<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Graph Api on JanBakker.tech</title><link>https://janbakker.tech/tags/graph-api/</link><description>Recent content in Graph Api on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 10 Feb 2026 14:37:11 +0000</lastBuildDate><atom:link href="https://janbakker.tech/tags/graph-api/index.xml" rel="self" type="application/rss+xml"/><item><title>A love story about Role Based Access Control for Applications in Exchange Online, Managed Identities, Entra ID Admin Units, and Graph API</title><link>https://janbakker.tech/a-love-story-about-role-based-access-control-for-applications-in-exchange-online-managed-identities-entra-id-admin-units-and-graph-api/</link><pubDate>Wed, 15 Nov 2023 21:41:34 +0000</pubDate><guid>https://janbakker.tech/a-love-story-about-role-based-access-control-for-applications-in-exchange-online-managed-identities-entra-id-admin-units-and-graph-api/</guid><description>&lt;p&gt;I&amp;rsquo;ve learned something new today. Hear me out.&lt;/p&gt;&#10;&lt;p&gt;Up until now, sending emails using managed identities trough Graph API was a bit of a hassle. You needed to grant access using Graph API or Powershell first, but before you could do that, you needed to find the correct IDs for Graph API, the Managed Identity, and the permission itself. Lucky for us, Jan Vidar spoiled us with &#10;&lt;a href="https://gotoguy.blog/2022/03/15/add-graph-application-permissions-to-managed-identity-using-graph-explorer/" rel="noopener"&gt;this nice blog post&lt;/a&gt;, which I used pretty often.&lt;/p&gt;</description></item><item><title>How to create a Temporary Access Pass using Logic Apps</title><link>https://janbakker.tech/how-to-create-a-temporary-access-pass-using-logic-apps/</link><pubDate>Sat, 21 Oct 2023 09:22:26 +0000</pubDate><guid>https://janbakker.tech/how-to-create-a-temporary-access-pass-using-logic-apps/</guid><description>&lt;p&gt;Now that more and more organizations are moving towards passwordless, a Temporary Access Pass becomes indispensable for onboarding and recovery. Using Logic Apps (or Power Automate), organizations can automate and integrate the creation of Temporary Access Passes in their current IT processes. Logic Apps can be triggered from customer service tools like ServiceNow or TOPdesk, to start fully automated workflows.&lt;/p&gt;</description></item><item><title>Manage user-preferred multi-factor authentication method in Microsoft Entra ID</title><link>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</link><pubDate>Tue, 11 Jul 2023 18:58:26 +0000</pubDate><guid>https://janbakker.tech/manage-user-preferred-multi-factor-authentication-method-in-microsoft-entra-id/</guid><description>&lt;p&gt;This post is all about setting the preferred multi-factor authentication method using Graph API. We already know the &#10;&lt;a href="https://janbakker.tech/system-preferred-multifactor-authentication-in-azure-ad-dont-settle-for-less/"&gt;system-preferred multi-factor authentication method&lt;/a&gt;, where Microsoft Entra ID will use the strongest method of all the registered methods, but this time we take a look a the default method set by the user.&lt;/p&gt;</description></item><item><title>Use Microsoft Graph Security for end-user notifications</title><link>https://janbakker.tech/use-microsoft-graph-security-for-end-user-notifications/</link><pubDate>Wed, 19 Aug 2020 13:11:23 +0000</pubDate><guid>https://janbakker.tech/use-microsoft-graph-security-for-end-user-notifications/</guid><description>&lt;p&gt;In this short blog post, I want to show how you can use the Microsoft Graph Security to send alerts and notifications to your end-users. I also want to show you that it is super easy to set up. All you need is:&lt;/p&gt;</description></item><item><title>Bulk dismiss risky users with Power Automate or Logic Apps</title><link>https://janbakker.tech/bulk-dismiss-risky-users-with-power-automate-or-logic-apps/</link><pubDate>Thu, 06 Aug 2020 07:48:02 +0000</pubDate><guid>https://janbakker.tech/bulk-dismiss-risky-users-with-power-automate-or-logic-apps/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update 08-10-2020:&lt;/strong&gt;&lt;/em&gt; Microsoft released an &#10;&lt;a href="https://docs.microsoft.com/en-us/connectors/azureadip/" rel="noopener"&gt;official connector for Azure AD Identity Protection&lt;/a&gt;. This would be much easier to use, since you don&amp;rsquo;t have to create a service principal to authenticate the custom connector. However, at the time of writing the official connector does not have the action to get all the risky users. Will keep an eye on things.&lt;/p&gt;&#10;&lt;/blockquote&gt;</description></item><item><title>Prepopulate phone methods for MFA and SSPR using Graph API</title><link>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</link><pubDate>Thu, 30 Jul 2020 07:29:00 +0000</pubDate><guid>https://janbakker.tech/prepopulate-phone-methods-for-mfa-and-sspr-using-graph-api/</guid><description>&lt;p&gt;This blog post shows the custom connector that is built on top of the Microsoft Graph API. With this connector, you can do bulk actions on Azure AD and provision phone numbers for your users. They can be used for MFA and SSPR. To understand how the connector works, please also read the first part of the blog where I explain the API in detail. In the second part, I have added a step-step-guide on how to create the custom connector and use it in an automation flow.&lt;/p&gt;</description></item><item><title>Use Power Automate or Logic Apps to keep an eye on your licenses</title><link>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</link><pubDate>Sat, 27 Jun 2020 18:37:43 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-or-logic-apps-to-keep-an-eye-on-your-licenses/</guid><description>&lt;p&gt;I guess we&amp;rsquo;ve all been there; you ran out of licenses in your Azure AD or Office 365 tenant. Despite you hang out in your admin portal every day, you were still taken by surprise when you discover an issue, caused by a license shortage. More often this is caused by the fact that the people who are responsible to buy these licenses, are not always IT admins. So it&amp;rsquo;s easy to run out of licenses. Time to get this fixed.&lt;/p&gt;</description></item><item><title>Use Graph API data in Power BI using Logic Apps</title><link>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</link><pubDate>Sat, 09 May 2020 12:50:34 +0000</pubDate><guid>https://janbakker.tech/use-graph-api-data-in-power-bi-using-logicapps/</guid><description>&lt;p&gt;Some things in the modern connected world seem so common that you just assume it&amp;rsquo;s possible by nature. Getting your Microsoft Graph API data into Microsoft Power BI for example. That must be easy peasy right? Well&amp;hellip;.&lt;/p&gt;&#10;&lt;p&gt;When I start looking for ways to do this, I assumed there was a builtin connector available in Power BI that I could use. Guess what? There is not (yet). There is a connector for the &lt;strong&gt;Microsoft Security Graph&lt;/strong&gt;, but that one &amp;ldquo;only&amp;rdquo; gives back the data from the security products. Just good to know that it&amp;rsquo;s out there, but that&amp;rsquo;s not what we&amp;rsquo;re looking for.&lt;/p&gt;</description></item><item><title>Use Power Automate for your custom "dynamic" groups</title><link>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</link><pubDate>Wed, 01 Apr 2020 19:52:46 +0000</pubDate><guid>https://janbakker.tech/use-power-automate-for-your-custom-dynamic-groups/</guid><description>&lt;h2 id="azure-ad-dynamic-groups"&gt;Azure AD Dynamic Groups&lt;a class="anchor" href="#azure-ad-dynamic-groups" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Dynamic groups in Azure AD are awesome. I use them a lot. Dynamic groups can create groups based on attributes. For example, you can create a group that includes all the users from the Sales Team. The query for the group would look like this:&lt;/p&gt;</description></item></channel></rss>