Get started with CLI Microsoft 365 for Power Platform people
tl;dr
CLI for Microsoft 365 is an amazing tool to manage your Microsoft 365 tenant and SPFx projects. But did you know, that also people working with Power Platform can massively benefit from using it?
To convince you, I chose a use case, that will probably relate to lots of people, but please be aware, that CLI for Microsoft can do so much more!
Use case: App registrations in Azure Active Directory
Very often when working with Power Automate or Power Apps, we want to leverage the power of Microsoft Graph API. To do so, we need to authenticate against Graph using Azure Active Directory (Azure AD) and register an application in the Azure portal at portal.azure.com. Depending on permissions, redirect URI, secret etc. we need to perform several steps and take note of certain outputs. Wouldn’t it be nice if the entire app registration process was rather a one line command that automatically outputs the values we need?
After installing CLI Microsoft 365 and logging in, all we need to do is
m365 aad app add `
--name 'myApp001' `
--redirectUris 'https://global.consent.azure-apim.net/redirect' `
--platform web `
--withSecret `
--apisDelegated 'https://graph.microsoft.com/People.Read.All' `
--grantAdminConsent `
What this does is registering an application with the following parameters:
- Displayname of the app is
myApp001 - Redirect URI is
https://global.consent.azure-apim.net/redirectthat is what you need for custom connectors in Power Platform - It does create a secret (and will output it)
- It has delegated permissions for
People.Read.Allon Graph API - Admin consent is already granted
If we run this command (and we can do this as one-line as well without the backticks ` at the end of each line)
m365 aad app add --name 'myApp001' --redirectUris 'https://global.consent.azure-apim.net/redirect' --platform web --withSecret --apisDelegated 'https://graph.microsoft.com/People.Read.All' --grantAdminConsent
we get the following output:
{
"appId": "164298a8-504c-4234-a43a-XXXXXXXXXXXX",
"objectId": "02b7577e-4d6b-478a-b34c-XXXXXXXXXXXX",
"tenantId": "b469e370-d6a6-45b5-928e-XXXXXXXXXXXX",
"secrets": [
{
"displayName": "Default",
"value": "XXXXX~5FUlgaKtYEAJ-XXXXX~DWsnj6yerYATXXX"
}
]
}
which means, that we can use appId and the value of the secret in our custom connector or in the HTTP action of our Power Automate flow.
Get started with CLI for Microsoft 365
If you now want to try this out as well, you need to follow these steps:
- Install node.js
With node.js comes npm and we will install CLI for Microsoft 365 with npm. If you don’t have npm or node.js installed:
- Open node.js
- Select 18.12.1 LTS
- Install node.js
- Install CLI for Microsoft 365
- Open a terminal of your choice, I use the built-in terminal of Visual Studio Code
- Type
npm i -g @pnp/cli-microsoft365to install CLI for Microsoft 365 globally
- Login
- To login, type
m365 login - You will see a message like this:
"To sign in, use a web browser to open the page https://microsoft.com/devicelogin and enter the code BAVUYWLZ3 to authenticate."- Do exactly that. Copy that code, open the URL and paste the code. - Select Next
- To login, type

Now log into the tenant you want to connect with using your username and password (+ optional MFA)

You can close the https://login.microsoftonline.com/common/oauth2/deviceauth page again
đź’ˇ Until you type m365 logout, you will stay logged in.
- Try out to register an app
Now lets see if that worked! Register your own application and validate in the Azure portal.
Feedback and what’s next?
If you liked this experience, maybe you want to dip your toes even a bit further into CLI for Microsoft 365 - here is why you should absolutely consider that:
- it’s open-source and we are all here to learn
- it’s an amazing project with the most awesome contributors
- it has a lot of super-helpful commands around Power Apps, Power Automate, and more in Power Platform - more to come! Any ideas?
Published on:
Learn moreRelated posts
You are holding GitHub Copilot Wrong!
Part 0 showed why constant prompting, re-prompting, and steering GitHub Copilot feels fragile. Not because Copilot is unreliable, but because ...
You are holding GitHub Copilot Wrong!
Most developers think that one can’t really use GitHub Copilot wrong. There is a chat interface that lets you also choose a model, so th...
Building a Multi-Hierarchy Ticket Classification System (Because Keywords Aren't Enough)
Look, I love a good keyword-based system as much as the next developer. They’re fast, predictable, and when your user says “VPN,&r...
Secretless cross-tenant dataverse access
Client secrets are like hiding your house key under the mat; easy to grab and impossible to audit. Certificates are just slightly better, beca...
How Azure CLI handles your tokens and what you might be ignoring
Running az login feels like magic. A browser pops up, you pick an account, and from then on, everything just works. No more passwords, no more...
How Dev Proxy teaches you to make your apps more resilient
I added Microsoft Dev Proxy to my Mermaid → Dataverse converter, because I wanted to test how it handled rate limits and API errors. What I go...
Building Azure functions that never store secrets — ever
What if your function could hit Microsoft Graph with no client secrets, no certs, and no Key Vault entries? That is exactly what a Managed id...
Introducing Mermaid to Dataverse Converter
Why diagrams matter (and why they usually fail us) Entity-Relationship Diagrams (ERDs) are the universal shorthand for talking about data mode...
It’s OK to be seen trying
It’s OK to be seen trying Somewhere along the way, we started believing that you’re only allowed to speak after you’ve figured everything out....
Stuck in pilot - Part 1: no foundations, no future
“We just need to test the AI. We’ll figure out the data later.” That sentence has quietly killed more AI pilots than any model failure ever ...