Scenario
An automation workflow stops after a Conditional Access change begins applying MFA or device requirements to a service identity.
Recommended Resolution Path
- Confirm the identity should be a workload identity rather than a human user account.
- Exclude only the specific app or identity with documented justification.
- Move unattended auth to certificates, managed identity, or app registrations where possible.
- Add monitoring for sign-in failures to catch policy drift earlier.
Technician Notes
Confirm the business impact, document the root cause, and capture any preventative follow-up in the PSA or client knowledge base.
- Log in to post comments
Subjects