In Entra, the service principal for an app: you assign users here, and it is where Conditional Access and single sign-on are enforced.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-700SC-500AB-900SC-300AZ-400
Each book explains Enterprise application in context, with comparison tables and the common traps.
Terms in this definition
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- SSO
Signing in once to gain access to multiple applications.
Related terms
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- Application segment
Destination defined on an enterprise application for Microsoft Entra Private Access, made up of an FQDN, wildcard FQDN, IP or range together with ports and protocol. Matching traffic is reachable solely by users assigned to that app.
- Assignment required
Setting on an enterprise application that allows sign-in only by users and groups that have been assigned to it.
- Default Access
If an enterprise application defines no app roles, users or groups assigned to it receive this role.
- JBoss EAP
Java enterprise application server from Red Hat. App Service offers it as one of its Java runtimes, next to Java SE and Tomcat.
- Non-gallery enterprise application
Used when an in-house or custom app is missing from the Microsoft Entra gallery: you add it yourself as an enterprise application, for example to configure SAML-based SSO.
- SAML token encryption
Feature that encrypts the SAML assertion using the public certificate of the application. You configure it on the enterprise application; the app registration has no such setting.
- Self-service application access
Setting on an enterprise application that lets users ask for access through My Apps; once approved, they are placed into a group you specify.