Many times, users/admins are not comfortable using their credentials being used as Connections. Some connectors do provide the ability to authenticate using Service Principal.
Let’s jump into this! 😊
Setting Up App Registration for Dynamics 365 CRM
Here’s how you setup an App Service to be used as a Service Principal for Dataverse connector in Power Automate –
- Go to the Azure Portal (https://portal.azure.com/) and the look for Azure Active Directory.
- In Azure Active Directory, look for App Registrations in the menu.
- Now, create a + New registration record.
- Now, give this App Registration a suitable name. And you can select your preferences on how the tenant type should be. I’ve left it to Single tenant or simplicity of the example.
- Now, once this is created, go to the API Permissions section.
- Now, look for a button to Add a permission.
- Then, select Dynamics CRM and select it.
- Once this is selected, you’ll get to select user_impersonation. Then, clicked Add permissions.
- Once added, you’ll see that the Status column is blank. Then, click on Grant admin consent for <TenantName>.
- Once you click on Grant admin consent button, you’ll be asked for confirmation. Confirm the same.
- Once you confirm, you’ll see the status as Granted as shown below.
- Then, go to Certificates and secrets. Once in that, click on + New client secret.
- You’ll be asked the the Description, do so and Save it.
- Now, you need to copy the value onto Notepad.
- Now, let’s move to adding this App Registration to the Power Platform Admin Center so that you can then give appropriate permissions so that it can be used for Authentication into Dataverse.
Add Application User in Power Platform Admin Center
Go to the Power Platform Admin Center (https://admin.powerplatform.microsoft.com/) and the to the Environments section and select the correct Dataverse environment –
- Select the environment which will have your Flow that will use the Dataverse connection in question.
And click Settings.
- Now, expand Users + permissions section and look for Application Users.
- Now, in Application Users, you’ll need to add the App Registration as a User and give Roles. Now, click on + New app user.
- Now, click on + Add an app.
- Now, any App Registration that has not yet been created in the current environment as user will automatically appear. Select the one you created – “Dataverse Service Principal” in this case and click on Add.
- Now, select the BU.
- Next, click on Security Roles’ pencil to give roles.
- I’m just giving System Administrator for simplicity of example.
- Now, you should be good to create this user. Click on Create.
- Finally, your Application Record will look like this –
- Now that your Application User is set in Dynamics / Power Platform Admin Center, you are all set to add this to authenticate the Dataverse Connector in Power Automate. Let’s do that!
Authenticating using Service Principle in Dataverse action
Now, let’s say you are starting a Flow with the Dataverse connector –
- Select the Dataverse trigger you want to use. I’ll pick a common one.
- Now, click on the three dots and look to add a new Connection if it already authenticated using the logged in user which is the default behavior.
- Now, you’ll see the option to select –
- Now, you’ll see these fields to fill in.
- Now, first give the connection itself a suitable name.
- Now, for Client ID – Go to the App Registration in Azure and look for the Client ID in the information section. It’ll look like this –
Paste it in the Client ID field and it’ll look like this –
- Now, look for Client Secret – open the Notepad where you saved the Secret we copied while creating the Client Secret record in Azure.
- Now, finally – Go to the App Registration record and you’ll find the Tenant ID here –
And paste is where it says Tenant. Now, Create this connection!
- Ensure that the Connection is selected.
- I’ll just add an extra variable in order to save this simple Flow and then we’ll create an Account (simple example if you see the screenshot below) in order to Run this Flow.
My Flow looks ready to be tested.
- Now, I’ll create an Account in my Dynamics 365 CRM.
- And the Flow would have Run already.
In order to ensure the connection is run by the Service Principal itself, you can do this –
- In advanced options, you can choose to “Run as” as “Flow owner“
- And when you check the details in the Flow Run, you can check the attribute in the trigger “RunAsSystemUserId“
- And if you check this GUID, it belongs to the Dataverse Service Principal user we set up.
And that’s how you can setup to run the Dataverse action to use Service Principal instead of user credentials!
Hope this was useful!
Here are some Power Automate posts you want to check out –
- Select the item based on a key value using Filter Array in Power Automate
- Select values from an array using Select action in a Power Automate Flow
- Blocking Attachment Extensions in Dynamics 365 CRM
- Upgrade Dataverse for Teams Environment to Dataverse Environment
- Showing Sandbox or Non Production Apps in Power App mobile app
- Create a Power Apps Per User Plan Trial | Dataverse environment
- Install On-Premise Gateway from Power Automate or Power Apps | Power Platform
- Co-presence in Power Automate | Multiple users working on a Flow
- Search Rows (preview) Action in Dataverse connector in a Flow | Power Automate
- Suppress Workflow Header Information while sending back HTTP Response in a Flow | Power Automate
- Call a Flow from Canvas Power App and get back response | Power Platform\
- FetchXML Aggregation in a Flow using CDS (Current Environment) connector | Power Automate
- Parsing Outputs of a List Rows action using Parse JSON in a Flow | Common Data Service (CE) connector
- Asynchronous HTTP Response from a Flow | Power Automate
- Validate JSON Schema for HTTP Request trigger in a Flow and send Response | Power Automate
- Converting JSON to XML and XML to JSON in a Flow | Power Automate