Create Team with run as account

%3CLINGO-SUB%20id%3D%22lingo-sub-1202378%22%20slang%3D%22en-US%22%3ECreate%20Team%20with%20run%20as%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1202378%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%C2%B4m%20quite%20new%20to%20automation%20in%20Azure%20but%20done%20a%20couple%20of%20thing%2C%20however%2C%20now%20we're%20about%20to%20create%20a%20standard%20to%20create%20a%20Team%20with%20a%20connected%20Planner%20from%20a%20%22template%22model%20for%20new%20customers%20so%20we%20can%20have%20a%20number%20of%20channels%20and%20a%20connected%20Planner%20with%20a%20number%20of%20pre-defined%20tasks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20obvious%20my%20way%20to%20go%20is%20to%20create%20a%20Azure%20Runbook%20and%20call%20it%20from%20a%20Power%20Automate%20flow.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%2C%20I've%20started%20with%20the%20first%20part%2C%20which%20is%20to%20create%20the%20Team%2C%20that's%20not%20an%20issue%20as%20long%20I'm%20using%20my%20admin-credentials%20before%2C%20but%20we're%20a%20CPS-partner%20and%20have%20forced%20MFA%20which%20can't%20have%20any%20exclusion%20so%20I%20need%20to%20come%20up%20with%20another%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20tried%20to%20read%20how%20to%20create%20an%20application%20and%20use%20Microsoft%20Graph%2C%20but%20it%20seems%20like%20it%20still%20need%20my%20credentials%3F%20Or%20am%20I%20doing%20anything%20wrong%3F%3C%2FP%3E%3CP%3EI've%20tried%20to%20use%20the%20RunAsAccount%20and%20gave%20that%20account%20access%20to%20both%20Microsoft%20Teams%20and%20Groups%2C%20both%20to%20create%20and%20view.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20is%20the%20command%20for%20now%3A%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3EParam%3C%2FSPAN%3E%3CSPAN%3E(%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%5Bstring%5D%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24teamname%3C%2FSPAN%3E%3CSPAN%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%23The%26nbsp%3Bname%26nbsp%3Bof%26nbsp%3Bthe%26nbsp%3Bteam%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%5Bstring%5D%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24teamowner%3C%2FSPAN%3E%3CSPAN%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%23Owner%26nbsp%3Bof%26nbsp%3Bthe%26nbsp%3Bteam%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%5Bstring%5D%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24mailnickname%3C%2FSPAN%3E%3CSPAN%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%23Mailadress%26nbsp%3Bof%26nbsp%3Bthe%26nbsp%3Btheam%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%3CSPAN%3E%5Bstring%5D%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24visibilty%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%23Visibility%26nbsp%3Bof%26nbsp%3Bthe%26nbsp%3Bteam%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3D%26nbsp%3BGet-AutomationConnection%26nbsp%3B-Name%26nbsp%3BAzureRunAsConnection%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EConnect-MicrosoftTeams%26nbsp%3B-Tenant%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.TenantID%26nbsp%3B%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E-ApplicationId%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.ApplicationID%26nbsp%3B-CertificateThumbprint%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.CertificateThumbprint%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%24newteam%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3D%26nbsp%3BNew-Team%26nbsp%3B-DisplayName%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24teamname%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B-Owner%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24teamowner%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B-Visibility%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24visibilty%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B-MailNickName%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24mailnickname%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edisconnect-microsoftteams%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EI%20get%20an%20internal%20error%20which%26nbsp%3BI%26nbsp%3Bcan't%20find%20any%20solution%20for%2C%20so%26nbsp%3BI%20tried%20to%20just%20fetch%20the%20groups%20we%26nbsp%3Bhave%20internally%20and%20see%20if%20that%20works%20with%20command%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CDIV%3E%3CDIV%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3D%26nbsp%3BGet-AutomationConnection%26nbsp%3B-Name%26nbsp%3BAzureRunAsConnection%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EConnect-MicrosoftTeams%26nbsp%3B-Tenant%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.TenantID%26nbsp%3B%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E-ApplicationId%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.ApplicationID%26nbsp%3B-CertificateThumbprint%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%24Conn%3C%2FSPAN%3E%3CSPAN%3E.CertificateThumbprint%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3Eget-team%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edisconnect-microsoftteams%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3EAnd%20on%20that%20command%26nbsp%3BI%20get%20following%20error%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CPRE%3E%3CSPAN%20class%3D%22azc-log-stream-text%20azc-text-stream-wrap-word-text%22%3EAccount%20%20%20%20%20%20%3A%2081a087e5-XXXXXXX-ec8f092%0AEnvironment%20%20%3A%20AzureCloud%0ATenant%20%20%20%20%20%20%20%3A%205f-XXXXXXXXXXXX-8c%0ATenantId%20%20%20%20%20%3A%205-XXXXXXXXXXXXXX-c%0ATenantDomain%20%3A%20xxxxx.xx%0AAn%20error%20occurred%20while%20fetching%20team%20with%20groupId%3A%209-bxxxxxxxx-6%0AError%20occurred%20while%20executing%20%0ACode%3A%20UnknownError%0AMessage%3A%20%0AInnerError%3A%0A%20%20RequestId%3A%208-xxxxxxxxx-c9%0A%20%20DateTimeStamp%3A%202020-02-29T12%3A56%3A41%0AHttpStatusCode%3A%20UnknownError%0AAn%20error%20occurred%20while%20fetching%20team%20with%20groupId%3A3xxxxxxxxxxxxx3%0AError%20occurred%20while%20executing%20%0ACode%3A%20UnknownError%0AMessage%3A%20%0AInnerError%3A%0A%20%20RequestId%3A%2038xxxxxxxxxxxxxxxxxxxb%0A%20%20DateTimeStamp%3A%202020-02-29T12%3A56%3A41%0AHttpStatusCode%3A%20UnknownError%3C%2FSPAN%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20this%20continues%20to%20the%20amount%20of%20Teams%20we%20have%20so%20it%20seems%20it%20can%20fetch%20some%20information%20but%20not%20everything%2C%20what%20have%20I%20done%20wrong%20or%20is%20it%20limitation%20in%20the%20service%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20can%20in%20that%20case%20use%20the%20App%20I%C2%B4ve%20created%20to%20connect%20to%20Graph%20API%20without%20my%20credentials%20since%20it%20won't%20work%20because%20the%20MFA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%2F%2FMartin%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1202378%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EApp%20Services%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAutomation%20%26amp%3B%20Control%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hi,

 

I´m quite new to automation in Azure but done a couple of thing, however, now we're about to create a standard to create a Team with a connected Planner from a "template"model for new customers so we can have a number of channels and a connected Planner with a number of pre-defined tasks.

 

So, obvious my way to go is to create a Azure Runbook and call it from a Power Automate flow.

 

But, I've started with the first part, which is to create the Team, that's not an issue as long I'm using my admin-credentials before, but we're a CPS-partner and have forced MFA which can't have any exclusion so I need to come up with another solution.

 

I've tried to read how to create an application and use Microsoft Graph, but it seems like it still need my credentials? Or am I doing anything wrong?

I've tried to use the RunAsAccount and gave that account access to both Microsoft Teams and Groups, both to create and view.

 

Here is the command for now:

Param(
    [string] $teamname#The name of the team
    [string] $teamowner#Owner of the team
    [string] $mailnickname#Mailadress of the theam
    [string] $visibilty #Visibility of the team
)
$Conn = Get-AutomationConnection -Name AzureRunAsConnection
Connect-MicrosoftTeams -Tenant $Conn.TenantID `
-ApplicationId $Conn.ApplicationID -CertificateThumbprint $Conn.CertificateThumbprint
 
$newteam = New-Team -DisplayName $teamname -Owner $teamowner -Visibility $visibilty -MailNickName $mailnickname
 
disconnect-microsoftteams
 
I get an internal error which I can't find any solution for, so I tried to just fetch the groups we have internally and see if that works with command:
$Conn = Get-AutomationConnection -Name AzureRunAsConnection
Connect-MicrosoftTeams -Tenant $Conn.TenantID `
-ApplicationId $Conn.ApplicationID -CertificateThumbprint $Conn.CertificateThumbprint

get-team
 
disconnect-microsoftteams
 
And on that command I get following error:
Account      : 81a087e5-XXXXXXX-ec8f092
Environment  : AzureCloud
Tenant       : 5f-XXXXXXXXXXXX-8c
TenantId     : 5-XXXXXXXXXXXXXX-c
TenantDomain : xxxxx.xx
An error occurred while fetching team with groupId: 9-bxxxxxxxx-6
Error occurred while executing 
Code: UnknownError
Message: 
InnerError:
  RequestId: 8-xxxxxxxxx-c9
  DateTimeStamp: 2020-02-29T12:56:41
HttpStatusCode: UnknownError
An error occurred while fetching team with groupId:3xxxxxxxxxxxxx3
Error occurred while executing 
Code: UnknownError
Message: 
InnerError:
  RequestId: 38xxxxxxxxxxxxxxxxxxxb
  DateTimeStamp: 2020-02-29T12:56:41
HttpStatusCode: UnknownError

 

And this continues to the amount of Teams we have so it seems it can fetch some information but not everything, what have I done wrong or is it limitation in the service?

 

How can in that case use the App I´ve created to connect to Graph API without my credentials since it won't work because the MFA.

 

//Martin

0 Replies