← BACK TO PROJECTS
CASE STUDY / 04ENTRA ID / LOGIC APPS / GRAPH

Catch expiry. Before disruption.

Entra Credential Expiry Monitoring

Owner-aware monitoring for application secrets and certificates, with threshold alerts and stateful deduplication.

PROJECT STATUSEngineered solution
01 / CONTEXT

The challenge.

Engineering work by Daniel Moussa · Microsoft 365 Engineer

App-registration secrets and certificates can expire quietly and interrupt dependent applications. An inventory alone does not ensure the right person gets a useful warning at the right time.

THE OBJECTIVE

Design centralized daily monitoring for Microsoft Entra application credentials, with owner resolution, multiple expiry thresholds, expired-credential visibility, and controlled notifications.

02 / ARCHITECTURE

Follow the system.

Select a stage to explore its role in the architecture.

SYSTEM FLOW / SELECT A STAGE01 OF 05
STAGE 01

Daily trigger

Azure Logic Apps starts a scheduled credential-monitoring run.

03 / IMPLEMENTATION

What I built.

01

Application credential inventory

Microsoft Graph application enumeration with pagination and analysis of both secrets and certificates.

02

State-aware alerting

Multiple expiry thresholds, expired-credential detection, and Azure Table Storage notification tracking.

03

Ownership-based delivery

Application-owner resolution, fallback administrators, and consolidated per-application notifications.

04 / ENGINEERING DECISIONS

The choices that matter.

Make warnings actionable

Group relevant credentials by application so owners receive context they can act on.

Persist notification state

Track alerts to avoid repeatedly notifying people about the same threshold condition.

Account for missing ownership

Fallback administrators retain visibility when application-owner data is insufficient.

05 / SECURITY & GOVERNANCE

Controls, by design.

  • Managed identity authentication and least-privilege application permissions.
  • Scoped mail delivery and RBAC considerations.
  • Owner-scoped notifications with administrative fallback when ownership data is incomplete.
06 / RESULT & CURRENT STATE

Where the work stands.

A centralized monitoring and notification design that makes upcoming and existing credential expiry visible to appropriate stakeholders, with owner resolution and stateful alert deduplication.

Architecture is generalized. Client and operational details remain private.
CONTINUE EXPLORING / NEXT CASE STUDY

Intune & Defender Endpoint Security

All projects