Power Platform
Power Platform inventory is a sync type on the Azure integration. It reads environments, DLP (data) policies, canvas apps and their sharing, custom connectors, connections and Power Automate flows, using the same service principal as the rest of the Azure integration.
It needs one step the other Azure sync types do not: the app registration has to be
registered with Power Platform as a management application. Until it is, every
collection fails with 403 Forbidden even though the credential itself is valid.
Register the management application
A Power Platform Administrator or Global Administrator does this once, signed in as themselves. A service principal cannot register itself, and Microsoft provides no Power Platform admin center option for it.
-
In the Microsoft Entra admin center, open App registrations, select the app connected to the Azure integration and copy its Application (client) ID.
-
Register it with PowerShell:
Install-Module -Name Microsoft.PowerApps.Administration.PowerShell -Scope CurrentUserAdd-PowerAppsAccountNew-PowerAppManagementApp -ApplicationId <application-client-id>Or with a bearer token for the administrator's own user account:
PUT https://api.bap.microsoft.com/providers/Microsoft.BusinessAppPlatform/adminApplications/<application-client-id>?api-version=2020-10-01 -
Run the Power Platform sync again from Active Integrations.
No Entra ID changes are needed: no API permissions, no admin consent and no directory role.
This grant is admin-level
Microsoft treats a registered management application like a user holding the Power
Platform Administrator role, and its permissions cannot be narrowed. The CyberOptix CTEM Platform only
ever issues read (GET) calls with it, but the grant itself is not read-only.
Microsoft does not offer a read-only alternative today:
| Option | Why it does not work |
|---|---|
| Entra ID API permissions | The Power Platform admin APIs do not use application permissions for service principals. |
| Entra ID Power Platform Administrator role on the service principal | Not a documented way to authorize a service principal. Only the management application registration is. |
| Power Platform RBAC Power Platform reader role (preview) | Read-only, but List Environments is excluded from RBAC, and the Power Apps, connector and Power Automate endpoints are not covered. |
| Power Platform API | Has no endpoint that lists DLP (data) policies. |
| Power Platform inventory API | Rejects service principals with 403 Forbidden. |
When Microsoft's RBAC covers these endpoints, the integration will move to the Reader role.
If an admin-level grant is not acceptable, leave the Power Platform sync type disabled. The rest of the Azure integration does not depend on it.
Power Automate flows
Microsoft supports service principals on the Flow APIs only where no license is required. Flows can therefore still fail in some environments after registration. Those failures are reported per environment and do not stop the other collections.