n8n Workflow: Entra ID Secret Expiry Alerts via Graph & Outlook
n8n Workflow: Entra ID Secret Expiry Alerts via Graph & Outlook
Regular price
£42.99
Regular price
£42.99
Sale price
Unit price
/
per
⬇
Instant Digital Download
∞
Unlimited Downloads
★
Lifetime Access in Your Account
Couldn't load pickup availability
🔥
128+ Sold
Popular with n8n builders
⚡
23 people viewing
High interest right now
✅
9 added today
Fast-moving digital product
n8n Workflow: Entra ID Secret Expiry Alerts via Graph & Outlook
Regular price
£42.99
Regular price
£42.99
Sale price
Unit price
/
per
Stay ahead of expiring Entra ID secrets & certificates—automatically
This n8n workflow checks Microsoft Entra ID (Azure AD) app registrations and enterprise apps every day for expiring or recently expired client secrets and certificates, then sends an HTML alert via Microsoft Outlook—with optional notifications to each application’s owners.
What this workflow does
- Runs daily at 07:00 using an n8n schedule to ensure consistent coverage.
- Scans Entra ID using Microsoft Graph to fetch app registrations and enterprise apps, including password credentials (client secrets) and key credentials (certificates), using pagination to process everything.
- Detects credential risk by flagging secrets/certificates that expire within a configured threshold or expired within a lookback window.
- Handles rotated credentials by optionally hiding credentials that already have a newer rotated successor.
- Enriches results with owners by looking up each affected app’s owners in Microsoft Graph, and keeps the item even if owner lookup fails.
- Generates an HTML summary report including credential status, expiry dates, owners, and direct links to the Entra admin center.
- Sends alerts via Microsoft Outlook to configured IT/security recipients and (if enabled) emails each affected owner separately.
Use cases
- Prevent authentication outages by proactively alerting teams before Entra ID secrets/certificates expire.
- Centralize credential hygiene across many app registrations and enterprise applications.
- Support SaaS operations teams that manage multiple integrations and want owner-level accountability.
Technical details
- Microsoft Graph access using an n8n Microsoft Entra Service Principal credential.
- Requires Graph permissions: Application.Read.All, User.Read.All, and Mail.Send (with admin consent).
- Workflow logic uses n8n nodes such as if, set, code, and merge (plus supporting nodes like sticky notes and HTTP Request for Graph calls).
Perfect for n8n automation engineers and SaaS operators who need reliable, Graph-powered Entra ID secret expiry monitoring with actionable Outlook email notifications.
