Microsoft Entra's identifier for an item in its directory. To register a service principal in Azure DevOps, copy the value shown under Enterprise applications; the app object's value under App registrations is the wrong one.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Object ID in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- Azure DevOps
Microsoft's suite of DevOps services, among them Azure Boards and Azure Pipelines.
- Enterprise
Any group of organisations with shared goals. Examples range from an entire company or one of its divisions to a government department, or several organisations working as partners or along a supply chain.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- Client ID
Identifier presented at runtime by an application or user-assigned managed identity when it asks for tokens (acrUserManagedIdentityID, for instance). Role assignments use a different value, the principal or object ID, and the resource ID is different again.
- Reset redemption status
Sends a fresh invitation to a guest, for instance when their sign-in email has changed, while preserving their object ID, group memberships and app assignments. Their UPN stays the same.