An application running in a browser or on a device, such as a single-page, mobile or desktop app, that cannot hold a secret and so can only get tokens for signed-in users. Leave Allow public client flows switched off unless it is required.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Public client in context, with comparison tables and the common traps.
Terms in this definition
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
Related terms
- Client secret
Password-like credential added to an app registration under Certificates & secrets, with its value displayed just once; public client apps don't have one.
- Confidential client
Because it runs on a server (a daemon, web API or web app, say) it can safely hold a secret, and so it authenticates as itself with a federated credential, certificate or client secret, something no public client can do.