<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Logic Apps on JanBakker.tech</title><link>https://janbakker.tech/categories/logic-apps/</link><description>Recent content in Logic Apps on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 10 Feb 2026 14:37:11 +0000</lastBuildDate><atom:link href="https://janbakker.tech/categories/logic-apps/index.xml" rel="self" type="application/rss+xml"/><item><title>Trigger Logic App on group membership changes in Entra ID</title><link>https://janbakker.tech/trigger-logic-app-on-group-membership-changes-in-entra-id/</link><pubDate>Sat, 11 Oct 2025 10:14:26 +0000</pubDate><guid>https://janbakker.tech/trigger-logic-app-on-group-membership-changes-in-entra-id/</guid><description>&lt;p&gt;A couple of years ago, I stumbled upon a neat Logic App / Power Automate connector that can respond to changes in group membership. &#10;&lt;a href="https://janbakker.tech/act-on-group-membership-changes-in-azure-active-directory/"&gt;Act on group membership changes in Azure Active Directory - JanBakker.tech&lt;/a&gt;&lt;br&gt;&#10;&lt;br&gt;&#10;Today, I&amp;rsquo;d like to give it some more love, since this is a very powerful, but underrated and probably also unknown piece of magic that will help you in a lot of automation scenarios. Especially when you are responsible for IAM Governance and lifecycle, but probably for a ton of other use cases.&lt;/p&gt;</description></item><item><title>Poor man’s IGA: Generate Temporary Access Pass for joiners</title><link>https://janbakker.tech/poor-mans-iga-generate-temporary-access-pass-for-joiners/</link><pubDate>Tue, 10 Jun 2025 18:31:40 +0000</pubDate><guid>https://janbakker.tech/poor-mans-iga-generate-temporary-access-pass-for-joiners/</guid><description>&lt;p&gt;This post is part of the &amp;ldquo;Poor Man&amp;rsquo;s IGA&amp;rdquo; series. The idea is simple: we pick one feature from the &#10;&lt;a href="https://m365maps.com/files/Entra-ID-Governance.htm" rel="noopener"&gt;Entra ID Governance&lt;/a&gt; stack, and think of an alternative, cheap(er) way to get it done. Why?&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Every organization deserves proper IAM tools.&lt;/li&gt;&#10;&lt;li&gt;Entra ID Governance is excellent, but too expensive for most organisations.&lt;/li&gt;&#10;&lt;li&gt;Get the most out of your existing license and built-in features.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Most of all, making solutions as outlined in the post is like playing with LEGO. You will have different building blocks that can also be (re)used in other processes. Working with Logic Apps, managed identities, and Graph API will give you great flexibility to create your own creative solutions.&lt;/p&gt;</description></item><item><title>Microsoft 365 end-user notifications for changes in authentication methods</title><link>https://janbakker.tech/microsoft-365-end-user-notifications-for-changes-in-authentication-methods/</link><pubDate>Wed, 21 Feb 2024 22:25:20 +0000</pubDate><guid>https://janbakker.tech/microsoft-365-end-user-notifications-for-changes-in-authentication-methods/</guid><description>&lt;p&gt;When moving away from traditional and weak authentication methods like passwords to stronger ones like Authenticator App and passkeys, it&amp;rsquo;s essential to keep informed when some of these methods change. Organizations moving to modern authentication are facing new challenges around onboarding and recovery of authentication methods, as attackers can also use this to settle in someone&amp;rsquo;s account by simply adding an extra authentication method. Entra ID will log this event, but no out-of-the-box feature informs the user.&lt;/p&gt;</description></item><item><title>A love story about Role Based Access Control for Applications in Exchange Online, Managed Identities, Entra ID Admin Units, and Graph API</title><link>https://janbakker.tech/a-love-story-about-role-based-access-control-for-applications-in-exchange-online-managed-identities-entra-id-admin-units-and-graph-api/</link><pubDate>Wed, 15 Nov 2023 21:41:34 +0000</pubDate><guid>https://janbakker.tech/a-love-story-about-role-based-access-control-for-applications-in-exchange-online-managed-identities-entra-id-admin-units-and-graph-api/</guid><description>&lt;p&gt;I&amp;rsquo;ve learned something new today. Hear me out.&lt;/p&gt;&#10;&lt;p&gt;Up until now, sending emails using managed identities trough Graph API was a bit of a hassle. You needed to grant access using Graph API or Powershell first, but before you could do that, you needed to find the correct IDs for Graph API, the Managed Identity, and the permission itself. Lucky for us, Jan Vidar spoiled us with &#10;&lt;a href="https://gotoguy.blog/2022/03/15/add-graph-application-permissions-to-managed-identity-using-graph-explorer/" rel="noopener"&gt;this nice blog post&lt;/a&gt;, which I used pretty often.&lt;/p&gt;</description></item><item><title>How to create a Temporary Access Pass using Logic Apps</title><link>https://janbakker.tech/how-to-create-a-temporary-access-pass-using-logic-apps/</link><pubDate>Sat, 21 Oct 2023 09:22:26 +0000</pubDate><guid>https://janbakker.tech/how-to-create-a-temporary-access-pass-using-logic-apps/</guid><description>&lt;p&gt;Now that more and more organizations are moving towards passwordless, a Temporary Access Pass becomes indispensable for onboarding and recovery. Using Logic Apps (or Power Automate), organizations can automate and integrate the creation of Temporary Access Passes in their current IT processes. Logic Apps can be triggered from customer service tools like ServiceNow or TOPdesk, to start fully automated workflows.&lt;/p&gt;</description></item><item><title>Mailbox usage reports, Graph API, and Logic Apps. What's not to like?</title><link>https://janbakker.tech/mailbox-usage-reports-graph-api-and-logic-apps-whats-not-to-like/</link><pubDate>Thu, 29 Dec 2022 17:40:37 +0000</pubDate><guid>https://janbakker.tech/mailbox-usage-reports-graph-api-and-logic-apps-whats-not-to-like/</guid><description>&lt;p&gt;Exchange Online does a pretty good job when it comes to alerting on mailbox storage. Exchange Online provides three kinds of notifications when a user&amp;rsquo;s mailbox is nearing or at capacity:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Warning&lt;/strong&gt;: The user receives an email warning that the mailbox is approaching the maximum size limit. This warning is intended to encourage users to delete unwanted mail.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Prohibit Send&lt;/strong&gt;: The user receives a prohibit-send notification email when the mailbox size limit is reached. The user can&amp;rsquo;t send new messages until enough email is deleted to bring the mailbox below the size limit.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Prohibit Send/Receive&lt;/strong&gt;: Exchange Online rejects any incoming mail when the mailbox size limit is reached and sends a non-delivery report (NDR) to the sender. The sender has the option to try resending the mail later. To receive messages again, the user must delete emails until the mailbox is below the size limit.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;And still, we find ourselves getting helpdesk tickets about mailboxes that can no longer send or receive email. It&amp;rsquo;s time to dive into the Exchange Storage reports. A good report can be downloaded from the Microsoft 365 admin center, but that is a manual action. What if we could download the report automatically, and use it to trigger some actions?&lt;/p&gt;</description></item><item><title>How to keep track of changes on Microsoft Docs &amp; Learn?</title><link>https://janbakker.tech/how-to-keep-track-of-changes-on-microsoft-docs-learn/</link><pubDate>Sun, 09 Oct 2022 21:01:04 +0000</pubDate><guid>https://janbakker.tech/how-to-keep-track-of-changes-on-microsoft-docs-learn/</guid><description>&lt;p&gt;When working with cloud services like Microsoft 365 or Azure Active Directory in particular, it&amp;rsquo;s very important to stay on top of new features and/or product changes. As you might know, the documentation for these services is stored on GitHub. This is where those changes will often reflect.&lt;/p&gt;</description></item><item><title>Automate issuing Temporary Access Pass for joiners with LifeCycle Workflows</title><link>https://janbakker.tech/automate-issuing-temporary-access-pass-for-joiners-with-lifecycle-workflows/</link><pubDate>Mon, 03 Oct 2022 13:31:49 +0000</pubDate><guid>https://janbakker.tech/automate-issuing-temporary-access-pass-for-joiners-with-lifecycle-workflows/</guid><description>&lt;p&gt;On September 30th, 2022, &#10;&lt;a href="https://twitter.com/pimjacobs89" rel="noopener"&gt;Pim Jacobs&lt;/a&gt; and I did a session on the brand new Lifecycle Workflows feature in Azure AD Identity Governance. During that session, I did a demo showing the integration with Logic Apps. Using this extension, I could use the Graph API to create a new Temporary Access Pass for a new hire, 7 days before the first workday. This post will describe the steps to build the solution.&lt;/p&gt;</description></item><item><title>Use Microsoft Graph Security for end-user notifications</title><link>https://janbakker.tech/use-microsoft-graph-security-for-end-user-notifications/</link><pubDate>Wed, 19 Aug 2020 13:11:23 +0000</pubDate><guid>https://janbakker.tech/use-microsoft-graph-security-for-end-user-notifications/</guid><description>&lt;p&gt;In this short blog post, I want to show how you can use the Microsoft Graph Security to send alerts and notifications to your end-users. I also want to show you that it is super easy to set up. All you need is:&lt;/p&gt;</description></item><item><title>Bulk dismiss risky users with Power Automate or Logic Apps</title><link>https://janbakker.tech/bulk-dismiss-risky-users-with-power-automate-or-logic-apps/</link><pubDate>Thu, 06 Aug 2020 07:48:02 +0000</pubDate><guid>https://janbakker.tech/bulk-dismiss-risky-users-with-power-automate-or-logic-apps/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update 08-10-2020:&lt;/strong&gt;&lt;/em&gt; Microsoft released an &#10;&lt;a href="https://docs.microsoft.com/en-us/connectors/azureadip/" rel="noopener"&gt;official connector for Azure AD Identity Protection&lt;/a&gt;. This would be much easier to use, since you don&amp;rsquo;t have to create a service principal to authenticate the custom connector. However, at the time of writing the official connector does not have the action to get all the risky users. Will keep an eye on things.&lt;/p&gt;&#10;&lt;/blockquote&gt;</description></item><item><title>Prepopulate phone methods using a Custom Connector in Power Automate</title><link>https://janbakker.tech/prepopulate-phone-methods-using-a-custom-connector-in-power-automate/</link><pubDate>Thu, 30 Jul 2020 07:30:00 +0000</pubDate><guid>https://janbakker.tech/prepopulate-phone-methods-using-a-custom-connector-in-power-automate/</guid><description>&lt;p&gt;This blog post shows the custom connector that is built on top of the Microsoft Graph API. With this connector, you can do bulk actions on Azure AD and provision phone numbers for your users. They can be used for MFA and SSPR. To understand how the connector works, please also read the first part of the blog where I explain the API in detail. In the second part, I have added a step-step-guide on how to create the custom connector and use it in an automation flow.&lt;/p&gt;</description></item><item><title>Prepopulate phone methods for MFA and SSPR using Graph API</title><link>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</link><pubDate>Thu, 30 Jul 2020 07:29:00 +0000</pubDate><guid>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</guid><description>&lt;p&gt;This blog post shows the custom connector that is built on top of the Microsoft Graph API. With this connector, you can do bulk actions on Azure AD and provision phone numbers for your users. They can be used for MFA and SSPR. To understand how the connector works, please also read the first part of the blog where I explain the API in detail. In the second part, I have added a step-step-guide on how to create the custom connector and use it in an automation flow.&lt;/p&gt;</description></item><item><title>Use Power Automate as your Conditional Access Police Department</title><link>https://janbakker.tech/use-power-automate-as-your-ca-police-department/</link><pubDate>Sat, 04 Jul 2020 07:10:42 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-as-your-ca-police-department/</guid><description>&lt;p&gt;Last week, I was working on a &#10;&lt;a href="https://janbakker.tech/microsoft-secure-score-series-14-designate-more-than-one-global-admin/"&gt;new blog for the Secure Score Series&lt;/a&gt; regarding global admin and break glass accounts. I came to the point where I was thinking of possible scenarios that could go wrong with these accounts. What if someone accidentally added these users to a certain group? What if that group would be triggered in some policy or maintenance tasks? A lot of these actions can be discovered using Microsoft Cloud App Security and Azure Monitor. This way, you will be alerted when someone touches the accounts in any way, or if the account is used to sign-in.&lt;/p&gt;</description></item><item><title>Use Power Automate or Logic Apps to keep an eye on your licenses</title><link>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</link><pubDate>Sat, 27 Jun 2020 18:37:43 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</guid><description>&lt;p&gt;I guess we&amp;rsquo;ve all been there; you ran out of licenses in your Azure AD or Office 365 tenant. Despite you hang out in your admin portal every day, you were still taken by surprise when you discover an issue, caused by a license shortage. More often this is caused by the fact that the people who are responsible to buy these licenses, are not always IT admins. So it&amp;rsquo;s easy to run out of licenses. Time to get this fixed.&lt;/p&gt;</description></item><item><title>Use Graph API data in Power BI using Logic Apps</title><link>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</link><pubDate>Sat, 09 May 2020 12:50:34 +0000</pubDate><guid>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</guid><description>&lt;p&gt;Some things in the modern connected world seem so common that you just assume it&amp;rsquo;s possible by nature. Getting your Microsoft Graph API data into Microsoft Power BI for example. That must be easy peasy right? Well&amp;hellip;.&lt;/p&gt;&#10;&lt;p&gt;When I start looking for ways to do this, I assumed there was a builtin connector available in Power BI that I could use. Guess what? There is not (yet). There is a connector for the &lt;strong&gt;Microsoft Security Graph&lt;/strong&gt;, but that one &amp;ldquo;only&amp;rdquo; gives back the data from the security products. Just good to know that it&amp;rsquo;s out there, but that&amp;rsquo;s not what we&amp;rsquo;re looking for.&lt;/p&gt;</description></item></channel></rss>