Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300SC-900AB-900SC-300AZ-400MD-102
Each book explains App registration in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- OIDC
OpenID Connect, an OAuth 2.0-based identity standard that issues JSON ID tokens. VCF Identity Broker supports it, alongside SAML 2.0, for external IdPs.
Related terms
- API permissions
Blade of a Microsoft Entra app registration where the client asks for application or delegated permissions; once consent is given they show up as claims in tokens.
- App manifest
Portal-editable JSON describing a Microsoft Entra app registration's attributes, including keyCredentials, accessTokenAcceptedVersion and groupMembershipClaims.
- App roles
Roles declared by an API in its app registration. When one app calls another using client credentials, the assigned roles appear in the token's
rolesclaim. - Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Application object
An app's single global definition, i.e. its app registration in the home tenant; every tenant using the app gets a service principal created from it.
- Client secret
Password-like credential added to an app registration under Certificates & secrets, with its value displayed just once; public client apps don't have one.
- Expose an API
Part of an app registration where you set the Application ID URI and the delegated scopes clients can request. Platforms, token claims and app role assignment are configured elsewhere.
- GraphQLApi.Execute.All
Lets signed-in users run GraphQL queries or mutations against Fabric through a Microsoft Entra app registration. The app registration has to be granted this delegated permission from the Power BI service.