Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
Every application in Microsoft Entra ID has two faces. The application object (managed under App registrations) is the global definition in the home tenant; the service principal (managed under Enterprise applications) is the local instance in each tenant where the app is used, and it is what gets assigned users, consented permissions, SSO and provisioning settings.
| Service principal type | Created when | Has an app object? | Notes |
|---|---|---|---|
| Application | An app is registered (automatic in the portal) or consented to in another tenant | Yes | One per tenant that uses the app; a multitenant app gets one in each consenting tenant |
| Managed identity | A managed identity is enabled or created | No | Can be granted permissions but not edited directly |
| Legacy | Apps created before app registrations existed | No | Usable only in the tenant where it was created |
Consequences worth knowing:
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.