Standard authorisation protocol through which the Microsoft identity platform hands apps access tokens. In the client credentials flow, an app exchanges its client ID and client secret for a token.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains OAuth 2.0 in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Client credentials
App-only OAuth 2.0 flow in which the application signs in as itself, not on behalf of a user; daemons, service-to-service calls and managed identities rely on it.
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds. - App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Client ID
Identifier presented at runtime by an application or user-assigned managed identity when it asks for tokens (acrUserManagedIdentityID, for instance). Role assignments use a different value, the principal or object ID, and the resource ID is different again.
- Client secret
Password-like credential added to an app registration under Certificates & secrets, with its value displayed just once; public client apps don't have one.
Related terms
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Azure DevOps OAuth
Deprecated OAuth 2.0 platform native to Azure DevOps, used by apps calling its REST APIs. Registrations stopped in April 2025, removal is planned during 2026, and Entra ID OAuth replaces it for new integrations.
- OpenID Connect
Sits on top of OAuth 2.0 to handle user sign-in. It also underpins workload identity federation, through which GitHub Actions gets Azure tokens without keeping any secret.
- ROPC
An OAuth 2.0 grant where the app itself takes the username and password. Personal Microsoft accounts, MFA and SSO are all out of reach, and Microsoft advises against using it.