← SC-300: identity, access, and operations
05 / 12 · 45 MIN

Applications, identities, and consent

Separate application representation, credentials, authorization, and provisioning.

Concept and mechanism

The application object represents application registration in the home tenant; a service principal represents the application in a particular tenant. A multitenant application can have several local representations with their own permissions. Portal registration can create both; creating only an application object through Graph requires a separate service-principal step. Keep these objects distinct in inventory. Delegated access acts for a user and depends on both application and user authorization. App-only uses application permissions without a signed-in user. A permission with All in its name does not remove delegated-context limitations. Admin consent is a grant requiring assessment rather than proof that requested access is necessary.

Guided application

Managed identities reduce team-maintained credentials but still require authorization. System-assigned follows the resource; user-assigned has an independent lifecycle and can be shared. Recreating a VM with the same name does not automatically preserve its deleted system identity. Sharing identity between read and write applications can expand access for all of them. In fictional handover, record the principal, consuming resource, permissions, and owner alongside rotation or recovery design. To publish on-premises web applications, Application Proxy uses an outbound-connecting connector; successful Entra sign-in does not demonstrate backend connectivity. If a user is still absent from a SaaS application, inspect provisioning: SSO and account creation are different processes. Diagnosis should follow the flow and identify the failing stage before adding privileges.

IN PRACTICE

A delegated application with Files.Read.All does not read a file its signed-in user cannot read.

Common pitfalls

App object as one global service principal; no secret as least privilege; name as identity; SSO as provisioning.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Inventory effective identity and validate each grant in the correct resource and tenant.

Create account

Reference: Application objects and service principals · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately

Microsoft is a trademark of the Microsoft group of companies. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Microsoft. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.