Roles declared by an API in its app registration. When one app calls another using client credentials, the assigned roles appear in the token's roles claim.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains App roles in context, with comparison tables and the common traps.
Terms in this definition
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Client credentials
App-only OAuth 2.0 flow in which the application signs in as itself, not on behalf of a user; daemons, service-to-service calls and managed identities rely on it.
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
Related terms
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Default Access
If an enterprise application defines no app roles, users or groups assigned to it receive this role.
- Token configuration
The blade in an app registration where optional claims like groups and email are added to issued tokens. App roles are configured separately.