web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / MFA Authentication or ...
Power Automate
Answered

MFA Authentication or APP Passwords

(0) ShareShare
ReportReport
Posted on by 34

One of my customer has MFA on all accounts including service accounts and their security team would not exclude service accounts from MFA. I am new to Power Automate. I do have some flows developed that runs on a schedule to connect to SharePoint online data source (lists and/or document libraries). It is using SharePoint HTTP connectors to complete the work. If I set this connector with Service account with MFA enabled

1. Does it cause problems? (will it keep asking for MFA authorization every time the flow runs?)

2. If it does, for Office 365 in turn for SharePoint, using App Passwords a reasonable alternative?

https://docs.microsoft.com/en-us/azure/active-directory/user-help/multi-factor-authentication-end-user-app-passwords

 

Can anyone shed some light for me?

 

Thanks

 

Categories:
I have the same question (0)
  • Verified answer
    eric-cheng Profile Picture
    5,171 on at

    Hi @bkk ,

     

    There are many factors depending on the policies setup in AAD which we wont know about.

     

    It is possible to adjust the token lifetime policy to reduce the times users will need to authenticate.   Please read here for more details.

     

    Just back on the topic of MFA conditional policies,  I am sure the security team is aware but it is possible to set MFA exclusions at a granular level e.g. to specific cloud services, from trusted devices, from the corporate network or whitelisted IPs.

     

    --------------------------------------------------------------------------
    If I have answered your question, please mark my post as a solution
    If you have found my response helpful, please give it a thumbs up

  • bkk Profile Picture
    34 on at

    Thanks Eric. Appreciate the information. Security is aware of the granular permissions and/or White listing of IP.  Security in this company (due to the business being in highly regulated industry), white listing huge blocks of IP is being ruled out. Granular permissions is something we are looking at.  This is a customer of mine, so I am trying to provide all options available and they can choose the best that fits them. I appreciate you providing a link that provides more details as well. Thanks for your time and help.

     

  • cbd Profile Picture
    2 on at

    Refreshing an old topic because I can't find a good answer to this question.

     

    My customer will not alter MFA policies for a service account. How do I handle token refreshes outside of telling them "sorry, you need to go in and manually fix connections on a regular basis."

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Power Automate

#1
trice602 Profile Picture

trice602 239 Super User 2026 Season 1

#2
David_MA Profile Picture

David_MA 177 Super User 2026 Season 1

#3
Kalathiya Profile Picture

Kalathiya 97 Super User 2026 Season 1

Last 30 days Overall leaderboard