Skip to main content

Power Platform

Power Platform inventory is a sync type on the Azure integration. It reads environments, DLP (data) policies, canvas apps and their sharing, custom connectors, connections and Power Automate flows, using the same service principal as the rest of the Azure integration.

It needs one step the other Azure sync types do not: the app registration has to be registered with Power Platform as a management application. Until it is, every collection fails with 403 Forbidden even though the credential itself is valid.

Register the management application​

A Power Platform Administrator or Global Administrator does this once, signed in as themselves. A service principal cannot register itself, and Microsoft provides no Power Platform admin center option for it.

  1. In the Microsoft Entra admin center, open App registrations, select the app connected to the Azure integration and copy its Application (client) ID.

  2. Register it with PowerShell:

    Install-Module -Name Microsoft.PowerApps.Administration.PowerShell -Scope CurrentUser
    Add-PowerAppsAccount
    New-PowerAppManagementApp -ApplicationId <application-client-id>

    Or with a bearer token for the administrator's own user account:

    PUT https://api.bap.microsoft.com/providers/Microsoft.BusinessAppPlatform/adminApplications/<application-client-id>?api-version=2020-10-01
  3. Run the Power Platform sync again from Active Integrations.

No Entra ID changes are needed: no API permissions, no admin consent and no directory role.

This grant is admin-level​

Read this before registering

Microsoft treats a registered management application like a user holding the Power Platform Administrator role, and its permissions cannot be narrowed. The CyberOptix CTEM Platform only ever issues read (GET) calls with it, but the grant itself is not read-only.

Microsoft does not offer a read-only alternative today:

OptionWhy it does not work
Entra ID API permissionsThe Power Platform admin APIs do not use application permissions for service principals.
Entra ID Power Platform Administrator role on the service principalNot a documented way to authorize a service principal. Only the management application registration is.
Power Platform RBAC Power Platform reader role (preview)Read-only, but List Environments is excluded from RBAC, and the Power Apps, connector and Power Automate endpoints are not covered.
Power Platform APIHas no endpoint that lists DLP (data) policies.
Power Platform inventory APIRejects service principals with 403 Forbidden.

When Microsoft's RBAC covers these endpoints, the integration will move to the Reader role.

If an admin-level grant is not acceptable, leave the Power Platform sync type disabled. The rest of the Azure integration does not depend on it.

Power Automate flows​

Microsoft supports service principals on the Flow APIs only where no license is required. Flows can therefore still fail in some environments after registration. Those failures are reported per environment and do not stop the other collections.

Microsoft references​