The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AI-103DP-750SC-900AB-900SC-200SC-300AZ-400DP-600DP-700
Each book explains Service principal in context, with comparison tables and the common traps.
Terms in this definition
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- Microsoft Entra roles
Administrative roles at tenant level, User Administrator for example, that manage objects in Entra but confer no rights over Azure resources, which Azure RBAC handles separately.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Certificate
Key Vault object holding an X.509 certificate, whose associated key and secret are managed alongside it.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- Agent identity
Service principal of a special kind representing an AI agent, holding no credentials itself. It can act on its own using app-only permissions or for a user using delegated ones; Conditional Access offers only block, not grant controls, for it.
- Application object
An app's single global definition, i.e. its app registration in the home tenant; every tenant using the app gets a service principal created from it.
- azcmagent
CLI that ships with the Azure Connected Machine agent. Running
azcmagent connectregisters a server with Azure Arc, and supplying a service principal ID plus a secret or certificate makes that onboarding unattended. - Azure Connected Machine Onboarding
Narrowly scoped built-in role, typically given to a service principal, whose only purpose is onboarding machines into Azure Arc in bulk.
- Azure Login action
Step in a GitHub Actions workflow that authenticates to Azure, either as the service principal of an Entra app or as a user-assigned managed identity; using OpenID Connect avoids storing any secret.
- azure/login
OpenID Connect is preferred over a service principal secret when this Action signs GitHub workflows in to Azure for later PowerShell or CLI steps.
- BYOC
Option for HTTPS on a Front Door custom domain in which your own certificate sits in Azure Key Vault, read through a managed identity or registered service principal; direct upload isn't possible and the chain must come from a Microsoft Trusted CA.
- ClientSecretCredential
Credential type in the Azure Identity library for signing in as a service principal from three values (tenant ID, client ID, client secret); the secret it depends on needs protecting and regular rotation.