Exchange Online Certificate Limitations
1 min
the limitations below relate to the use of application only authentication , where activate connects to microsoft services using an application identity rather than operating as a signed in user activate uses this model for automated integrations such as exchange online, where certificate based app only authentication can be used with scoped permissions and rbac limitation what this relates to activate impact group photos cannot be set or read microsoft does not expose all group photo operations to applications using application only authentication these operations are generally associated with interactive or delegated microsoft 365 functionality rather than identity lifecycle administration not applicable activate does not use group photos as part of user provisioning, group management, access management, or identity lifecycle workflows the inability to read or update a group's photo therefore has no functional impact on activate group labels cannot be assigned or used some microsoft 365 group metadata and labelling functionality is unavailable or restricted when operating through an application identity this can include functionality intended to be applied within an interactive microsoft 365 user experience rather than through an automated identity management process not applicable activate does not rely on microsoft 365 group labels when creating, updating, assigning membership to, or otherwise managing groups existing activate identity management workflows are therefore unaffected some cmdlets requiring user context are unsupported certain microsoft powershell cmdlets are designed to run in the context of an authenticated user they may depend on information about the current signed in user or require a delegated user token and therefore cannot be executed using app only authentication not applicable to currently supported activate operations activate's automated workflows are designed around operations that can be performed using service or application identities cmdlets that specifically require an interactive user context are not used as part of the supported automated provisioning and lifecycle management processes activate documentation also identifies certificate based app only authentication as the authentication model for exchange online integrations where applicable actions requiring user mfa or delegated permissions are unsupported application only authentication has no interactive user session as a result, an operation that requires an individual user to authenticate, complete an mfa challenge, consent interactively, or provide a delegated permission cannot be performed by the background application identity this is distinct from authentication to the activate user portal, where end users can authenticate through entra id using oidc/oauth2, conditional access and mfa not applicable to activate's automated identity management actions background provisioning and lifecycle operations are intentionally designed to run without an interactive user session where a person interacts directly with the activate portal, that user's authentication and mfa requirements are handled separately through entra id an activate automation therefore does not need to impersonate a user or complete an mfa challenge on the user's behalf