subscription plans are pooled at the tenant level, all of it read on Microsoft’s Power Pages pricing page on 2026-09-11. In Microsoft’s own words, users “needing access to multiple Power Pages sites will require additional authenticated user capacity.”
The security posture is documented rather than inferred. Power Pages is hosted as Azure App Service, which carries ISO, SOC, and PCI DSS compliance; it supports TLS 1.2 with built-in Azure DDoS protection and dynamic IP restriction, and it can be fronted with Azure Front Door for edge caching and web application firewall capabilities. Authorization runs through web roles, table permissions, and page permissions, with authentication providers including Microsoft Entra External ID.
Option 3: A custom web application on Azure App Service
When the calculation logic is the product, this is the right answer. Some workbooks encode two decades of engineering judgment in formulas, iterative solvers, and macros that no low-code surface will reproduce faithfully. Rebuilding that as code and hosting it on Azure App Service keeps the logic exact and removes the formula-and-flow calculation ceiling that the low-code surfaces impose.
Azure App Service runs .NET, Java, Node.js, Python, and PHP on both Windows and Linux, or a custom container. For a regulated estate the relevant features are the enterprise ones: virtual network integration for secure ingress and egress, App Service environments for fully isolated applications on dedicated networking and VMs, deployment slots for predictable staged releases, autoscale against demand, and ISO, SOC, and PCI compliance. There is also a Managed Instance option that Microsoft positions for “legacy or infrastructure-bound web apps requiring Component Object Model (COM), registry access, Windows/Microsoft Installers (MSI), drive mapping, or stricter network boundaries,” which is worth knowing about when the old tool depends on a COM add-in that has to come along.
This is the path i3solutions took for a global aerospace and defense manufacturer whose cost estimating ran on spreadsheets. The rebuild used ASP.NET with a Razor MVC structure, Entity Framework, SQL Server, jQuery, and Power BI. The web-enabled estimating tool reduced rework by 30%, eliminating version mismatches and manual reconciliation across teams. Engineers now generate accurate cost estimates in a fraction of the time, saving approximately $250k annually in rework-related labor. When i3 rebuilt a spreadsheet-bound estimating process into a web application, it removed version-control errors across hundreds of estimates and cut approval cycles from five days to one. The full write-up is in the modernizing a legacy Excel tool into a web application case study.
Option 4: Third-party Excel-to-web platforms
These platforms, Caspio and SpreadsheetWeb among them, take the workbook itself as the input and publish it as a web application, keeping the formulas as the calculation engine. For a wide audience on lower-sensitivity data they are genuinely fast, and the pricing model is the reason to look at them. The constraint that rules them out is the compliance boundary: if the data is export controlled or sits inside a federal boundary, a commercial multi-tenant platform is not a candidate, and that is settled before speed enters the argument.
SpreadsheetWeb’s deployment models matter more than its price bands for a regulated buyer. Its pricing page, read 2026-09-11, offers a public cloud in which “We host your application and data on multi-tenant cloud infrastructure,” a Private Cloud that is “A dedicated SpreadsheetWeb instance on Microsoft Azure, managed by us,” with “no shared infrastructure,” and Server Licensing: “Install on your own servers, or on a dedicated EC2 or Azure instance you control. Workbooks, submitted data, and calculation all stay inside your perimeter.”
The evaluation question is not the price, it is where the compliance boundary lands. Under the Microsoft options the boundary is your tenant and your Azure subscription, and the attestations you already rely on carry over. Under a third-party platform the calculation engine and the data both sit in the vendor’s environment, so your compliance evidence becomes the vendor’s compliance evidence. Ask for current third-party attestations directly rather than inferring them: SpreadsheetWeb’s published pricing page, read 2026-09-11, states deployment options and names no security certification anywhere on it, which is a gap in that source rather than a finding about the product. That question is answerable in one email, and it should be answered before a shortlist becomes a decision.
The security dimensions that actually decide it
Identity. Internal users belong in Entra ID. External users need an external identity provider, which is the line between a Power Apps app and a Power Pages site. A platform that manages its own separate user list is a second identity estate to review.
Data residency and sovereign clouds. If the data is export controlled or covered by a federal boundary, this decides the option list before anything else does. i3solutions installs and helps configure applications inside IL4 and IL6 government cloud environments and other government networks, and no commercial multi-tenant SaaS platform is a candidate in that conversation.
Network isolation. Virtual network integration or a dedicated App Service environment for a custom application, virtual network support and IP firewall through Managed Environments on the Power Platform side, Azure Front Door in front of a Power Pages site.
Secrets and keys. Connection strings and API keys leave the workbook and belong in a managed store. i3solutions holds application secrets in Azure Key Vault as a matter of course.
Audit and evidence. The reason the rebuild is defensible at all is that the new host produces a record: who changed which value, when, and under which approval. Whether the destination you pick emits that record in a form your assessor accepts has a yes-or-no answer, and it costs far less to establish before the build than after it.
i3solutions has replaced Excel-based workflows in aerospace manufacturing, financial services, and healthcare environments, including organizations operating under CMMC obligations and ITAR export control requirements. i3solutions establishes Power Platform governance frameworks as part of every Excel modernization engagement.
The scalability dimensions to test before you commit
Concurrency. How many people use it at once, and does that number grow with the business or with the customer base. Seat-priced hosting fails at the second pattern. The 256-user shared-workbook ceiling you are leaving (Microsoft’s published limit) is the floor to design against, not the target.
Calculation weight. If a single submission triggers a long iterative computation, the host has to be able to scale compute independently of the interface, which favors the custom application.
Integration surface. Every system of record the application must read or write is a constraint on where it can live. Integration is also where the effort actually goes: a strong 70 percent of i3solutions engagements include some type of ETL process, behind the scenes and baked into almost everything i3solutions does.
Release cadence. How often the logic changes, and whether you can promote a change without downtime. Deployment slots on App Service and managed-solution pipelines on the Power Platform are the two mature answers.
Which host for which application
| The application you are converting | Host | The reason, and the caveat |
|---|---|---|
| Internal departmental process, defined team, governed data | Power Apps on Dataverse | Fastest to a governed result. Count the seats before assuming the price. |
| Submission or intake form for suppliers, customers, or the public | Power Pages | Priced per website in user capacity packs rather than by seat. The packs are assigned at the environment level. |
| Deep calculation logic, decades of embedded engineering judgment | Custom application on Azure App Service | The only option with no logic ceiling. It is a build, so scope it as one. |
| Export-controlled, IL4 or above, or a federal boundary | Custom application, or Power Platform in the relevant government cloud | The boundary decides before anything else does. Commercial SaaS is not a candidate. |
| Legacy tool with COM add-ins or installer dependencies | Azure App Service, Managed Instance | Microsoft documents it for web apps requiring COM, registry access, MSI, or drive mapping, in the App Service overview. |
| Wide audience, low data sensitivity, needs to be live this quarter | Third-party Excel-to-web platform | Unlimited-user pricing is the real advantage. Get the vendor’s current attestations in writing first. |
| Reporting and analysis, no transactions, no workflow | Probably none of the above | If nobody submits anything, the honest answer is a governed dataset and a Power BI report. |
The migration is the risk, not the hosting
Hosting decisions get the attention because they are architectural. The engagements that go wrong go wrong on the extraction. The business logic in a mature workbook is undocumented, and it includes hidden circular dependencies, brittle macros, and rules that only survive because one person remembers them. The failure mode is specific: the new application returns a number the old workbook did not, nobody can say which of the two is right, and the release stalls in parallel running while the difference is traced back through the formulas one at a time. The acceptance test that prevents it is agreed before the build rather than after: the workbook and the application are run against the same inputs, and every difference is traced to a named formula before the release proceeds.
i3solutions applies its proprietary Data-Lift Framework to Excel modernization: extracting the business logic embedded in the workbook, eliminating hidden circular dependencies, and refactoring brittle macros. i3solutions Excel modernization work uses custom data-parsing scripts, Power Query ETL, and internally built schema-mapping tools. Whichever host you choose, budget the extraction honestly, because it is the phase that determines whether the new application produces the same numbers as the old one.
The payoff shows up in more than accuracy. A federal research agency replaced paper wall charts and Excel spreadsheets with an automated program tracking database: the agency no longer needs their paper wall charts or excel spreadsheets and realized a 240% return on investment in the first year by eliminating this combined manual effort of approximately one full time employee. The program tracking case study covers how that was measured. In a separate modernization, retiring on-premises infrastructure eliminated approximately $500,000 per year in hosting, licensing, and maintenance costs, while enabling cloud scalability at no additional capital expense.
Where i3solutions fits
i3solutions has been a Microsoft partner since 1997, is a Microsoft Solutions Partner, and has completed more than 600 Microsoft platform implementations. On this class of work specifically, the relevant experience is that the hosting decision has been made in both directions: to Power Apps and Dataverse where the process is internal and governed, and to a custom application on Azure App Service backed by Azure SQL where the logic will not fit a low-code surface.
Related reading for the pieces of this decision that have their own page: Dataverse vs SQL Server covers the data store choice in depth, Excel vs SharePoint for data management covers the case where the answer is not an application at all, and Power Apps development services covers delivery on the Power Platform side.
If you are weighing two of these destinations against each other, settle the four inputs first: who the users are, what regulates the data, how complex the calculation logic is, and how much the application has to integrate with systems of record. A scoping conversation puts those four on the table, and the regulatory boundary alone decides the option list before anything else does.
If the four inputs point in two directions, the quickest way through is a conversation with someone who has made this call in both of them. Bring the workbook and the audience it serves, and ask which host they would pick and what would change that answer. If you are building the internal case rather than the architecture, ask for comparable engagements where the hosting decision went each way, and for a direct read on the extraction phase, which is the part that sets the schedule. Contact a senior architect
Frequently asked questions
Where should an Excel-to-web application be hosted?
Choose by audience and regulation first. Internal, licensed users on governed data belong on Power Apps with Dataverse. External or anonymous audiences belong on Power Pages, which is priced per website in user capacity packs rather than per seat. Applications whose calculation logic is the product, or that need strict network isolation, belong in a custom web application on Azure App Service backed by Azure SQL. Third-party Excel-to-web platforms suit wide audiences on lower-sensitivity data where speed to live outweighs owning the compliance boundary.
Does moving off Excel automatically make the data more secure?
No. It makes security possible, which the spreadsheet did not. The gain comes from what the host provides: server-side authorization at the row and column level, an identity provider you already govern, an audit record of who changed what, and a controlled release path. A converted application on a host with none of those is a spreadsheet with a login page.
Can we host it in SharePoint to avoid a new platform?
Sometimes, for small and non-transactional cases. i3solutions selects Dataverse over SharePoint as the primary relational store when a client needs scalable high-volume transactional data, and holds application secrets in Azure Key Vault. A SharePoint list resembles a table closely enough to be tempting and behaves nothing like one under transaction volume or relational depth, which is a problem that appears in year two rather than in the pilot.
How does hosting change what the application costs to run?
The pricing model changes shape by option. Power Apps is priced per user per month, so cost scales with seats and a bounded internal team is the case it fits. Power Pages is priced per website in user capacity packs, so cost scales with audience volume per website rather than with headcount. A custom application on Azure App Service costs Azure consumption plus the build. Third-party platforms bill a flat tier with unlimited application users. Model the three-year curve for your actual audience shape rather than comparing headline prices. The heuristic that settles it: if the user count grows with your headcount, seat pricing stays the cheaper shape; if it grows with your customer or supplier base, per-website or flat-tier pricing is the one to model first.
What about a legacy tool that depends on COM add-ins?
Azure App Service publishes a Managed Instance option that Microsoft documents for “legacy or infrastructure-bound web apps requiring Component Object Model (COM), registry access, Windows/Microsoft Installers (MSI), drive mapping, or stricter network boundaries.” It is the documented path when a dependency has to survive the move rather than be rewritten. The same App Service overview calls for validating telemetry, certificate automation, and operational processes before production adoption.
Can any of this run in a government cloud?
Yes, and the boundary should be the first input rather than a late constraint. i3solutions installs and helps configure applications inside IL4 and IL6 government cloud environments and other government networks. Confirm the option list against your boundary before evaluating anything else, because it removes most commercial multi-tenant platforms from consideration outright.
How long does the extraction phase take?
The schedule is set by how much undocumented logic the workbook carries, which is why it is assessed rather than estimated from file size. i3solutions applies its Data-Lift Framework to extract the business logic embedded in the workbook, eliminate hidden circular dependencies, and refactor brittle macros, using custom data-parsing scripts, Power Query ETL, and internally built schema-mapping tools. Plan for the extraction to be the phase that sets the schedule.
Sources
- Microsoft Support, Excel specifications and limits (worksheet size, cell character capacity, shared workbook concurrency)
- Microsoft, Power Apps pricing and Microsoft Learn, What is Power Apps?, both read 2026-09-11
- Microsoft, Power Pages pricing, read 2026-09-11; Microsoft Learn, What is Power Pages? and Power Pages capabilities, read August 2026
- Microsoft Learn, Overview of Azure App Service (runtimes, VNet integration, App Service environments, staging environments, compliance, Managed Instance) and Set up staging environments in Azure App Service (deployment slots), both read 2026-09-11
- Microsoft Learn, Managed environments overview (virtual network support, IP firewall, extended backup)
- Caspio, Pricing, read August 2026
- SpreadsheetWeb, Pricing, read 2026-09-11