Hi,
I have a tenant in which MFA has been activated for all users. I have created a user to run all my flows, but the flows breaks after a while and the only message i see is "Invalid connection". I assume this is because of MFA. Are there anyway to handle this or do i have to disable MFA for that specific user ?
Solved! Go to Solution.
This solution should work for customers that use Microsoft Flow and service accounts for running the flow: https://blog.peterdahl.net/2018/01/09/microsoft-flow-and-azure-conditional-access-azure-mfa/
I still need feedback from Microsoft around a solution that will work for end-users.
/Peter Selch Dahl
Hi @Bjarke,
I’m afraid that it might be caused by MFA authentication.
Please suggest your user try to refresh their connections to see if it will work.
There is a similar issue on this thread, Staff @TravisB has some suggestion on it. Please check it for more details:
https://powerusers.microsoft.com/t5/General-Flow-Discussion/Flow-Connections-error-due-to-Credential...
Best regards,
Mabel Mao
This solution should work for customers that use Microsoft Flow and service accounts for running the flow: https://blog.peterdahl.net/2018/01/09/microsoft-flow-and-azure-conditional-access-azure-mfa/
I still need feedback from Microsoft around a solution that will work for end-users.
/Peter Selch Dahl
Peter's answer was the fix we needed to bypass Azure Conditional Access(MFA) in order to keep Flows running. In case anyone needs the Flow IPs formatted for MFA exceptions, here is the US list formatted and sorted. This is for the Logic App Service IP List from Peter's Flow Limits and Configuration link.
13.91.252.184/32
13.92.98.111/32
40.114.82.191/32
40.117.99.79/32
40.117.100.228/32
40.118.241.243/32
40.118.244.241/32
40.121.91.41/32
52.160.90.237/32
52.160.92.112/32
137.135.106.54/32
138.91.188.137/32
- Dan
Great to hear that it resolved your issue. I know that Microsoft is aware of the issue and that this solution is not the best in the world. I gets the job done for now 🙂
Only works if you have Azure AD premium though, otherwise you can't add a policy.
Another solution would be to support app passwords?
Hi all,
Is this issue still current? If so, do we know if Microsoft is planning to solve this issue?
Thanks in advance for any insights.
KR,
Lucas
Hi Peter - thanks for this post. Are you aware of any negative security consequences that could arise from bypassing MFA in this fashion?
I'd take a guess that generally speaking it's never good practice to "bypass" security. So this is not a great workaround. Understandable if absolutely required to continue using Flows that are running key business processes/applications etc.
Hi Lucas - I would say the problem is still current unless you pay up for the expanded Azure rights so allow conditional access.
I reduced the issue on my end by increasing the reprompt issue from 2 days to the maximum allowed. Not an ideal sitation by any means.
Yes. This is in no way best practice from a security point of view. The workaround would allow potential hackers to execute code or task using Microsoft Flow without requiring to prove their identity using two factor authentication. I would also recommend using this solution as a last resort. I hope that Microsoft will find a solution for this issue. Many other Microsoft services are also strungling with delegated credentials / doing stuff on behalf of users as most of these require passive authentication flows.
/Peter
Thank you!
It helped me to solve my problem!
Addresses for EU:
13.69.227.208/28
13.69.64.208/28
52.174.88.118/32
52.178.150.68/32
137.117.161.181/32
Hi,
Just a quick follow up, is this issue resolved with Microsoft?
What is the solution?
Episode Seven of Power Platform Connections sees David Warner and Hugo Bernier talk to Dian Taylor, alongside the latest news, product reviews, and community blogs. Use the hashtag #PowerPlatformConnects on social media for a chance to have your work featured on the show.
Super Users – 2023 Season 1 We are excited to kick off the Power Users Super User Program for 2023 - Season 1. The Power Platform Super Users have done an amazing job in keeping the Power Platform communities helpful, accurate and responsive. We would like to send these amazing folks a big THANK YOU for their efforts. Super User Season 1 | Contributions July 1, 2022 – December 31, 2022 Super User Season 2 | Contributions January 1, 2023 – June 30, 2023 Curious what a Super User is? Super Users are especially active community members who are eager to help others with their community questions. There are 2 Super User seasons in a year, and we monitor the community for new potential Super Users at the end of each season. Super Users are recognized in the community with both a rank name and icon next to their username, and a seasonal badge on their profile. Power Apps Power Automate Power Virtual Agents Power Pages Pstork1* Pstork1* Pstork1* OliverRodrigues BCBuizer Expiscornovus* Expiscornovus* ragavanrajan AhmedSalih grantjenkins renatoromao Mira_Ghaly* Mira_Ghaly* Sundeep_Malik* Sundeep_Malik* SudeepGhatakNZ* SudeepGhatakNZ* StretchFredrik* StretchFredrik* 365-Assist* 365-Assist* cha_cha ekarim2020 timl Hardesh15 iAm_ManCat annajhaveri SebS Rhiassuring LaurensM abm TheRobRush Ankesh_49 WiZey lbendlin Nogueira1306 Kaif_Siddique victorcp RobElliott dpoggemann srduval SBax CFernandes Roverandom schwibach Akser CraigStewart PowerRanger MichaelAnnis subsguts David_MA EricRegnier edgonzales zmansuri GeorgiosG ChrisPiasecki ryule AmDev fchopo phipps0218 tom_riha theapurva takolota Akash17 momlo BCLS776 Shuvam-rpa rampprakash ScottShearer Rusk ChristianAbata cchannon Koen5 a33ik Heartholme AaronKnox okeks Matren David_MA Alex_10 Jeff_Thorpe poweractivate Ramole DianaBirkelbach DavidZoon AJ_Z PriyankaGeethik BrianS StalinPonnusamy HamidBee CNT Anonymous_Hippo Anchov KeithAtherton alaabitar Tolu_Victor KRider sperry1625 IPC_ahaas zuurg rubin_boer cwebb365 Dorrinda G1124 Gabibalaban Manan-Malhotra jcfDaniel WarrenBelz Waegemma drrickryp GuidoPreite If an * is at the end of a user's name this means they are a Multi Super User, in more than one community. Please note this is not the final list, as we are pending a few acceptances. Once they are received the list will be updated.
Join us for an in-depth look into the latest updates across Microsoft Dynamics 365 and Microsoft Power Platform that are helping businesses overcome their biggest challenges today. Find out about new features, capabilities, and best practices for connecting data to deliver exceptional customer experiences, collaborating, and creating using AI-powered capabilities, driving productivity with automation—and building towards future growth with today’s leading technology. Microsoft leaders and experts will guide you through the full 2023 release wave 1 and how these advancements will help you: Expand visibility, reduce time, and enhance creativity in your departments and teams with unified, AI-powered capabilities.Empower your employees to focus on revenue-generating tasks while automating repetitive tasks.Connect people, data, and processes across your organization with modern collaboration tools.Innovate without limits using the latest in low-code development, including new GPT-powered capabilities. Click Here to Register Today!
We are excited to share the ‘Power Platform Communities Front Door’ experience with you! Front Door brings together content from all the Power Platform communities into a single place for our community members, customers and low-code, no-code enthusiasts to learn, share and engage with peers, advocates, community program managers and our product team members. There are a host of features and new capabilities now available on Power Platform Communities Front Door to make content more discoverable for all power product community users which includes ForumsUser GroupsEventsCommunity highlightsCommunity by numbersLinks to all communities Users can see top discussions from across all the Power Platform communities and easily navigate to the latest or trending posts for further interaction. Additionally, they can filter to individual products as well. Users can filter and browse the user group events from all power platform products with feature parity to existing community user group experience and added filtering capabilities. Users can now explore user groups on the Power Platform Front Door landing page with capability to view all products in Power Platform. Explore Power Platform Communities Front Door today. Visit Power Platform Community Front door to easily navigate to the different product communities, view a roll up of user groups, events and forums.
We are so excited to see you for the Microsoft Power Platform Conference in Las Vegas October 3-5 2023! But first, let's take a look back at some fun moments and the best community in tech from MPPC 2022 in Orlando, Florida. Featuring guest speakers such as Charles Lamanna, Heather Cook, Julie Strauss, Nirav Shah, Ryan Cunningham, Sangya Singh, Stephen Siciliano, Hugo Bernier and many more. Register today: https://www.powerplatformconf.com/
User | Count |
---|---|
13 | |
12 | |
12 | |
11 | |
8 |
User | Count |
---|---|
27 | |
24 | |
19 | |
19 | |
18 |