Concept and mechanism
Authentication establishes identity; authorization decides the permitted operation. A managed identity avoids managing an application password but needs destination permissions. Its lifecycle also matters: a user-assigned identity exists independently of the resource using it. A signed, unexpired token may have been issued for another API. The receiving resource must validate audience, issuer, and other applicable conditions. Afterward, it still needs access rules for the specific requested object.
Guided application
For a Graph job without a user, assess app-only access and permissions supported by the operation. In an RBAC vault, separate resource management from reading values. To delegate temporary blob access, limit SAS scope, operations, and lifetime and treat it as a credential. Do not assume every SAS type shares revocation or stored access policies. At handover, record principal, role, scope, owner, and functional verification without including tokens or secrets in the document.
A GetSecret 403 with confirmed networking and Key Vault Contributor requires checking data-plane access, not opening the vault to the Internet.
Common pitfalls
Accepting a Graph token in your own API; confusing Reader with secret-value access; hiding interface IDs as the only control.
Related topics: Telemetry and request diagnosis · Messages, events, and API contracts
Validate identity and authorization at each relevant boundary.
Reference: Access tokens · AZ-204 archived objectives 2026-01-14; retired 2026-07-31