A user, group or service principal: anything that can receive a privilege grant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Principal in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
Related terms
- Azure Event Hubs Data Sender
Lets a principal send events to an event hub. For change event streaming, the database's managed identity should get this built-in role scoped to the event hub itself, not to its namespace.
- Client ID
Identifier presented at runtime by an application or user-assigned managed identity when it asks for tokens (acrUserManagedIdentityID, for instance). Role assignments use a different value, the principal or object ID, and the resource ID is different again.
- Delegated role assignment management with conditions
Sometimes called constrained delegation: someone gets a role that can write role assignments, such as Role Based Access Control Administrator, but an ABAC condition limits what they may hand out or take away, by role, by type of principal or by specific principal.
- Deny settings
On a deployment stack, DenyDelete or DenyWriteAndDelete applies deny assignments to the managed resources that bind every principal, Owners too, apart from any excluded.
- External data access
A metastore option, disabled unless an admin switches it on, that opens Unity Catalog data to reads and writes from other engines via REST APIs (Unity's own or the Iceberg catalog). Each principal also needs the external use privilege on the schema.
- IMPERSONATE
The permission that lets a principal take on the execution context of another login or database user, as happens when a module is declared with EXECUTE AS.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - Microsoft Entra admin
Set on an Azure SQL managed instance or logical server, this is the single Entra principal (a user, group, managed identity or service principal) able to log in to all its databases and to add further Entra users.