Tracing Undocumented Application Users in Dataverse
A client secret expiry notice landed in our inbox recently, and what should have been a five minute renewal turned into a proper archaeology exercise. The environment had a handful of Application Users sitting in the Power Platform admin centre with names like D365 Integration User and Dynamics Connect . Perfectly sensible names, except nobody currently on the team could say what they were actually connected to. No documentation, no runbook, no owner listed anywhere. Just an app registration in Entra ID with a secret ticking down towards expiry. The obvious problem: if you rotate a secret without knowing what consumes it, you find out what consumes it the hard way, usually at the worst possible time. And if you leave it alone, the integration breaks anyway when the secret expires. So the question became: how do you work out where an Application User is being used inside Dynamics 365 when there is nothing external telling you? Why the Admin Centre Doesn't Help Here The first pl...


