StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 1: Manage identity, access, and governance

App registrations vs enterprise applications (service principals), API permissions, admin consent and user consent settings

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

When you register an application with Microsoft Entra ID, two objects are involved. The application object, seen under App registrations, is the global definition of the app: its name, application (client) ID, redirect URIs, credentials (client secrets or certificates), the permissions it asks for and any app roles or scopes it exposes. It lives in the app's home tenant. The service principal, seen under Enterprise applications, is the local instance of that app in a specific tenant. It is what actually gets signed in, assigned users, granted consent and targeted by Conditional Access. One application object can have service principals in many tenants (a multitenant app), each with its own consent and assignments.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan