Entra permission type under which an app works on behalf of whoever is signed in, reaching only the data that user can access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Delegated permissions in context, with comparison tables and the common traps.
Terms in this definition
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- API permissions
Blade of a Microsoft Entra app registration where the client asks for application or delegated permissions; once consent is given they show up as claims in tokens.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Microsoft Entra agentic identity
When a Security Copilot agent runs in Intune it gets an agentic user, its own identity in Microsoft Entra, so it works with delegated permissions of its own and not those of the admin.
- Microsoft Graph
API giving access to Entra and Microsoft 365 data. Authorisation uses application or delegated permissions rather than Azure RBAC.
- Permission classifications
Mark delegated permissions that need no admin consent as Low, Medium (preview) or High (preview). If users may only consent to apps from verified publishers, they can grant only low-impact ones.