An Azure service that automates the access and use of data across clouds without writing code.
Hi @MP-9390
A Connected API connection does not, by itself, confirm that the workflow runtime can obtain and use the required token. In a Standard Logic App, a managed connector involves two authentication paths: one between the workflow and the managed API connection, and another between that connection and Office 365.
Verify the following:
- Open the failed trigger in Run history and review its raw outputs. Capture the complete inner error, HTTP status, and any AADSTS code. WorkflowAppOAuthTokenFailure alone is insufficient to identify whether the failure is caused by the Logic App connection, Microsoft Entra Conditional Access, or Exchange mailbox authorization.
- In the Standard Logic App, open Workflows > Connections > API Connections and confirm that the workflow references the intended Office 365 connection. Standard workflows store the connection mapping in connections.json.
- If the Logic App or API connection was deployed through ARM/Bicep or another pipeline, verify that the managed API connection has an access policy for the Logic App’s managed identity. Every managed API connection used by a Standard workflow requires an associated access policy.
- Confirm that the account used to create the Office 365 Outlook connection belongs to the tenant hosting the mailbox and has access to that shared mailbox. Use an Outlook connector operation that explicitly supports shared mailboxes and enter the shared address in its Mailbox address parameter. Mailbox-permission changes can take approximately two hours to propagate.
- If the connector’s inner error is AADSTS53003, review the user’s Microsoft Entra sign-in logs and Conditional Access result. Conditional Access can block token issuance for this connector.
If the connection mapping, access policy, and mailbox permissions are correct, reauthorize or recreate the Office 365 connection using the intended mailbox-enabled account and then reselect that connection in the workflow. Deleting and recreating the Outlook connection is among its shared-mailbox troubleshooting actions.
Please provide the complete inner error from the failed trigger and indicate whether the Logic App/API connection was created in the portal or deployed through automation; that will distinguish a runtime access-policy failure from an Office 365 token or mailbox-permission failure.
References:
Authenticate Access for Connections
API connection resources and access policies
Office 365 Outlook Common Errors
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.