Error 403 on access to AD User from Azure Logic App

Viewed 1928

I want to manage my AD Users with an Azure Logic App and i have some trouble when i try to "get user" using the connector "get user" of Azure Active Directory.

"error": {
    "code": "ErrorInsufficientPermissionsInAccessToken",
    "message": "Exception of type 'Microsoft.Fast.Profile.Core.Exception.ProfileAccessDeniedException' was thrown.",

To "get user", i create a specific AD User (a Guest) with Global administrator role (so the user can create/update AD Users). After i put the Active Directory Connector "get user" and sign in with this user.

Did i miss something ?

1 Answers

Reason Of Your Error:

You are trying with personal account with guest privilege in that case need to set Object ID. I have tested and reproduce it. See the below screen shot:

enter image description here

Resolution Of Error:

Switch your connection like below:

enter image description here

User Tenant User Email:

You could try following way with tenant user credentials Like exampleUser@tenant.onmicrosoft.com instead of example@outlook.com or example@domain.com :

enter image description here

Point To Remember:

  1. Guest user has no privilege to perform this operation but with Object ID it can be done.
  2. User must be tenant specific user for example exampleUser@tenant.onmicrosoft.com

For more details you could take a look here

Related