Memory hook: Registration defines the app; service principal represents it in a tenant.
Must remember
An app registration defines an application’s identity/configuration; a service principal is its tenant-local representation, commonly managed under enterprise applications. A multitenant app can have service principals in several tenants. Configure redirect URIs, supported accounts, credentials and API permissions deliberately.
Delegated permissions act with a signed-in user under applicable limits; application permissions support app-only access. Consent authorizes requested permissions under tenant policy; admin consent may be required for sensitive scopes. App roles and user/group assignment govern supported application access and should not be confused with directory administrator roles.
Managed identities give supported Azure workloads service identities without application-managed secrets. System-assigned lifecycle follows its resource; user-assigned identities have an independent reusable lifecycle. Use the correct identity and grant downstream access explicitly. A managed identity’s existence does not automatically authorize reading Key Vault or storage.
Enterprise-app integration includes SaaS SSO, provisioning and supported on-premises publishing through Application Proxy connectors. Authentication and provisioning are different: successful SSO does not automatically create all required application entitlements. Collections help organize user-facing applications; lifecycle and assignment remain governed.
Defender for Cloud Apps discovers cloud usage, integrates connected apps and supports access/session/OAuth-app policies. Conditional Access app control can enforce supported session restrictions through its proxy path. Investigate excessive consent, unused credentials and suspicious app behavior; revoke/rotate the actual affected service credentials or grants rather than a random user password.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Azure workload calls a supported service | Managed identity plus least-privilege target permissions. |
| Daemon acts without a user | Application permissions with appropriate consent. |
| Publish supported on-premises web app | Application Proxy with connectors and access policy. |
Traps
- App registration and enterprise application are related but different objects.
- SSO and user provisioning are not the same function.
Active recall
1. What is a service principal?
The application/workload’s identity representation in a tenant.
2. Delegated versus application permissions?
Access with a user versus app-only access.
3. System-assigned versus user-assigned identity?
Resource-coupled lifecycle versus independently managed reusable identity.
4. Why review consent?
An app may retain broad access through granted permissions.
5. Why might a managed identity get Forbidden?
Its target permissions, scope, identity selection or resource policy may be wrong.