To configure app registration in Microsoft Entra, choose the correct tenant and account model, register the application, configure its platform and exact redirect URI, add least-privilege API permissions, select a secure credential, grant consent when required, and validate the resulting tokens. The correct settings depend on whether the app is a web app, SPA, mobile client, API, daemon, or Azure workload.
Microsoft Entra ID, formerly Azure Active Directory, uses an app registration to define an application’s identity and trust relationship with the Microsoft identity platform. A well-configured registration is more than a name and a client ID: it connects the application to authentication flows, redirect URIs, credentials, permissions, scopes, app roles, and token-validation rules.
Key takeaways
- For most internal employee applications, Accounts in this organizational directory only is the safest starting account model.
- The portal path is Entra ID > App registrations > New registration; the Overview page provides the Application (client) ID and Directory (tenant) ID.
- Web, SPA, mobile, desktop, daemon, and API applications require different platform and credential configurations.
- Redirect URIs must match the URI sent in the authentication request, including the scheme, host, port, path, and relevant case.
- Delegated permissions represent an application acting for a signed-in user, while application permissions represent an unattended application acting as itself.
- Microsoft guidance recommends certificates or federated credentials over client secrets for applicable production confidential clients, and managed identities are often preferable for supported Azure-hosted workloads.
What does an app registration create?
An app registration creates an application identity and establishes a trust relationship between the application and Microsoft Entra ID. The registration stores protocol and authorization configuration such as supported account types, redirect URIs, credentials, API permissions, exposed scopes, app roles, and optional claims. Microsoft’s application registration quickstart describes the registration object and the values exposed after registration.
Several Microsoft Entra objects and identifiers are easy to confuse:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Term | Meaning | Where it is used |
|---|---|---|
| Application object | The global definition of the application in its home tenant. | Stores the application’s configuration and identity definition. |
| Service principal | A tenant-local instance of the application object. | Represents the application in a tenant where it is used, consented to, assigned access, or governed. |
| Enterprise application | The administrative view of a service principal in a tenant. | Used for tenant-local access, assignment, visibility, and administration. |
| Application (client) ID | The identifier for the application registration. | Placed in authorization requests and token-acquisition configuration. |
| Directory (tenant) ID | The identifier of a Microsoft Entra tenant. | Used to select or restrict the identity authority and tenant. |
| Object ID | The identifier of a particular directory object. | Identifies an individual application object, service principal, user, or other directory object; it is not interchangeable with the client ID. |
An application object cannot be moved between tenants after creation, so select the intended home tenant deliberately. A registration is also not the same thing as simply creating a user-facing enterprise application: the app registration is where the application’s authentication and authorization protocol configuration is defined.
Which app registration configuration should you choose?
The best configuration depends on where authentication runs, whether a user is present, which tenant owns the users, and whether the application calls an API or exposes one. Use this decision table before opening the portal:
| Application scenario | Account model or platform | Credential and permission starting point |
|---|---|---|
| Internal employee web app | Single tenant; Web platform | Authorization code flow; delegated permissions for user actions |
| Multitenant SaaS | Any organizational directory; Web, SPA, or another platform matching the client | Careful issuer and tenant validation; consent and customer-tenant onboarding design |
| Browser SPA | Single-page application platform | Authorization code flow with PKCE; never embed a client secret |
| Mobile app | Android or iOS/macOS platform | Platform-specific redirect URI; public-client design; no secret |
| Desktop app | Mobile and desktop applications platform | Public-client configuration where required; no extractable secret |
| Background daemon | Confidential client | Certificate or federated credential; application permissions when no user is present |
| Custom protected API | Separate API registration | Expose scopes and/or app roles; validate issuer, audience, signature, scopes, and roles |
| Azure-hosted workload | Managed identity where supported | Prefer resource identity over manually managed credentials for Azure service access |
Do not select a platform based only on the programming language. Select the platform based on where the authentication response is handled and how the application obtains tokens.
Should the app be single-tenant or multitenant?
Choose a single-tenant registration unless the application is intentionally designed to serve users from other Microsoft Entra tenants. The supported account-type choice controls which identities may sign in, but it does not by itself complete a multitenant architecture.
| Supported account type | Appropriate use | Main consideration |
|---|---|---|
| Accounts in this organizational directory only | Internal, line-of-business, or single-tenant applications | Simplest tenant and issuer model; usually the safest default for internal software. |
| Accounts in any organizational directory | Multitenant SaaS or partner applications for work or school accounts | Requires customer-tenant consent, tenant-aware security, and data-isolation controls. |
| Accounts in any organizational directory and personal Microsoft accounts | Applications supporting both work or school accounts and consumer Microsoft accounts | Requires handling both organizational and personal-account scenarios. |
| Personal Microsoft accounts only | Consumer applications using Microsoft accounts | Does not target workforce-tenant users as the primary account population. |
The official account-type guidance explains these four choices and their intended audiences. Multitenant selection should be treated as an architecture and security decision, not as a way to make an internal app available everywhere.
A multitenant application must validate issuer, tenant claims, and token context correctly; isolate each customer’s data; support consent in customer tenants; and handle tenants that block user consent. API permissions may require administrator approval. When a multitenant application is used or consented to in a customer tenant, a service principal is created in that customer tenant.
What are the prerequisites for app registration?
You need access to the intended Microsoft Entra tenant and an account with at least the Application Developer role for the standard registration workflow. Microsoft’s registration quickstart lists an active Azure account, a workforce or external tenant, and at least the Application Developer role among the prerequisites.
Tenant policy can still limit the operation. Administrators may restrict who can register applications, who can add credentials, who can request permissions, or who can grant consent. A technically correct registration can therefore fail because the tenant blocks application registration or user consent.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBefore registering, document:
- Whether the application is single-tenant or multitenant.
- Where the authorization response is handled.
- The exact development, staging, and production callback URIs.
- The APIs the application will call and the minimum permissions required.
- Whether the application acts for a user or runs without a user.
- The credential and rotation process for each environment.
Higher privileges may be required for tenant-wide administrator consent or for managing credentials and permissions, depending on tenant policy.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How do you register an application in Microsoft Entra?
The current Microsoft Entra admin center workflow is Entra ID > App registrations > New registration. Microsoft can change portal labels or navigation, but these are the documented locations for the standard workflow.
- Sign in to the Microsoft Entra admin center.
- Select the correct tenant.
- Open Entra ID.
- Select App registrations.
- Select New registration.
- Enter a meaningful application name.
- Select the supported account type.
- Add a redirect URI only when the application scenario and framework provide one.
- Select Register.
- On the Overview page, record the Application (client) ID and Directory (tenant) ID.
The Microsoft registration procedure confirms the portal path and the identifiers shown on the Overview page.
How should you name registrations?
Use names that identify the product, workload, and environment, such as product-web-prod, product-api-prod, product-web-dev, and product-daemon-prod. Keep development, staging, and production registrations separate when redirect URIs, credentials, or permissions differ. Separate registrations reduce the blast radius of a credential leak and prevent test callbacks from being mixed with production callbacks.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The display name is not a security boundary and does not need to be globally unique. Multiple registrations may have the same display name, so an environment and workload naming convention is important for human administration.
How do you configure the correct platform and redirect URI?
Open Manage > Authentication and add the platform that matches the actual client: Web, Single-page application, Mobile and desktop applications, Android, or iOS/macOS, as applicable.
Web applications
Choose Web for a server-side application that handles the authorization-code response, including applications built with ASP.NET Core, Django, Flask, Express, Spring, or similar server frameworks. A framework-specific development callback might be https://localhost:5001/signin-oidc; a Microsoft Flask sample uses http://localhost:5000/getAToken. These are examples, not universal values. The Microsoft web sign-in quickstart shows how the application’s configured callback must correspond to the portal entry.
Single-page applications
Choose Single-page application for a browser application built with React, Angular, Vue, Blazor WebAssembly, or another SPA framework. Use authorization code flow with PKCE through an appropriate Microsoft Authentication Library configuration. A browser cannot safely protect a client secret, so do not place a secret in JavaScript, browser storage, or a downloaded bundle.
Mobile and desktop applications
Choose Mobile and desktop applications for desktop clients, or choose the Android or iOS/macOS platform when the application needs platform-specific configuration. Microsoft’s mobile sign-in quickstart includes the pattern msal{client_id}://auth. Android configuration also includes the package name and signature hash.
Mobile and desktop applications may require Authentication > Advanced settings > Allow public client flows. Enable the setting only for a client that genuinely cannot keep a credential private. The setting does not make a server application safer or replace a confidential-client credential.
Rank #3
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why must redirect URIs match exactly?
Entra sends the browser back to the registered redirect URI after authentication and validates the URI supplied by the application against the values registered for that application. The application sign-in flow documentation explains this validation behavior.
Register the exact scheme, host, port, path, and relevant case. A difference between http and https, a different port, a missing callback segment, or a trailing slash can cause a redirect mismatch. Keep production callbacks on HTTPS, separate development and production values, remove obsolete entries, and never register a callback controlled by another party. Do not treat localhost as a production callback.
Microsoft’s redirect URI best-practice guidance covers URI limits, matching behavior, and the use of different path components when multiple localhost flows are needed. Register logout URLs separately when the framework uses them.
How do you fix a redirect URI mismatch?
- Copy the redirect URI from the actual authorization request or application configuration.
- Compare it character-for-character with the portal entry.
- Confirm that the request uses the intended client ID and tenant.
- Confirm that the portal platform type matches the client.
- Remove duplicate or obsolete entries and verify the environment configuration.
- Retest in a private browser session.
Which credential should a production application use?
Use no credential for a public client, use a certificate or federated credential for many confidential production clients, and consider a managed identity for a supported Azure-hosted workload. Client secrets are easy to create but are weaker operationally and must never be embedded in browser, mobile, or desktop applications.
| Credential | Best fit | Operational guidance |
|---|---|---|
| Client secret | Short-lived development or controlled legacy confidential-client scenarios | Copy the secret Value, not the Secret ID; store it in a secret manager, set an expiry, rotate it before expiration, and revoke it if compromised. |
| Certificate | Confidential server applications, daemons, and server-to-server workloads | Upload the public certificate; keep the private key in a secure environment; plan renewal and ensure the configured certificate identifier matches. |
| Federated credential | CI/CD and supported external workload identity scenarios | An external workload presents an OIDC token, and Entra validates the configured issuer, subject, and audience without a stored client secret. |
| Managed identity | Supported Azure resources calling Azure services | Removes credential management from application code, but is not a general replacement for user sign-in or arbitrary external workloads. |
Microsoft’s production web-application guidance says not to use client secrets in production applications and recommends certificates or federated credentials for applicable confidential-client scenarios. The guidance is not a universal requirement for every application: public clients cannot safely hold secrets, and the right choice depends on the workload.
When is a managed identity better than an app registration credential?
Consider a managed identity before creating a secret or certificate when an Azure-hosted resource needs to call a supported Azure service. Microsoft’s service principal and managed identity guidance recommends considering managed identities instead of manually managed service-principal credentials for Azure resources.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →A managed identity is tied to an Azure resource. It does not replace a customer-facing OAuth client, user sign-in, a reusable identity across arbitrary tenants, or every external workload. Federated credentials are often a better fit for CI/CD because the workload can exchange a short-lived external identity token without storing a long-lived secret.
How do you add API permissions and grant consent?
Open Manage > API permissions, select Add a permission, choose the target API, select the minimum required delegated or application permissions, and then review consent before granting it.
- Select Add a permission.
- Choose Microsoft Graph, a custom API, or another protected API.
- Choose Delegated permissions when the application acts for a signed-in user.
- Choose Application permissions when a background application acts without a user.
- Select only the permissions the application actually needs.
- Select Add permissions.
- Grant administrator consent only after reviewing the permission list and its tenant-wide effect.
The standard registration flow adds the basic User.Read permission, but the application’s real requirements must still be reviewed. The registration quickstart documents the API permissions location and standard flow.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Permission type | What the token represents | Typical use | Review concern |
|---|---|---|---|
| Delegated | An application acting for a signed-in user | A web application reading the signed-in user’s profile or mail | Access is constrained by the user and the granted scopes, but consent and tenant policy still apply. |
| Application | The application acting as itself | A background daemon processing mailboxes or files without an interactive user | Access is not constrained by a signed-in user, so least privilege and administrator review are especially important. |
User consent may be disabled by tenant policy, and some permissions require administrator consent. Consent to Microsoft Graph does not authorize a custom API. A permission shown in the portal does not guarantee that an issued token contains the expected claim until the correct flow and consent have been used. Existing consent can remain after permissions are removed, so verify the service principal’s effective grants.
For an external customer tenant, an administrator may need to approve the requested permissions when customer users cannot consent themselves. Microsoft documents this scenario in its external tenant application registration guidance.
How do you protect a custom web API?
Register a custom API separately from its client, expose the API’s scopes or app roles, grant the client those permissions, and configure the API to validate the incoming token for the API’s own audience.
- Register the protected API as its own application.
- Open Expose an API.
- Set or confirm the Application ID URI.
- Add delegated scopes such as
access_as_userwhen user-delegated access is needed. - Add app roles when application-permission access is needed.
- Register the client application separately.
- Add the API’s delegated or application permissions to the client.
- Grant consent where required.
- Configure the API to validate issuer, audience, signature, and required scopes or roles.
The Microsoft custom API sample guidance covers exposed scopes and app roles for delegated and application access.
The API audience is a frequent source of false success. Entra can issue a valid token that the API rejects if the token was issued for Microsoft Graph or for the client application rather than for the protected API. The API’s expected aud claim, the scope requested by the client, and the API registration must describe the same resource.
Free tools Windows power users keep installed
One-click scans. No signup required.
Authentication answers who signed in. Authorization answers what the caller may do. Consent records what a user or administrator approved. Scopes and app roles describe what the API accepts. Application permissions describe what an application may do without a user. The API must enforce authorization instead of trusting the fact that Entra issued a token.
How should you configure roles, groups, and optional claims?
Configure optional claims, group claims, app roles, token settings, and logout behavior only after basic sign-in and API access work. App roles can express application or user authorization; delegated scopes normally appear in the scp claim; application roles normally appear in the roles claim.
Possible advanced configuration includes:
- App roles for user or application authorization.
- Optional claims and directory extension attributes.
- Group claims.
- Scopes in the
scpclaim. - Roles in the
rolesclaim. - Front-channel logout and single sign-on settings.
Do not use tokens as an unlimited directory-data container. Large group memberships can produce group-overage behavior, in which the token does not contain the complete group list. When claims do not contain the data required for an authorization decision, the application should use an appropriate directory or API query and apply its own authorization rules.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How do you test an app registration?
Test tenant selection, sign-in, callback handling, token acquisition, API audience, permissions, consent, refresh behavior, and logout separately. A successful sign-in alone does not prove that the API configuration is correct.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- Navigate to the application.
- Confirm that the browser is sent to the expected Entra authority.
- Sign in with an account allowed by the selected account type.
- Confirm that Entra returns the browser to the registered callback.
- Check application logs for the client ID, tenant, redirect URI, and error details; avoid logging production token contents.
- Acquire a token using the intended flow.
- Send the access token to the intended API, not automatically to Microsoft Graph.
- Confirm that the API validates the token’s issuer, signature, audience, and required scopes or roles.
- Test refresh-token behavior where the selected flow supports it.
- Test logout separately from sign-in.
For a web app, the Microsoft web sign-in quickstart demonstrates recording the client and tenant IDs and configuring redirect URIs and credentials before running the sample.
Registration validation checklist
- Correct Directory (tenant) ID.
- Correct Application (client) ID.
- Correct authority or accepted issuer.
- Correct platform and exact redirect URI.
- Correct credential, if the client is confidential.
- Correct API audience.
- Required delegated scope or application role.
- Consent granted where required.
- Token signature, issuer, expiry, and audience validated by the application or API.
- Access token sent to the intended resource.
How do you troubleshoot common Microsoft Entra errors?
| Symptom | Likely cause | Recovery path |
|---|---|---|
AADSTS50011 or redirect URI mismatch |
Wrong scheme, host, port, path, trailing slash, app registration, platform, or environment. | Compare the callback in the actual request character-for-character with the correct portal entry. |
invalid_client |
Wrong client ID; expired credential; Secret ID used instead of secret Value; unavailable private key; credential belongs to another registration. | Verify the registration, use the secret Value, check expiry and certificate access, and confirm whether the client is public or confidential. |
unauthorized_client |
Unsupported flow, disabled public-client flow, secret used by a public client, or tenant policy blocking the flow. | Match the flow to the platform and enable public-client behavior only for a genuine public client. |
consent_required or interaction_required |
Missing user or administrator consent, newly added permissions, Conditional Access, blocked user consent, or unavailable tenant permission. | Review the requested permissions and tenant policy, then obtain the required consent through the approved administrative process. |
invalid_scope |
Wrong scope format, wrong API, unexposed custom scope, delegated scope used in client credentials, or incorrect application-permission request. | Confirm the target API, expose the custom scope, and use the flow-specific scope format. |
Entra accepts the token but the API returns 401 Unauthorized |
aud does not match the API, issuer is not accepted, required scp or roles claim is missing, signature is not validated correctly, or token is expired. |
Request a token for the API and check audience, issuer, signature, expiry, scopes, and roles. |
| The app does not appear for users | New app registrations are hidden from users by default. | Open Entra ID > Enterprise apps > [application] > Properties and review Visible to users?, subject to tenant administration. |
Use the client ID, tenant ID, redirect URI, and error code from application logs to distinguish a wrong-registration problem from a permission or credential problem. A correct-looking portal page is not enough if the running application is loading values from a different environment.
What should you harden before production?
A production-ready app registration uses separate environments, minimal permissions, secure credentials, exact HTTPS callbacks, and API-side token validation. Complete this checklist before releasing the application:
- Create separate development, staging, and production registrations when their callbacks, permissions, or credentials differ.
- Use HTTPS for production redirect URIs and remove test or obsolete callbacks.
- Never place client secrets in source code, JavaScript, browser storage, mobile binaries, or desktop packages.
- Store unavoidable secrets and private keys in a controlled secret-management system and rotate them before expiration.
- Prefer certificates or federated credentials for applicable confidential production clients.
- Use managed identity for supported Azure-hosted service-to-service workloads.
- Request the smallest practical set of delegated permissions or application permissions.
- Review administrator consent as a tenant-wide authorization decision.
- Validate token issuer, signature, audience, expiry, scopes, and roles in the API.
- Enforce customer-tenant data isolation in multitenant applications.
- Monitor sign-in, consent, credential, and service-principal activity through the organization’s approved logging and audit processes.
Does app registration require Microsoft Entra P1 or P2?
Basic app registration does not automatically require Microsoft Entra ID P1 or P2; Microsoft’s pricing material identifies a free Entra edition, while premium identity controls are licensed separately or through qualifying bundles. Specific features, tenant policies, commercial agreements, regions, taxes, and billing channels can change the requirement and effective cost.
Recommended Free Tools
As a pricing signal, Microsoft’s US pricing page displayed the following figures on August 18, 2026: Microsoft Entra ID P1 at $6.00 per user/month and P2 at $9.00 per user/month, paid yearly with annual commitment. The same page displayed Microsoft Entra Suite at $12.00 per user/month under the same observed pricing terms. Treat those figures as market- and date-specific rather than universal quotes.
| Plan or option | When it may fit | Important qualification |
|---|---|---|
| Microsoft Entra ID Free | Basic registration, authentication, and foundational identity capabilities | Feature availability depends on the tenant and scenario; premium controls are not included. |
| Microsoft Entra ID P1 | Organizations needing premium access controls such as Conditional Access and related capabilities | Microsoft states P1 is available standalone or included with Microsoft 365 E3 and Microsoft 365 Business Premium. |
| Microsoft Entra ID P2 | Organizations needing capabilities such as Identity Protection, risk-based Conditional Access, or Privileged Identity Management | Microsoft states P2 is available standalone or included with Microsoft 365 E5. |
| Microsoft Entra Suite | Organizations evaluating a broader identity and network-access package | Usually excessive for an individual developer or a project needing only OAuth/OIDC registration. |
Check Microsoft’s Entra ID product information and pricing page for the tenant’s market and licensing agreement. Do not buy P1 or P2 merely because an application needs an ordinary registration.
Final configuration checklist
A correctly configured Microsoft Entra app registration has a deliberately selected home tenant and account model, a platform matching the real client, exact environment-specific redirect URIs, a credential appropriate to the client type, least-privilege permissions, reviewed consent, and a test proving that the requested token is intended for the correct API.
- Choose single tenant, multitenant organizational accounts, organizational plus personal accounts, or personal accounts only.
- Register the application in the correct tenant and record the client ID and tenant ID.
- Configure Web, SPA, mobile, desktop, Android, iOS/macOS, or no interactive platform according to the workload.
- Register exact HTTPS production callbacks and keep environments separate.
- Use PKCE for public clients and never distribute secrets with client code.
- Use certificates or federation for applicable confidential production clients, and managed identity for supported Azure workloads.
- Add only the delegated scopes or application permissions the application requires.
- Expose custom API scopes and app roles from a separate API registration.
- Grant consent through the appropriate user or administrator process.
- Validate the token’s issuer, audience, signature, expiry, scopes, and roles.
Frequently Asked Questions
What is the difference between an app registration and an enterprise application in Microsoft Entra?
An app registration is the application object and protocol configuration in its home tenant. An enterprise application is the tenant-local administrative view of the service principal created for that application, including local permissions, assignments, visibility, and governance.
Can a SPA, mobile app, or desktop app use a Microsoft Entra client secret?
A SPA, mobile app, or desktop app should not use a client secret because the distributed client cannot keep the secret private. These public clients should use the platform-appropriate authorization code flow with PKCE and public-client configuration where required.
Why does Microsoft Entra issue a token that my API rejects?
The API usually rejects the token because the token’s audience does not match the API, the issuer is not accepted, the token lacks the required scope or role, the signature is not validated correctly, or the token is expired. Request a token for the API rather than for Microsoft Graph or the client application.
Should an Azure-hosted application use an app registration or a managed identity?
An Azure-hosted workload should consider a managed identity first when it needs to call a supported Azure service, because managed identity removes manually managed credentials from application code. Managed identity does not replace user sign-in, customer-facing OAuth clients, or every external workload.
The Bottom Line
Configure the registration around the application’s real trust boundary: who signs in, where the callback runs, which API receives the token, and whether a user is present. Single-tenant internal apps are usually the simplest starting point; multitenant apps require tenant-aware security and consent design. Keep public clients secretless, prefer stronger workload credentials in production, request least-privilege permissions, and verify the API audience before treating sign-in as complete.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

