Hi ,
Thanks for reaching out to Microsoft Q&A.
The standalone Logic App works because you trigger it directly with your own call and relaxed settings. When called from Entra ID Governance, the Logic App must be HTTP-triggered with the exact schema, supported region, and proper authentication (managed identity or OAuth). If any of these do not match, Entra ID silently skips the custom extension. Access assignment still succeeds because access packages do not fail when extensions fail, so the user gets resource access but the admin account is not created.
Please 'Upvote'(Thumbs-up) and 'Accept' as answer if the reply was helpful. This will be benefitting other community members who face the same issue.