Part of an app registration where you set the Application ID URI and the delegated scopes clients can request. Platforms, token claims and app role assignment are configured elsewhere.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Expose an API in context, with comparison tables and the common traps.
Terms in this definition
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Application ID URI
Set on the Expose an API page, defaulting to
api://<application-client-id>, this globally unique value names a web API. Prefixing it to a scope name gives the complete scope string. - Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Role assignment
Gives access in Azure RBAC by binding three things together: who (a security principal), what (a role definition) and where (a scope).