An Azure service that automates the access and use of data across clouds without writing code.
Hello AdamBudziski-8216,
The issue arises due to a fundamental limitation in how Azure Event Grid interacts with Logic Apps (Consumption) when OAuth authentication is enforced. While Logic Apps support disabling SAS-based authentication in favor of OAuth (Bearer tokens), Event Grid’s webhook delivery mechanism does not yet support sending events with OAuth tokens to Consumption-tier Logic Apps. Instead, Event Grid relies on SAS tokens for authentication when invoking Logic App HTTP triggers.
This creates a conflict: If SAS is disabled, Event Grid cannot deliver events, yet enabling SAS reintroduces security risks. The problem does not exist in Logic Apps (Standard), which supports Managed Identity authentication for Event Grid. However, Consumption Logic Apps lack this capability, forcing users to either re-enable SAS (with manual token validation) or introduce an intermediary service (like Azure Functions) to handle OAuth authentication before forwarding events.
There are few alternatives you may try, as I have provided below options:
Option 1: Re-enable SAS (Temporarily) & Use Event Grid Validation
- Re-enable SAS in your Logic App (either via ARM template or the portal).
- Configure an Event Grid subscription using the SAS-based URL.
- Add manual OAuth validation inside the Logic App:
- Use an "HTTP Request" trigger (instead of the built-in Event Grid trigger).
- Add a "Parse JSON" action to extract the Authorization header.
- Use a "Condition" action to validate the Bearer token (if present).
- If the token is missing/invalid, reject the request.
Option 2: Use an Intermediate Azure Function (Recommended) - Since Event Grid does support OAuth for Azure Functions, you can:
Create an Azure Function with an Event Grid trigger.
Configure OAuth (Bearer token) authentication for the Function.
Forward the event to your Logic App (using its OAuth-protected endpoint).
This way, Event Grid authenticates with the Function (OAuth), and the Function forwards the event to the Logic App (also OAuth).
If the above answer helped, please do not forget to "Accept Answer" as this may help other community members to refer the info if facing a similar issue. Your contribution to the Microsoft Q&A community is highly appreciated.