Logic App: Issue with OAuth Token Failure in Office 365 Outlook Connector

MP-9390 0 Reputation points
2026-09-30T15:43:57.6133333+00:00

Descrizione del problema

I am experiencing a problem with my Logic App (Standard) private that uses the Office 365 Outlook connector. The workflow, named Email_ingestion, fails during execution with the error 'WorkflowAppOAuthTokenFailure'. Although th api connection,, appears to be connected, the workflow cannot obtain a valid OAuth token to access the shared mailbox in the tenant where the mailbox is hosted.

Ambiente

Web App, Office 365 Outlook, Microsoft.Web/sites

Cosa ho già provato

I have examined the details of the case and the available diagnostic information. The connection appears to be established and in a connected state. I also verified that the API connection is reachable and the API connection resource shows no anomalies. I have not yet performed any configuration changes or token refresh attempts beyond initial setup.

Stato attuale

Currently, I am seeking assistance to confirm if the issue is related to tenant or consent misalignment, or if there are other configuration issues. I need guidance on how to verify the OAuth token acquisition process and how to troubleshoot the connection's authentication flow.

Azure Logic Apps
Azure Logic Apps

An Azure service that automates the access and use of data across clouds without writing code.


2 answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Allan Solomon Mejia 10,225 Reputation points
    2026-09-30T19:32:39.15+00:00

    Hi @MP-9390

    A Connected API connection does not, by itself, confirm that the workflow runtime can obtain and use the required token. In a Standard Logic App, a managed connector involves two authentication paths: one between the workflow and the managed API connection, and another between that connection and Office 365.

    Verify the following:

    1. Open the failed trigger in Run history and review its raw outputs. Capture the complete inner error, HTTP status, and any AADSTS code. WorkflowAppOAuthTokenFailure alone is insufficient to identify whether the failure is caused by the Logic App connection, Microsoft Entra Conditional Access, or Exchange mailbox authorization.
    2. In the Standard Logic App, open Workflows > Connections > API Connections and confirm that the workflow references the intended Office 365 connection. Standard workflows store the connection mapping in connections.json.
    3. If the Logic App or API connection was deployed through ARM/Bicep or another pipeline, verify that the managed API connection has an access policy for the Logic App’s managed identity. Every managed API connection used by a Standard workflow requires an associated access policy.
    4. Confirm that the account used to create the Office 365 Outlook connection belongs to the tenant hosting the mailbox and has access to that shared mailbox. Use an Outlook connector operation that explicitly supports shared mailboxes and enter the shared address in its Mailbox address parameter. Mailbox-permission changes can take approximately two hours to propagate.
    5. If the connector’s inner error is AADSTS53003, review the user’s Microsoft Entra sign-in logs and Conditional Access result. Conditional Access can block token issuance for this connector.

    If the connection mapping, access policy, and mailbox permissions are correct, reauthorize or recreate the Office 365 connection using the intended mailbox-enabled account and then reselect that connection in the workflow. Deleting and recreating the Outlook connection is among its shared-mailbox troubleshooting actions.

    Please provide the complete inner error from the failed trigger and indicate whether the Logic App/API connection was created in the portal or deployed through automation; that will distinguish a runtime access-policy failure from an Office 365 token or mailbox-permission failure.

    References:

    Authenticate Access for Connections

    View Workflow Status

    Edit and Manage Workflows

    API connection resources and access policies

    Shared Mailbox Support

    Office 365 Outlook Common Errors


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.