Identifier presented at runtime by an application or user-assigned managed identity when it asks for tokens (acrUserManagedIdentityID, for instance). Role assignments use a different value, the principal or object ID, and the resource ID is different again.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Client ID in context, with comparison tables and the common traps.
Terms in this definition
- UAMI
A user-assigned managed identity: an Azure resource of its own that can be attached to services. Mirroring Azure SQL Database requires the logical server to have a primary identity enabled, which may be its system-assigned identity or, in preview, a UAMI.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Principal
A user, group or service principal: anything that can receive a privilege grant.
- Object ID
Microsoft Entra's identifier for an item in its directory. To register a service principal in Azure DevOps, copy the value shown under Enterprise applications; the app object's value under App registrations is the wrong one.
- Resource ID
The unique path that identifies an Azure resource, shaped like /subscriptions/.../resourceGroups/.../providers/.... Moving the resource to a different resource group or subscription gives it a new ID.
Related terms
- ClientSecretCredential
Credential type in the Azure Identity library for signing in as a service principal from three values (tenant ID, client ID, client secret); the secret it depends on needs protecting and regular rotation.
- Custom audience
Lets each point-to-site gateway admit only certain groups: register an app, set its client ID as that gateway's Audience and authorise the Azure VPN Client app as a client, creating one such registration per gateway.
- M2M
Lets automation call Azure Databricks by having a service principal swap its OAuth client ID and secret for short-lived access tokens, known as the client credentials flow; this machine-to-machine approach is the preferred one for unattended processes.
- OAuth 2.0
Standard authorisation protocol through which the Microsoft identity platform hands apps access tokens. In the client credentials flow, an app exchanges its client ID and client secret for a token.