Microsoft Entra permissions granted to the app itself and used without any signed-in user, which means they reach every user's data. For per-user access they are not least privilege.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Application permissions in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Least privilege
The security practice of giving each task only the permissions it requires, scoped as narrowly as possible.
Related terms
- Admin consent
Approval of an app's permissions for the whole tenant, given by an administrator with the right authority. Application permissions always need it, and owning the app does not grant it.
- AI Administrator
Microsoft Entra role for managing Microsoft 365 Copilot and other AI settings; holders may also consent on behalf of the whole tenant, Microsoft Graph application permissions excepted.
- Daemon app
Service or background process that runs without anyone signed in, authenticating as itself via client credentials, which is why it needs application permissions with admin consent.
- Privileged Role Administrator
Entra role whose holders can consent for the whole organisation to any permission, Graph application permissions included. It also looks after PIM, administrative units, role-assignable groups and the assignment of Entra roles.
- Tenant-wide admin consent
Approving an app's requested permissions for all users at once. A Privileged Role Administrator can always do it; Cloud Application, Application and AI Administrators can too, except for Microsoft Graph application permissions.