OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
Also called grant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Authorisation code in context, with comparison tables and the common traps.
Terms in this definition
- OAuth 2.0
Standard authorisation protocol through which the Microsoft identity platform hands apps access tokens. In the client credentials flow, an app exchanges its client ID and client secret for a token.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Delegated permissions
Entra permission type under which an app works on behalf of whoever is signed in, reaching only the data that user can access.
Related terms
- Admin consent
Approval of an app's permissions for the whole tenant, given by an administrator with the right authority. Application permissions always need it, and owning the app does not grant it.
- Admin consent workflow
Feature allowing users to ask an administrator to approve an app they cannot consent to themselves. Nominated reviewers handle the requests, yet the approver must hold a role able to grant admin consent.
- AKS-ACR integration
Running az aks create or az aks update with --attach-acr grants AcrPull to a cluster's kubelet managed identity, letting nodes fetch images with no pull secrets. Registries using ABAC can't use this; grant Container Registry Repository Reader manually there.
- ALL PRIVILEGES
A shortcut grant in Unity Catalog covering every privilege relevant to an object. Four are deliberately left out:
MANAGE,READ METADATAand the two external use privileges for schemas and locations. - App-based Conditional Access
Restricts sign-in to apps that are protected by Intune, using the grant called Require app protection policy. From 30 June 2026, the approved-client-app grant became read-only, together with every policy that includes it.
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Authentication strength
Grant control in Conditional Access that restricts which combinations of methods meet a policy, for example the built-in Phishing-resistant MFA. It narrows methods without enabling them; enabling is done in the authentication methods policy.
- Azure DevOps Administrator
Microsoft Entra role for managing enterprise-level Azure DevOps policies across the organisations connected to the tenant; it gives no rights to register apps or grant admin consent.