web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / securily launch extern...
Power Apps
Unanswered

securily launch external web requests

(0) ShareShare
ReportReport
Posted on by 32

Hi

 

we need to setup an external integration with a document storage solution. That solution has an external api. In order to have a reusable integration pattern, we propose to setup a logic app. I know that we could call out to that logic app via webhook trigger (or service hub, if we would put that in front of the logic app). However, they think sas tokens are not secure enough, and want to put API Management in front, with security based on Azure AD.

 

I was wondering what would be the safest way of calling that endpoint, since we now have to store clientid/secret somewhere, instead of the sas token. Working with keyvault seems to have the same issue (we could store the endpoint in there, but need some kind of identity to get the values).

 

An alternative i thought of was power automate, but since we have multiple triggers, we would have to create a flow for every (When record created). If we would have to create a plugin, then we have to code the authentication part (and perhaps store the token and its lifecycle somewhere).

 

What would be the most convenient and secure way to solve this in your opinion?

I assume Power Platform cannot be used with managed identities?

I have the same question (0)
  • EricRegnier Profile Picture
    8,720 Most Valuable Professional on at

    Hi @KimB,

    No, unfortunately Power Platform doesn't not support Managed Identities. A flow or logic app can have action that supports Managed Identities but not CDS or a flow itself. Also, unfortunately up-to-now native KeyVault integration with CDS/D365 is not supported. We usually integrate manually with KV via the KV Rest API and/or via an Azure Function to KV (with Managed Identities).

    Typically integration with an external system, if we cannot leverage Dataflows or Power Automate, the CDS best practice is Azure Service Bus Queues which is supported out-of-the-box but uses SAS Key... I never tried it yet authenticating a Queue with a SPN and not sure it supports it out-of-the-box...

    BTW with Power Automate and the "Common Data Service (current environment)" connector you can have multiple triggers in a flow: https://docs.microsoft.com/en-us/power-automate/connection-cds-native#:~:text=You%20must%20create%20solution%2Daware,records%20within%20Common%20Data%20Service.

     

    Hope this helps!

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Apps

#1
WarrenBelz Profile Picture

WarrenBelz 721 Most Valuable Professional

#2
Michael E. Gernaey Profile Picture

Michael E. Gernaey 320 Super User 2025 Season 2

#3
Power Platform 1919 Profile Picture

Power Platform 1919 268

Last 30 days Overall leaderboard