<!DOCTYPE html><html class="layout layout-holy-grail show-table-of-contents conceptual show-breadcrumb default-focus theme-light" lang="en-us" dir="ltr" data-authenticated="false" data-auth-status-determined="true" data-target="docs" x-ms-format-detection="none" data-layout-restored="true" style="--window-inner-height: 720px !important; --atlas-header-height: 108px !important; --atlas-footer-height: 125px !important; --atlas-header-visible-height: 108px !important; --atlas-footer-visible-height: 0px !important;"><head>
			<title>OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform | Microsoft Learn</title>
			<meta charset="utf-8">
			<meta name="viewport" content="width=device-width, initial-scale=1.0">
			<meta name="color-scheme" content="light dark">

			<meta name="description" content="Build web applications by using the Microsoft identity platform implementation of the OAuth 2.0 authentication protocol.">
			<link rel="canonical" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow"> 

			<!-- Non-customizable open graph and sharing-related metadata -->
			<meta name="twitter:card" content="summary_large_image">
			<meta name="twitter:site" content="@MicrosoftLearn">
			<meta property="og:type" content="website">
			<meta property="og:image:alt" content="Microsoft Learn">
			<meta property="og:image" content="https://learn.microsoft.com/en-us/media/open-graph-image.png">
			<!-- Page specific open graph and sharing-related metadata -->
			<meta property="og:title" content="OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform">
			<meta property="og:url" content="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow">
			<meta property="og:description" content="Build web applications by using the Microsoft identity platform implementation of the OAuth 2.0 authentication protocol.">
			<meta name="platform_id" content="c41aa014-b4c6-25dd-3bb7-50f6278dfe76"> <meta name="scope" content="Microsoft Entra">
			<meta name="locale" content="en-us">
			 
			<meta name="uhfHeaderId" content="MSDocsHeader-Entra">

			<meta name="page_type" content="conceptual">

			<!--page specific meta tags-->
			

			<!-- custom meta tags -->
			
		<meta name="breadcrumb_path" content="/entra/breadcrumb/toc.json">
	
		<meta name="feedback_system" content="Standard">
	
		<meta name="feedback_product_url" content="/entra/identity-platform/developer-support-help-options">
	
		<meta name="author" content="cilwerner">
	
		<meta name="ms.author" content="cwerner">
	
		<meta name="manager" content="pmwongera">
	
		<meta name="ms.date" content="2026-01-30T00:00:00Z">
	
		<meta name="ms.service" content="identity-platform">
	
		<meta name="ms.reviewer" content="jmprieur, ludwignick">
	
		<meta name="ms.topic" content="reference">
	
		<meta name="ms.custom" content="sfi-image-nochange">
	
		<meta name="document_id" content="d32f55ac-acbc-292b-d1b7-ffdd257b11e1">
	
		<meta name="document_version_independent_id" content="ae2a266c-051b-7307-93fd-74bc521c93bf">
	
		<meta name="updated_at" content="2026-06-15T17:40:00Z">
	
		<meta name="original_content_git_url" content="https://github.com/MicrosoftDocs/entra-docs-pr/blob/live/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md">
	
		<meta name="gitcommit" content="https://github.com/MicrosoftDocs/entra-docs-pr/blob/a4be4ac419c4e857b1c4de7dee22c9f7e0c750f9/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md">
	
		<meta name="git_commit_id" content="a4be4ac419c4e857b1c4de7dee22c9f7e0c750f9">
	
		<meta name="site_name" content="Docs">
	
		<meta name="depot_name" content="MSDN.entra-docs">
	
		<meta name="schema" content="Conceptual">
	
		<meta name="toc_rel" content="toc.json">
	
		<meta name="feedback_help_link_type" content="">
	
		<meta name="feedback_help_link_url" content="">
	
		<meta name="word_count" content="2819">
	
		<meta name="asset_id" content="identity-platform/v2-oauth2-client-creds-grant-flow">
	
		<meta name="moniker_range_name" content="">
	
		<meta name="item_type" content="Content">
	
		<meta name="source_path" content="docs/identity-platform/v2-oauth2-client-creds-grant-flow.md">
	
		<meta name="previous_tlsh_hash" content="16EB3572970D8B21FF926D061893B741B6F0D08AADB096D8242969E291850EA3DF1D9C96FF87ABC52372435312EB7D0DD6D4F739803C379355B99879C1AC1663BB987372D0">
	
		<meta name="github_feedback_content_git_url" content="https://github.com/MicrosoftDocs/entra-docs/blob/main/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md">
	
		<meta name="markdown_url" content="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow?accept=text/markdown">
	 
		<meta name="cmProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/1ae5c491-970a-4062-8301-6336e69f9026" data-source="generated">
	
		<meta name="cmProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/5f286262-a4cb-47f4-92d3-dc24f172492b" data-source="generated">
	
		<meta name="cmProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/1e31b9be-b6e9-4221-a20b-d1460dbd5dfa" data-source="generated">
	
		<meta name="spProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/f2c3e52e-3667-4e8a-bf11-20b9eaccdc8c" data-source="generated">
	
		<meta name="spProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/90571f66-8410-4272-8117-79ce87fc2dcc" data-source="generated">
	
		<meta name="spProducts" content="https://authoring-docs-microsoft.poolparty.biz/devrel/8d63a4c4-4889-43b4-a98e-8e50dbfdb083" data-source="generated">
	

			<!-- Apply persisted/system theme before first paint to prevent wrong-theme flash when scripts are deferred. -->
			<script id="theme-preference">
				(function () {
			try {
				var stored = localStorage.getItem('theme');
				var theme = /^(light|dark|high-contrast)$/.test(stored)
					? stored
					: matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light';
				document.documentElement.classList.add('theme-' + theme);
			} catch (e) {}
		})();;
			</script>

			<script id="atlas-layout-preferences">
				(function () {
			try {
				var state = JSON.parse(localStorage.getItem('atlas-layout-preferences') || '{}');
				var view = state["docs-layout-persistence"] || {};
				var excludesKey = "";
				var blocked = {};
				if (excludesKey) {
					var exclusions = JSON.parse(localStorage.getItem('atlas-layout-exclusions') || '{}');
					if (Object.prototype.hasOwnProperty.call(exclusions, excludesKey)) {
						var scoped = exclusions[excludesKey];
						if (scoped) {
							if (typeof scoped === 'object') blocked = scoped;
						}
					}
				}
				var html = document.documentElement;
				for (var c in view) {
					if (Object.prototype.hasOwnProperty.call(blocked, c)) continue;
					if (view[c]) html.classList.add(c);
					else html.classList.remove(c);
				}
			} catch (e) {}
		})();;
			</script>

			<!-- assets and js globals -->
			
			<link rel="stylesheet" href="/static/assets/0.4.03503.8087-34604b98/styles/site.css">
			
			<script src="https://wcpstatic.microsoft.com/mscc/lib/v2/wcp-consent.js"></script>
			<script async="" src="https://js.monitor.azure.com/scripts/c/ms.jsll-4.min.js"></script>
			

			<!-- msdocs global object -->
			<script id="msdocs-script">
		var msDocs = {
  "environment": {
    "accessLevel": "online",
    "azurePortalHostname": "portal.azure.com",
    "reviewFeatures": false,
    "supportLevel": "production",
    "systemContent": true,
    "siteName": "learn",
    "legacyHosting": false
  },
  "data": {
    "contentLocale": "en-us",
    "contentDir": "ltr",
    "userLocale": "en-us",
    "userDir": "ltr",
    "pageTemplate": "Conceptual",
    "layoutStateStorageKey": "docs-layout-persistence",
    "brand": "entra",
    "context": {},
    "standardFeedback": true,
    "showFeedbackReport": false,
    "feedbackHelpLinkType": "",
    "feedbackHelpLinkUrl": "",
    "feedbackSystem": "Standard",
    "feedbackGitHubRepo": "MicrosoftDocs/entra-docs",
    "feedbackProductUrl": "/entra/identity-platform/developer-support-help-options",
    "extendBreadcrumb": false,
    "isEditDisplayable": true,
    "isPrivateUnauthorized": false,
    "hideViewSource": false,
    "isPermissioned": false,
    "hasRecommendations": false,
    "contributors": [
      {
        "name": "cilwerner",
        "url": "https://github.com/cilwerner"
      },
      {
        "name": "ShawnKupfer",
        "url": "https://github.com/ShawnKupfer"
      },
      {
        "name": "csmulligan",
        "url": "https://github.com/csmulligan"
      },
      {
        "name": "CelesteDG",
        "url": "https://github.com/CelesteDG"
      },
      {
        "name": "OwenRichards1",
        "url": "https://github.com/OwenRichards1"
      },
      {
        "name": "Penguinwizzard",
        "url": "https://github.com/Penguinwizzard"
      },
      {
        "name": "PesalaPavan",
        "url": "https://github.com/PesalaPavan"
      },
      {
        "name": "Court72",
        "url": "https://github.com/Court72"
      },
      {
        "name": "alexbuckgit",
        "url": "https://github.com/alexbuckgit"
      },
      {
        "name": "vladik-vitre",
        "url": "https://github.com/vladik-vitre"
      },
      {
        "name": "BuckeyeGuyJFlo",
        "url": "https://github.com/BuckeyeGuyJFlo"
      },
      {
        "name": "v-dirichards",
        "url": "https://github.com/v-dirichards"
      },
      {
        "name": "TDroogers",
        "url": "https://github.com/TDroogers"
      },
      {
        "name": "prmerger-automator[bot]",
        "url": "https://github.com/prmerger-automator[bot]"
      },
      {
        "name": "dstrockis",
        "url": "https://github.com/dstrockis"
      },
      {
        "name": "BryanLa",
        "url": "https://github.com/BryanLa"
      },
      {
        "name": "garrodonnell",
        "url": "https://github.com/garrodonnell"
      },
      {
        "name": "nickludwig",
        "url": "https://github.com/nickludwig"
      },
      {
        "name": "darrelmiller",
        "url": "https://github.com/darrelmiller"
      },
      {
        "name": "FaithOmbongi",
        "url": "https://github.com/FaithOmbongi"
      },
      {
        "name": "amartyadav",
        "url": "https://github.com/amartyadav"
      },
      {
        "name": "shwetamathur7",
        "url": "https://github.com/shwetamathur7"
      },
      {
        "name": "derisen",
        "url": "https://github.com/derisen"
      },
      {
        "name": "mmacy",
        "url": "https://github.com/mmacy"
      },
      {
        "name": "rwike77",
        "url": "https://github.com/rwike77"
      },
      {
        "name": "psignoret",
        "url": "https://github.com/psignoret"
      },
      {
        "name": "hpsin",
        "url": "https://github.com/hpsin"
      },
      {
        "name": "JamesTran-MSFT",
        "url": "https://github.com/JamesTran-MSFT"
      },
      {
        "name": "davidmu1",
        "url": "https://github.com/davidmu1"
      },
      {
        "name": "denrea",
        "url": "https://github.com/denrea"
      },
      {
        "name": "omondiatieno",
        "url": "https://github.com/omondiatieno"
      },
      {
        "name": "msewaweru",
        "url": "https://github.com/msewaweru"
      },
      {
        "name": "WhippsP",
        "url": "https://github.com/WhippsP"
      },
      {
        "name": "nschonni",
        "url": "https://github.com/nschonni"
      },
      {
        "name": "shashishailaj",
        "url": "https://github.com/shashishailaj"
      },
      {
        "name": "AllisonAm",
        "url": "https://github.com/AllisonAm"
      },
      {
        "name": "Saisang",
        "url": "https://github.com/Saisang"
      },
      {
        "name": "rjagiewich",
        "url": "https://github.com/rjagiewich"
      },
      {
        "name": "v-kents",
        "url": "https://github.com/v-kents"
      }
    ]
  },
  "functions": {}
};;
	</script>

			<!-- base scripts, msdocs global should be before this -->
			<script src="/static/assets/0.4.03503.8087-34604b98/scripts/en-us/index-docs.js" async=""></script>
			

			<!-- json-ld -->
			
		<style></style><link rel="preload" as="image" href="/en-us/media/ask-learn/meet-ask-learn-base.png"><link rel="preload" as="image" href="/en-us/media/ask-learn/check-for-accuracy-base.png"><script type="application/ld+json">{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"name":"Learn","position":1,"@type":"ListItem","item":"https://learn.microsoft.com/en-us/"},{"name":"Microsoft Entra","position":2,"@type":"ListItem","item":"https://learn.microsoft.com/en-us/entra/"},{"name":"Microsoft identity platform","position":3,"@type":"ListItem","item":"https://learn.microsoft.com/en-us/entra/identity-platform/"}]}</script></head>
	
			<body id="body" data-bi-name="body" class="layout-body " lang="en-us" dir="ltr">
				<header class="layout-body-header background-color-body-medium">
		<div class="header-holder has-default-focus">
			
		<a href="#main" style="z-index: 1070" class="outline-color-text visually-hidden-until-focused position-fixed inner-focus focus-visible top-0 left-0 right-0 padding-xs text-align-center background-color-body">
			Skip to main content
		</a>
	
		<a href="#" data-skip-to-ask-learn="" style="z-index: 1070" class="outline-color-text visually-hidden-until-focused position-fixed inner-focus focus-visible top-0 left-0 right-0 padding-xs text-align-center background-color-body">
			Skip to Ask Learn chat experience
		</a>
	

			<div hidden="" id="cookie-consent-holder" data-test-id="cookie-consent-container"></div>
			<!-- Unsupported browser warning -->
			<div id="unsupported-browser" style="background-color: white; color: black; padding: 16px; border-bottom: 1px solid grey;" hidden="">
				<div style="max-width: 800px; margin: 0 auto;">
					<p style="font-size: 24px">This browser is no longer supported.</p>
					<p style="font-size: 16px; margin-top: 16px;">
						Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
					</p>
					<div style="margin-top: 12px;">
						<a href="https://go.microsoft.com/fwlink/p/?LinkID=2092881 " style="background-color: #0078d4; border: 1px solid #0078d4; color: white; padding: 6px 12px; border-radius: 2px; display: inline-block;">
							Download Microsoft Edge
						</a>
						<a href="https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge" style="background-color: white; padding: 6px 12px; border: 1px solid #505050; color: #171717; border-radius: 2px; display: inline-block;">
							More info about Internet Explorer and Microsoft Edge
						</a>
					</div>
				</div>
			</div>
			<!-- site header -->
			<div id="ms--site-header" data-test-id="site-header-wrapper" itemscope="itemscope" itemtype="http://schema.org/Organization">
				<div id="ms--mobile-nav" class="site-header display-none-tablet padding-inline-none gap-none" data-bi-name="mobile-header" data-test-id="mobile-header"><!----><div id="ms--site-header-hamburger" data-test-id="site-header-hamburger"><button type="button" class="button button-clear inner-focus" data-test-id="mobile-nav-open-button" data-bi-name="mobile-nav-open-button" title="Global navigation" aria-label="Global navigation"><span class="icon" aria-hidden="true"><span class="docon docon-menu"></span></span></button></div><a class="site-header-brand" itemprop="url" href="/en-us/" data-bi-name="site-header-brand-learn-mobile" data-test-id="site-header-brand-mobile"><span><!---->Learn<!----></span></a><!----><a href="https://www.microsoft.com" aria-label="Microsoft" itemprop="url" data-bi-name="site-header-microsoft-logo-mobile" data-test-id="site-header-microsoft-logo-mobile" class="site-header-logo site-header-logo-centered"><!----><svg aria-hidden="true" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg" itemprop="logo" itemscope="itemscope"><path d="M11.5216 0.5H0V11.9067H11.5216V0.5Z" fill="#f25022"></path><path d="M24.2418 0.5H12.7202V11.9067H24.2418V0.5Z" fill="#7fba00"></path><path d="M11.5216 13.0933H0V24.5H11.5216V13.0933Z" fill="#00a4ef"></path><path d="M24.2418 13.0933H12.7202V24.5H24.2418V13.0933Z" fill="#ffb900"></path></svg><!----></a><!----><search-expander data-test-id="site-header-search-mobile" class="display-flex flex-grow-1 justify-content-flex-end"><div hidden="" id="ms--site-header-search-mobile" class="display-flex align-items-center gap-xxs width-full padding-left-xxs"><!----><form class="flex-grow-1" method="GET" role="search" id="ms--site-header-search-form-mobile" data-bi-name="site-header-search-form-mobile" name="site-header-search-form-mobile" aria-label="Search" action="/en-us/search/"><!----><div class="autocomplete display-block" data-bi-name="autocomplete"><!----><div class="field-body control "><input role="combobox" maxlength="100" aria-autocomplete="list" autocapitalize="off" autocomplete="off" autocorrect="off" spellcheck="false" id="site-header-search-autocomplete-input-mobile" data-test-id="site-header-search-autocomplete-input-mobile" class="autocomplete-input input   width-full" type="search" name="terms" aria-expanded="false" aria-owns="ax-1-listbox" aria-controls="ax-1-listbox" aria-activedescendant="" aria-label="Search" aria-describedby="ms--site-header-search-autocomplete-input-mobile-description" placeholder="Search" data-bi-name="site-header-search-autocomplete-input-mobile" pattern=".*"> <span hidden="" id="ms--site-header-search-autocomplete-input-mobile-description"><!---->Suggestions will filter as you type<!----></span></div><ul role="listbox" id="ax-1-listbox" data-test-id="site-header-search-autocomplete-input-mobile-listbox" class="autocomplete-suggestions is-vertically-scrollable padding-xxs " aria-label="Suggestions" hidden=""><!----> <!----></ul><!----></div><button type="submit" class="visually-hidden" tabindex="-1" aria-hidden="true"></button><input name="category" hidden="" value=""> <!----></form><button data-search-expander-trigger-close="" type="button" class="button button-clear inner-focus" aria-controls="ms--site-header-search-mobile" aria-label="Close search" data-bi-name="site-header-search-close-mobile" data-test-id="site-header-search-close-mobile"><span class="icon" aria-hidden="true"><span class="docon docon-navigate-close"></span></span></button></div><button data-search-expander-trigger-open="" type="button" class="button button-clear inner-focus" aria-controls="ms--site-header-search-mobile" aria-label="Open search" data-bi-name="site-header-search-open-mobile" data-test-id="site-header-search-open-mobile"><span class="icon" aria-hidden="true"><span class="docon docon-search"></span></span></button></search-expander><!----><!----><a href="#" data-bi-name="site-header-sign-in-mobile" data-test-id="site-header-sign-in-mobile" class="link-button font-size-sm flex-shrink-0 docs-sign-in auth-status-determined not-authenticated margin-right-xs margin-left-xxs"><!---->Sign in<!----></a> <details data-bi-name="site-header-user-mobile" class="popover popover-right auth-status-determined authenticated margin-right-xs margin-left-xxs"><summary data-bi-name="site-header-user-avatar" aria-label="Your Account" data-test-id="site-header-user-mobile"><div class="persona persona-sm"><figure class="persona-avatar"><img alt="" data-profile-property="avatarThumbnailUrl"></figure></div></summary><div class="popover-content width-auto" data-bi-name="site-header-user-menu"><div class="persona persona-sm"><figure class="persona-avatar"><img alt="" data-profile-property="avatarUrl" aria-labelledby="ms--user-display-name-mobile"></figure><div class="persona-details" data-test-id="persona-detail-mobile"><p class="persona-name" data-profile-property="displayName" id="ms--user-display-name-mobile"></p><p data-profile-property="upn"></p></div></div><ul class="padding-block-xs"><li class="padding-bottom-xs"><a data-profile-property="profileUrl" class="font-size-sm" data-bi-name="site-header-user-profile" href="https://learn.microsoft.com/en-us/users/me/activity/"><!---->Profile<!----></a></li><li class="padding-bottom-xs"><a class="font-size-sm" data-bi-name="site-header-user-analytics" href="https://learn.microsoft.com/en-us/users/me/analytics/"><!---->Analytics<!----></a></li><li><a data-profile-property="settingsUrl" class="font-size-sm" data-bi-name="site-header-user-settings" href="https://learn.microsoft.com/en-us/users/me/settings/"><!---->Settings<!----></a></li></ul><div class="border-top padding-top-xs"><a class="docs-sign-out font-size-sm" href="#" data-bi-name="site-header-sign-out-mobile" data-test-id="site-header-user-sign-out-mobile"><!---->Sign out<!----></a></div></div></details><!----> <!----></div>
				<div id="ms--primary-nav" class="site-header display-none display-flex-tablet" data-bi-name="L1-header" data-test-id="primary-header"><!----><!----><a href="https://www.microsoft.com" aria-label="Microsoft" itemprop="url" data-bi-name="site-header-microsoft-logo" data-test-id="site-header-microsoft-logo" class="site-header-logo "><!----><svg aria-hidden="true" viewBox="0 0 25 25" fill="none" xmlns="http://www.w3.org/2000/svg" itemprop="logo" itemscope="itemscope"><path d="M11.5216 0.5H0V11.9067H11.5216V0.5Z" fill="#f25022"></path><path d="M24.2418 0.5H12.7202V11.9067H24.2418V0.5Z" fill="#7fba00"></path><path d="M11.5216 13.0933H0V24.5H11.5216V13.0933Z" fill="#00a4ef"></path><path d="M24.2418 13.0933H12.7202V24.5H24.2418V13.0933Z" fill="#ffb900"></path></svg><!----></a><div class="site-header-divider"></div><a class="site-header-brand" itemprop="url" href="/en-us/" data-bi-name="site-header-brand-learn" data-test-id="site-header-brand"><span><!---->Learn<!----></span></a><div id="ms--search-expander-wrapper" class="display-flex justify-content-space-between flex-grow-1 align-items-center overflow-x-hidden height-full"><!----><overflow-menu class="align-self-stretch" style="display: block; overflow: hidden; width: 100%;"><nav class="site-header-nav" data-bi-name="primary-nav" data-overflow-menu-container="" aria-label="Global" style="visibility: visible; overflow: hidden;"><button type="button" data-overflow-menu-prev-button="" data-bi-name="site-header-btn-prev" class="button button-clear button-sm inner-focus" hidden="" aria-label="Previous"><span class="icon" aria-hidden="true"><span class="docon docon-chevron-left-light"></span></span></button><ul class="display-flex gap-xxs-desktop"><!----><!----><li aria-setsize="4" aria-posinset="1"><panel-controller data-bi-name="site-header-btn-1-documentation"><button type="button" aria-expanded="false" class="site-header-button" data-overflow-menu-item="" aria-controls="ms--panel-1" data-test-id="site-header-panel-controller-1" style="white-space: nowrap;"><span><!---->Documentation<!----></span><span class="icon expanded-indicator" aria-hidden="true"><span class="docon docon-chevron-down-light"></span></span></button><div class="site-header-panel" hidden="" id="ms--panel-1" data-bi-name="panel-1-documentation" data-test-id="site-header-panel-1"><!----><div class="site-header-panel-content"><ul class="site-header-panel-links"><!----><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/docs/" data-bi-name="panel-link-1-all-product-documentation"><!---->All product documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/azure/?product=popular" data-bi-name="panel-link-2-azure-documentation"><!---->Azure documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/dynamics365/" data-bi-name="panel-link-3-dynamics-365-documentation"><!---->Dynamics 365 documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/copilot/" data-bi-name="panel-link-4-microsoft-copilot-documentation"><!---->Microsoft Copilot documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/microsoft-365/" data-bi-name="panel-link-5-microsoft-365-documentation"><!---->Microsoft 365 documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/power-platform/" data-bi-name="panel-link-6-power-platform-documentation"><!---->Power Platform documentation<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/samples/" data-bi-name="panel-link-7-code-samples"><!---->Code samples<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/troubleshoot/" data-bi-name="panel-link-8-troubleshooting-documentation"><!---->Troubleshooting documentation<!----></a></li><!----><!----></ul><!----></div><section class="site-header-panel-featured-content"><!----><!----><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="featured-card-1-msignite"><div class="card-content"><p class="card-supertitle line-clamp-2 line-height-normal"><!---->Register now<!----></p><a class="card-title color-text background-color-transparent stretched-link" href="https://ignite.microsoft.com/home?wt.mc_ID=msignite26_gmee_corp_np_oo_MSLearnRegLaunch"><!---->Microsoft Ignite | November 17-20, 2026<!----></a><p class="card-content-description line-clamp-2"><!---->Interactive learning, certifications, and direct access to experts all in one place.<!----></p></div></article><!----><!----></section> <!----></div></panel-controller></li><!----><li aria-setsize="4" aria-posinset="2"><panel-controller data-bi-name="site-header-btn-2-training"><button type="button" aria-expanded="false" class="site-header-button" data-overflow-menu-item="" aria-controls="ms--panel-2" data-test-id="site-header-panel-controller-2" style="white-space: nowrap;"><span><!---->Training &amp; Labs<!----></span><span class="icon expanded-indicator" aria-hidden="true"><span class="docon docon-chevron-down-light"></span></span></button><div class="site-header-panel" hidden="" id="ms--panel-2" data-bi-name="panel-2-training" data-test-id="site-header-panel-2"><!----><div class="site-header-panel-content"><ul class="site-header-panel-links"><!----><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/" data-bi-name="panel-link-1-training"><!---->All training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/browse/?products=azure" data-bi-name="panel-link-2-azure-training"><!---->Azure training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/browse/?products=dynamics-365" data-bi-name="panel-link-3-dynamics-365-training"><!---->Dynamics 365 training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/browse/?products=ms-copilot" data-bi-name="panel-link-4-microsoft-copilot-training"><!---->Microsoft Copilot training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/browse/?products=m365" data-bi-name="panel-link-5-microsoft-365-training"><!---->Microsoft 365 training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/browse/?products=power-platform" data-bi-name="panel-link-6-microsoft-power-platform-training"><!---->Microsoft Power Platform training<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/labs/" data-bi-name="panel-link-7-labs"><!---->Labs<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/credentials/" data-bi-name="panel-link-8-credentials"><!---->Credentials<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/training/career-paths/" data-bi-name="panel-link-9-career-paths"><!---->Career paths<!----></a></li><!----><!----></ul><!----></div><section class="site-header-panel-featured-content"><!----><!----><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="featured-card-1-msignite"><div class="card-content"><p class="card-supertitle line-clamp-2 line-height-normal"><!---->Register now<!----></p><a class="card-title color-text background-color-transparent stretched-link" href="https://ignite.microsoft.com/home?wt.mc_ID=msignite26_gmee_corp_np_oo_MSLearnRegLaunch"><!---->Microsoft Ignite | November 17-20, 2026<!----></a><p class="card-content-description line-clamp-2"><!---->Interactive learning, certifications, and direct access to experts all in one place.<!----></p></div></article><!----><!----></section> <!----></div></panel-controller></li><!----><li aria-setsize="4" aria-posinset="3"><panel-controller data-bi-name="site-header-btn-3-qna"><button type="button" aria-expanded="false" class="site-header-button" data-overflow-menu-item="" aria-controls="ms--panel-3" data-test-id="site-header-panel-controller-3" style="white-space: nowrap;"><span><!---->Q&amp;A<!----></span><span class="icon expanded-indicator" aria-hidden="true"><span class="docon docon-chevron-down-light"></span></span></button><div class="site-header-panel" hidden="" id="ms--panel-3" data-bi-name="panel-3-qna" data-test-id="site-header-panel-3"><!----><div class="site-header-panel-content"><ul class="site-header-panel-links"><!----><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/questions/ask/" data-bi-name="panel-link-1-ask-a-question"><!---->Ask a question<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/133/azure/" data-bi-name="panel-link-2-azure-questions"><!---->Azure questions<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/60/windows/" data-bi-name="panel-link-3-windows-questions"><!---->Windows questions<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/9/m365/" data-bi-name="panel-link-4-m365-questions"><!---->Microsoft 365 questions<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/131/office-outlook/" data-bi-name="panel-link-5-microsoft-outlook-questions"><!---->Microsoft Outlook questions<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/108/office-teams/" data-bi-name="panel-link-6-microsoft-teams-questions"><!---->Microsoft Teams questions<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/tags/" data-bi-name="panel-link-7-popular-tags"><!---->Popular tags<!----></a></li><!----><li><a class="button button-clear button-sm button-block text-align-left font-weight-normal justify-content-flex-start inner-focus border-none background-color-body-accent-onhover" href="/en-us/answers/questions/" data-bi-name="panel-link-8-all-questions"><!---->All questions<!----></a></li><!----><!----></ul><!----></div><section class="site-header-panel-featured-content"><!----><!----><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="featured-card-1-msignite"><div class="card-content"><p class="card-supertitle line-clamp-2 line-height-normal"><!---->Register now<!----></p><a class="card-title color-text background-color-transparent stretched-link" href="https://ignite.microsoft.com/home?wt.mc_ID=msignite26_gmee_corp_np_oo_MSLearnRegLaunch"><!---->Microsoft Ignite | November 17-20, 2026<!----></a><p class="card-content-description line-clamp-2"><!---->Interactive learning, certifications, and direct access to experts all in one place.<!----></p></div></article><!----><!----></section> <!----></div></panel-controller></li><!----><li aria-setsize="4" aria-posinset="4"><panel-controller data-bi-name="site-header-btn-4-topics"><button type="button" aria-expanded="false" class="site-header-button" data-overflow-menu-item="" aria-controls="ms--panel-4" data-test-id="site-header-panel-controller-4" style="white-space: nowrap;"><span><!---->Topics<!----></span><span class="icon expanded-indicator" aria-hidden="true"><span class="docon docon-chevron-down-light"></span></span></button><div class="site-header-panel" hidden="" id="ms--panel-4" data-bi-name="panel-4-topics" data-test-id="site-header-panel-4"><!----><div class="site-header-panel-content"><ul class="site-header-panel-cards"><!----><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-1-agents"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/agents/"><!---->Agents<!----></a><p class="card-content-description line-clamp-2"><!---->Key concepts and resources for agentic computing<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-2-ai"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/ai/"><!---->Artificial intelligence<!----></a><p class="card-content-description line-clamp-2"><!---->Curated resources for AI fluency with apps and services<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-3-devops"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/devops/"><!---->DevOps<!----></a><p class="card-content-description line-clamp-2"><!---->DevOps practices, Git version control and Agile methods<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-4-microsoft-learn-for-organizations"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/training/organizations/"><!---->Learn for Organizations<!----></a><p class="card-content-description line-clamp-2"><!---->Curated offerings from Microsoft to boost your team’s technical skills<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-5-security"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/security/"><!---->Security<!----></a><p class="card-content-description line-clamp-2"><!---->Guidance to help you tackle security challenges<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-6-startups"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/startups/"><!---->Startups hub<!----></a><p class="card-content-description line-clamp-2"><!---->Technical guidance to move toward enterprise readiness<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-7-assessments"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/assessments/"><!---->Assessments<!----></a><p class="card-content-description line-clamp-2"><!---->Interactive guidance with custom recommendations<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-8-student-hub"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/training/student-hub/"><!---->Student hub<!----></a><p class="card-content-description line-clamp-2"><!---->Self-paced and interactive training for students<!----></p></div></article></li><!----><li><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="panel-card-9-educator-center"><div class="card-content"><a class="card-title color-text background-color-transparent stretched-link" href="/en-us/training/educator-center/"><!---->Educator center<!----></a><p class="card-content-description line-clamp-2"><!---->Resources for educators to bring technical innovation in their classroom<!----></p></div></article></li><!----><!----></ul><!----></div><section class="site-header-panel-featured-content"><!----><!----><article class="card position-relative background-color-body-accent-onhover background-color-body-dark box-shadow-none" data-bi-name="featured-card-1-msignite"><div class="card-content"><p class="card-supertitle line-clamp-2 line-height-normal"><!---->Register now<!----></p><a class="card-title color-text background-color-transparent stretched-link" href="https://ignite.microsoft.com/home?wt.mc_ID=msignite26_gmee_corp_np_oo_MSLearnRegLaunch"><!---->Microsoft Ignite | November 17-20, 2026<!----></a><p class="card-content-description line-clamp-2"><!---->Interactive learning, certifications, and direct access to experts all in one place.<!----></p></div></article><!----><!----></section> <!----></div></panel-controller></li><!----><!----></ul><button type="button" data-overflow-menu-next-button="" data-bi-name="site-header-btn-next" class="button button-clear button-sm inner-focus margin-left-auto" hidden="" aria-label="Next"><span class="icon" aria-hidden="true"><span class="docon docon-chevron-right-light"></span></span></button></nav></overflow-menu><!----><search-expander data-test-id="site-header-search" class="flex-grow-1 margin-left-xxs"><div hidden="" id="ms--site-header-search" class="display-flex align-items-center gap-xxs "><!----><form class="flex-grow-1" method="GET" role="search" id="ms--site-header-search-form" data-bi-name="site-header-search-form" name="site-header-search-form" aria-label="Search" action="/en-us/search/"><!----><div class="autocomplete display-block" data-bi-name="autocomplete"><!----><div class="field-body control "><input role="combobox" maxlength="100" aria-autocomplete="list" autocapitalize="off" autocomplete="off" autocorrect="off" spellcheck="false" id="site-header-search-autocomplete-input" data-test-id="site-header-search-autocomplete-input" class="autocomplete-input input input-sm  width-full" type="search" name="terms" aria-expanded="false" aria-owns="ax-0-listbox" aria-controls="ax-0-listbox" aria-activedescendant="" aria-label="Search" aria-describedby="ms--site-header-search-autocomplete-input-description" placeholder="Search" data-bi-name="site-header-search-autocomplete-input" pattern=".*"> <span hidden="" id="ms--site-header-search-autocomplete-input-description"><!---->Suggestions will filter as you type<!----></span></div><ul role="listbox" id="ax-0-listbox" data-test-id="site-header-search-autocomplete-input-listbox" class="autocomplete-suggestions is-vertically-scrollable padding-xxs " aria-label="Suggestions" hidden=""><!----> <!----></ul><!----></div><button type="submit" class="visually-hidden" tabindex="-1" aria-hidden="true"></button><input name="category" hidden="" value=""> <!----></form><button data-search-expander-trigger-close="" type="button" class="button button-clear inner-focus" aria-controls="ms--site-header-search" aria-label="Close search" data-bi-name="site-header-search-close" data-test-id="site-header-search-close"><span class="icon" aria-hidden="true"><span class="docon docon-navigate-close"></span></span></button></div><button data-search-expander-trigger-open="" type="button" class="button button-clear inner-focus" aria-controls="ms--site-header-search" aria-label="Open search" data-bi-name="site-header-search-open" data-test-id="site-header-search-open"><span class="icon" aria-hidden="true"><span class="docon docon-search"></span></span></button></search-expander><!----></div><!----><a href="#" data-bi-name="site-header-sign-in" data-test-id="site-header-sign-in" class="link-button font-size-sm flex-shrink-0 docs-sign-in auth-status-determined not-authenticated "><!---->Sign in<!----></a> <details data-bi-name="site-header-user" class="popover popover-right auth-status-determined authenticated "><summary data-bi-name="site-header-user-avatar" aria-label="Your Account" data-test-id="site-header-user"><div class="persona "><figure class="persona-avatar"><img alt="" data-profile-property="avatarThumbnailUrl"></figure></div></summary><div class="popover-content width-auto" data-bi-name="site-header-user-menu"><div class="persona "><figure class="persona-avatar"><img alt="" data-profile-property="avatarUrl" aria-labelledby="ms--user-display-name"></figure><div class="persona-details" data-test-id="persona-detail"><p class="persona-name" data-profile-property="displayName" id="ms--user-display-name"></p><p data-profile-property="upn"></p></div></div><ul class="padding-block-xs"><li class="padding-bottom-xs"><a data-profile-property="profileUrl" class="font-size-sm" data-bi-name="site-header-user-profile" href="https://learn.microsoft.com/en-us/users/me/activity/"><!---->Profile<!----></a></li><li class="padding-bottom-xs"><a class="font-size-sm" data-bi-name="site-header-user-analytics" href="https://learn.microsoft.com/en-us/users/me/analytics/"><!---->Analytics<!----></a></li><li><a data-profile-property="settingsUrl" class="font-size-sm" data-bi-name="site-header-user-settings" href="https://learn.microsoft.com/en-us/users/me/settings/"><!---->Settings<!----></a></li></ul><div class="border-top padding-top-xs"><a class="docs-sign-out font-size-sm" href="#" data-bi-name="site-header-sign-out" data-test-id="site-header-user-sign-out"><!---->Sign out<!----></a></div></div></details><!----> <!----></div>
				<div id="ms--secondary-nav" class="display-none display-flex-tablet" data-bi-name="L2-header" data-test-id="secondary-header"><!----><div class="site-header width-full"><!----> <a class="site-header-brand font-size-h6 padding-inline-none margin-right-xxs" itemprop="url" href="/en-us/entra" data-bi-name="secondary-nav-link-category-microsoft-entra"><span><!---->Microsoft Entra <!----></span></a>  <nav class="site-header-nav width-auto" data-bi-name="secondary-nav" aria-label="Site"><ul class="display-flex"><!----><!----><li><a data-test-id="header-link-microsoft-entra-id" class="has-external-link-indicator site-header-button " href="/en-us/entra/identity/" data-bi-name="secondary-nav-link-1-microsoft-entra-id"><span><!---->Microsoft Entra ID<!----></span></a></li><!----><li><a data-test-id="header-link-agent-id" class="has-external-link-indicator site-header-button " href="/en-us/entra/agent-id/" data-bi-name="secondary-nav-link-2-agent-id"><span><!---->Agent ID<!----></span></a></li><!----><li><a data-test-id="header-link-external-id" class="has-external-link-indicator site-header-button " href="/en-us/entra/external-id/" data-bi-name="secondary-nav-link-3-external-id"><span><!---->External ID<!----></span></a></li><!----><li><a data-test-id="header-link-global-secure-access" class="has-external-link-indicator site-header-button " href="/en-us/entra/global-secure-access/" data-bi-name="secondary-nav-link-4-global-secure-access"><span><!---->Global Secure Access<!----></span></a></li><!----><li><a data-test-id="header-link-id-governance" class="has-external-link-indicator site-header-button " href="/en-us/entra/id-governance/" data-bi-name="secondary-nav-link-5-id-governance"><span><!---->ID Governance<!----></span></a></li><!----><li><a data-test-id="header-link-microsoft-security-documentation" class="has-external-link-indicator site-header-button " href="/en-us/security/" data-bi-name="secondary-nav-link-6-microsoft-security-documentation"><span><!---->Microsoft Security documentation<!----></span></a></li><!----><li><a data-test-id="header-link-troubleshooting" class="has-external-link-indicator site-header-button " href="/en-us/troubleshoot/entra/welcome-entra" data-bi-name="secondary-nav-link-7-troubleshooting"><span><!---->Troubleshooting<!----></span></a></li><!----><li class="dropdown" hidden=""><button type="button" aria-expanded="false" class="dropdown-trigger site-header-button  site-header-button-icon-chevron" aria-controls="bx-11" data-bi-name="secondary-nav-btn-more" value="undefined"><span><!---->More<!----></span><span aria-hidden="true" class="icon expanded-indicator "><span class="docon docon-chevron-down-light"></span></span></button><ul class="dropdown-menu padding-bottom-xxs background-color-body-medium" id="bx-11" aria-label="More" data-bi-name="secondary-nav-menu-more"><!----><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/entra/identity/" data-bi-name="secondary-nav-link-1-microsoft-entra-id"><span><!---->Microsoft Entra ID<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/entra/agent-id/" data-bi-name="secondary-nav-link-2-agent-id"><span><!---->Agent ID<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/entra/external-id/" data-bi-name="secondary-nav-link-3-external-id"><span><!---->External ID<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/entra/global-secure-access/" data-bi-name="secondary-nav-link-4-global-secure-access"><span><!---->Global Secure Access<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/entra/id-governance/" data-bi-name="secondary-nav-link-5-id-governance"><span><!---->ID Governance<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/security/" data-bi-name="secondary-nav-link-6-microsoft-security-documentation"><span><!---->Microsoft Security documentation<!----></span></a></li><!----><li hidden=""><a class="has-external-link-indicator site-header-button width-full justify-content-flex-start padding-inline-xs padding-block-xxs " href="/en-us/troubleshoot/entra/welcome-entra" data-bi-name="secondary-nav-link-7-troubleshooting"><span><!---->Troubleshooting<!----></span></a></li><!----><!----></ul></li><!----><!----></ul></nav><span class="nav-bar-spacer"></span><div class="buttons"><!----> <a data-test-id="navbar-primary-cta" class="button button-sm button-primary button-filled margin-right-none" href="https://entra.microsoft.com/" data-bi-name="secondary-nav-cta-primary-admin-center"><!---->Admin center<!----></a><!----></div>   <!----></div><!----></div>
			</div>
			
		<!-- banner -->
		<div data-banner="">
			<div id="disclaimer-holder"></div>
			
		</div>
		<!-- banner end -->
	
		</div>
	</header>
				 <section id="layout-body-menu" class="layout-body-menu border-right display-flex background-color-body-medium" data-bi-name="menu">
					
		<div id="left-container" class="left-container display-none padding-none display-block-tablet width-full display-none-until-layout-restored" data-toc-container="true" data-toc-collapsed="false">
			<div id="ms--toc-content" class="padding-left-sm padding-right-none padding-bottom-sm height-full">
				<nav id="affixed-left-container" class="margin-top-xxs-tablet position-sticky display-flex flex-direction-column width-full" aria-label="Primary" data-bi-name="left-toc" role="navigation" style="top: 8px; height: calc(-117px + 100vh); max-height: 11443px;">
					<div id="ms--collapsible-toc-header" class="display-flex flex-direction-row-reverse justify-content-center align-items-center margin-bottom-xxs margin-right-xxs">
						<button type="button" class="button button-clear inner-focus" data-collapsible-toc-toggle="" aria-expanded="true" aria-controls="ms--toc-content" aria-label="Collapse" title="Collapse" data-bi-name="toc-collapse">
							<span class="icon icon-mirrored-rtl font-size-md" aria-hidden="true">
								<span class="docon docon-panel-left-contract display-none-layout-menu-collapsed"></span>
								<span class="docon docon-panel-left-expand display-none display-inline-layout-menu-collapsed"></span>
							</span>
						</button>
						<div id="ms--collapsible-toc-moniker-slot" class="flex-grow-1 display-none-layout-menu-collapsed"></div>
					</div>
				<form action="javascript:" role="search" aria-label="Search" class="margin-bottom-xxs display-none-layout-menu-collapsed" style="padding-inline-end: 24px;"><label class="visually-hidden" for="ax-2">Search</label><div class="autocomplete display-block" data-bi-name="autocomplete"><!----><div class="field-body control has-icons-left"><input role="combobox" maxlength="100" aria-autocomplete="list" autocapitalize="off" autocomplete="off" autocorrect="off" spellcheck="false" id="ax-2" data-test-id="ax-2" class="autocomplete-input input input-sm control has-icons-left width-full" type="text" aria-expanded="false" aria-owns="ax-3-listbox" aria-controls="ax-3-listbox" aria-activedescendant="" aria-describedby="ms--ax-2-description" placeholder="Find by title" pattern=".*"><span aria-hidden="true" class="icon is-small is-left"><span class="color-text-subtle docon docon-find-by-title"></span></span> <span aria-hidden="true" class="autocomplete-loader loader color-primary " hidden=""></span><span hidden="" id="ms--ax-2-description"><!---->Suggestions will filter as you type<!----></span></div><ul role="listbox" id="ax-3-listbox" data-test-id="ax-2-listbox" class="autocomplete-suggestions is-vertically-scrollable padding-xxs " aria-label="Suggestions" hidden=""><!----> <!----></ul><!----></div></form><ul class="tree table-of-contents is-vertically-scrollable flex-grow-1 flex-shrink-1 padding-right-sm display-none-layout-menu-collapsed" role="tree" aria-label="Table of contents" data-bi-name="tree" data-is-collapsible="true"><li role="none"><a aria-setsize="13" aria-level="1" aria-posinset="1" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/">Microsoft identity platform</a></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="2" role="treeitem" tabindex="-1" id="title-2-1" aria-expanded="true"><span data-bi-name="tree-expander" class="tree-expander">Overview</span><ul class="tree-group" role="group"><li role="none"><a aria-setsize="3" aria-level="2" aria-posinset="1" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-overview">What is the Microsoft identity platform?</a></li><li role="none"><a aria-setsize="3" aria-level="2" aria-posinset="2" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/whats-new-docs">What's new in docs?</a></li><li role="none"><a aria-setsize="3" aria-level="2" aria-posinset="3" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/sample-v2-code">Samples</a></li></ul></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="3" role="treeitem" tabindex="-1" id="title-3-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Concepts</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="4" role="treeitem" tabindex="-1" id="title-4-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Single-page app (SPA)</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="5" role="treeitem" tabindex="-1" id="title-5-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Web app</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="6" role="treeitem" tabindex="-1" id="title-6-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Web API</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="7" role="treeitem" tabindex="-1" id="title-7-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Desktop</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="8" role="treeitem" tabindex="-1" id="title-8-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Mobile</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="9" role="treeitem" tabindex="-1" id="title-9-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Service, daemon, script</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="10" role="treeitem" tabindex="-1" id="title-10-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Command-line interface (CLI) app</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="11" role="treeitem" tabindex="-1" id="title-11-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">How-to</span></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="12" role="treeitem" tabindex="-1" id="title-12-1" aria-expanded="true"><span data-bi-name="tree-expander" class="tree-expander">Reference</span><ul class="tree-group" role="group"><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="1" role="treeitem" tabindex="-1" id="title-12-1_1-2" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Token claims reference</span></li><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="2" role="treeitem" tabindex="-1" id="title-12-1_2-2" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Microsoft Authentication Library (MSAL) reference</span></li><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="3" role="treeitem" tabindex="-1" id="title-12-1_3-2" aria-expanded="true"><span data-bi-name="tree-expander" class="tree-expander">Protocol reference (OAuth, OIDC, SAML)</span><ul class="tree-group" role="group"><li role="none"><a aria-setsize="7" aria-level="3" aria-posinset="1" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-app-types">OAuth 2.0 application types</a></li><li class="tree-item" aria-setsize="7" aria-level="3" aria-posinset="2" role="treeitem" tabindex="-1" id="title-12-1_3-2_2-3" aria-expanded="true"><span data-bi-name="tree-expander" class="tree-expander">Token grant flows</span><ul class="tree-group" role="group"><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="1" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow">OAuth 2.0 auth code grant</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="2" role="treeitem" tabindex="0" class="tree-item tree-leaf has-external-link-indicator is-selected" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow" aria-current="page">OAuth 2.0 client credentials grant</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="3" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code">OAuth 2.0 device code flow</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="4" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-on-behalf-of-flow">OAuth 2.0 on-behalf-of flow</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="5" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-implicit-grant-flow">OAuth 2.0 implicit grant flow</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="6" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth-ropc">OAuth 2.0 resource owner password credentials grant</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="7" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-protocols-oidc">OpenID Connect (OIDC)</a></li><li role="none"><a aria-setsize="8" aria-level="4" aria-posinset="8" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/reference-oidc-extensibility">OIDC extensibility reference</a></li></ul></li><li role="none"><a aria-setsize="7" aria-level="3" aria-posinset="3" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/certificate-credentials">Certificate credentials</a></li><li role="none"><a aria-setsize="7" aria-level="3" aria-posinset="4" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/signing-key-rollover">Signing key rollover</a></li><li role="none"><a aria-setsize="7" aria-level="3" aria-posinset="5" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/userinfo">UserInfo endpoint (OIDC)</a></li><li class="tree-item" aria-setsize="7" aria-level="3" aria-posinset="6" role="treeitem" tabindex="-1" id="title-12-1_3-2_6-3" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">SAML 2.0</span></li><li class="tree-item" aria-setsize="7" aria-level="3" aria-posinset="7" role="treeitem" tabindex="-1" id="title-12-1_3-2_7-3" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">WS-Federation</span></li></ul></li><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="4" role="treeitem" tabindex="-1" id="title-12-1_4-2" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">App registration reference</span></li><li role="none"><a aria-setsize="10" aria-level="2" aria-posinset="5" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/reference-native-authentication-api">Native authentication API reference</a></li><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="6" role="treeitem" tabindex="-1" id="title-12-1_6-2" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Endpoint reference</span></li><li class="tree-item" aria-setsize="10" aria-level="2" aria-posinset="7" role="treeitem" tabindex="-1" id="title-12-1_7-2" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">API reference</span></li><li role="none"><a aria-setsize="10" aria-level="2" aria-posinset="8" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/reference-v2-libraries">Microsoft auth libraries by app type</a></li><li role="none"><a aria-setsize="10" aria-level="2" aria-posinset="9" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/reference-error-codes">AADSTS error code reference</a></li><li role="none"><a aria-setsize="10" aria-level="2" aria-posinset="10" role="treeitem" tabindex="-1" class="tree-item tree-leaf has-external-link-indicator" data-bi-name="tree-leaf" href="https://learn.microsoft.com/en-us/entra/identity-platform/troubleshoot-required-resource-access-limits">Configured permissions limits troubleshooting</a></li></ul></li><li class="tree-item" aria-setsize="13" aria-level="1" aria-posinset="13" role="treeitem" tabindex="-1" id="title-13-1" aria-expanded="false"><span data-bi-name="tree-expander" class="tree-expander">Resources</span></li></ul><div class="margin-right-sm border-top display-none-layout-menu-collapsed"><button class="margin-block-xxs button button-sm button-clear button-block inner-focus justify-content-flex-start-tablet padding-inline-none display-none-layout-menu-collapsed" data-bi-name="download-pdf" rel="nofollow"><!----><span class="icon" aria-hidden="true"><span class="docon docon-download"></span></span><span><!---->Download PDF<!----></span><!----></button></div></nav>
			</div>
		</div>
	
			  </section>

				<main id="main" role="main" class="layout-body-main " data-bi-name="content" lang="en-us" dir="ltr">
					
			<div id="ms--content-header" class="content-header default-focus border-bottom-none" data-bi-name="content-header">
		<div class="content-header-controls margin-xxs margin-inline-sm-tablet">
			<button type="button" class="contents-button button button-sm margin-right-xxs" data-bi-name="contents-expand" aria-haspopup="true" data-contents-button="">
				<span class="icon" aria-hidden="true"><span class="docon docon-menu"></span></span>
				<span class="contents-expand-title"> Table of contents </span>
			</button>
			<button type="button" class="ap-collapse-behavior ap-expanded button button-sm" data-bi-name="ap-collapse" aria-controls="action-panel">
				<span class="icon" aria-hidden="true"><span class="docon docon-exit-mode"></span></span>
				<span>Exit editor mode</span>
			</button>
		</div>
	</div>
			<div data-main-column="" class="reading-width margin-inline-auto layout-padding padding-top-none padding-top-sm-tablet padding-bottom-sm">
				<div>
					
		<div id="article-header" class="background-color-body margin-bottom-xs display-none-print">
			<div class="display-flex align-items-center justify-content-space-between">
				
		<details id="article-header-breadcrumbs-overflow-popover" class="popover popover-left" data-for="article-header-breadcrumbs" hidden="">
			<summary class="button button-clear button-primary button-sm inner-focus" aria-label="All breadcrumbs">
				<span class="icon" aria-hidden="true">
					<span class="docon docon-more"></span>
				</span>
			</summary>
			<div id="article-header-breadcrumbs-overflow" class="popover-content"><!----><nav aria-label="All breadcrumbs"><ol class="list-style-none"><!----><!----><li><a class="button button-clear button-sm button-block text-align-left inner-focus justify-content-flex-start padding-xxs border-none font-weight-normal" href="https://learn.microsoft.com/en-us/" title="Learn"><span class="line-clamp-1"><!---->Learn<!----></span></a></li><!----><!----><li><a class="button button-clear button-sm button-block text-align-left inner-focus justify-content-flex-start padding-xxs border-none font-weight-normal" href="https://learn.microsoft.com/en-us/entra/" title="Microsoft Entra"><span class="line-clamp-1"><!---->Microsoft Entra<!----></span></a></li><!----><!----><li><a class="button button-clear button-sm button-block text-align-left inner-focus justify-content-flex-start padding-xxs border-none font-weight-normal" href="https://learn.microsoft.com/en-us/entra/identity-platform/" title="Microsoft identity platform"><span class="line-clamp-1"><!---->Microsoft identity platform<!----></span></a></li><!----><!----></ol></nav> <!----></div>
		</details>

		<bread-crumbs id="article-header-breadcrumbs" role="group" aria-label="Breadcrumbs" data-test-id="article-header-breadcrumbs" class="overflow-hidden flex-grow-1 margin-right-sm margin-right-md-tablet margin-right-lg-desktop margin-left-negative-xxs padding-left-xxs" style="display: block; white-space: nowrap; overflow: hidden;"><!----><nav aria-label="Breadcrumb"><ol class="breadcrumbs"><!----><!----><li class="breadcrumbs-item" data-bread-crumbs-collapse-target=""><a href="https://learn.microsoft.com/en-us/"><!---->Learn<!----></a></li><!----><!----><li class="breadcrumbs-item" data-bread-crumbs-collapse-target=""><a href="https://learn.microsoft.com/en-us/entra/"><!---->Microsoft Entra<!----></a></li><!----><!----><li class="breadcrumbs-item" data-bread-crumbs-collapse-target="" style=""><a href="https://learn.microsoft.com/en-us/entra/identity-platform/" style=""><!---->Microsoft identity platform<!----></a></li><!----><!----></ol></nav><!----></bread-crumbs>
	 
		<div id="article-header-page-actions" class="margin-left-auto display-flex flex-wrap-no-wrap align-items-stretch">
			
		<button class="button button-sm border-none inner-focus display-none-tablet flex-shrink-0 " data-bi-name="ask-learn-assistant-entry" data-test-id="ask-learn-assistant-modal-entry-mobile" data-ask-learn-modal-entry="" type="button" style="min-width: max-content;" aria-expanded="false" aria-label="Ask Learn">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
		</button>
		<button class="button button-sm display-none display-inline-flex-tablet display-none-desktop flex-shrink-0 margin-right-xxs border-color-ask-learn " data-bi-name="ask-learn-assistant-entry" data-test-id="ask-learn-assistant-modal-entry-tablet" data-ask-learn-modal-entry="" type="button" style="min-width: max-content;" aria-expanded="false">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
		<button class="button button-sm display-none flex-shrink-0 display-inline-flex-desktop margin-right-xxs border-color-ask-learn" data-bi-name="ask-learn-assistant-entry" data-test-id="ask-learn-assistant-flyout-entry" data-ask-learn-flyout-entry="" data-flyout-button="toggle" type="button" style="min-width: max-content;" aria-expanded="false" aria-controls="ask-learn-flyout">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
	 

			<details class="popover popover-right" id="article-header-page-actions-overflow">
				<summary class="justify-content-flex-start button button-clear button-sm button-primary inner-focus" aria-label="More actions" title="More actions">
					<span class="icon" aria-hidden="true">
						<span class="docon docon-more-vertical"></span>
					</span>
				</summary>
				<div class="popover-content">
					
		<button type="button" id="ms--focus-mode-button" data-focus-mode="" data-bi-name="focus-mode-entry" data-page-action-item="overflow-all" data-popover-close="" class="button button-clear button-sm button-block justify-content-flex-start text-align-left inner-focus display-none display-inline-flex-tablet" aria-pressed="false">
			<span class="icon" aria-hidden="true">
				<span class="docon docon-glasses"></span>
			</span>
			<span>Reading mode</span>
		</button>
	 
		<button data-page-action-item="overflow-mobile" type="button" class="display-block-layout-menu-collapsed button-block button-sm inner-focus button button-clear display-none-tablet justify-content-flex-start text-align-left" data-bi-name="contents-expand" data-contents-button="" data-popover-close="">
			<span class="icon" aria-hidden="true"><span class="docon docon-editor-list-bullet"></span></span>
			<span class="contents-expand-title">Table of contents</span>
		</button>
	 
		<a id="lang-link-overflow" class="button-sm inner-focus button button-clear button-block justify-content-flex-start text-align-left" data-bi-name="language-toggle" data-page-action-item="overflow-all" data-check-hidden="true" data-read-in-link="" href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow" hidden="" data-bi="{&quot;cN&quot;:&quot;language-toggle&quot;,&quot;value&quot;:&quot;off&quot;}">
			<span class="icon" aria-hidden="true" data-read-in-link-icon="">
				<span class="docon docon-locale-globe"></span>
			</span>
			<span data-read-in-link-text="">Read in English</span>
		</a>
	
					
		<button type="button" class="collection button button-clear button-sm button-block justify-content-flex-start text-align-left inner-focus" data-list-type="collection" data-bi-name="collection" data-page-action-item="overflow-all" data-check-hidden="true" data-popover-close="" data-pressed="false" title="Add OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform | Microsoft Learn to a collection">
			<span class="icon" aria-hidden="true">
				<span class="docon docon-circle-addition"></span>
			</span>
			<span class="collection-status">Add to Collections</span>
		</button>
	 
		<button type="button" class="collection button button-block button-clear button-sm justify-content-flex-start text-align-left inner-focus" data-list-type="plan" data-bi-name="plan" data-page-action-item="overflow-all" data-check-hidden="true" data-popover-close="" data-pressed="false" title="Add OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform | Microsoft Learn to a plan">
			<span class="icon" aria-hidden="true">
				<span class="docon docon-circle-addition"></span>
			</span>
			<span class="plan-status">Add to Plans</span>
		</button>
	 
					
		<a data-contenteditbtn="" class="button button-clear button-block button-sm inner-focus justify-content-flex-start text-align-left text-decoration-none" data-bi-name="edit" data-page-action-item="overflow-all" data-check-hidden="true" href="https://github.com/MicrosoftDocs/entra-docs/blob/main/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md" data-original_content_git_url="https://github.com/MicrosoftDocs/entra-docs-pr/blob/live/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md" data-original_content_git_url_template="{repo}/blob/{branch}/docs/identity-platform/v2-oauth2-client-creds-grant-flow.md" data-pr_repo="" data-pr_branch="">
			<span class="icon" aria-hidden="true">
				<span class="docon docon-edit-outline"></span>
			</span>
			<span>Edit</span>
		</a>
	  
		<hr class="margin-block-xxs">
		
				<button class="button button-block button-clear button-sm justify-content-flex-start text-align-left inner-focus" type="button" data-bi-name="copy-markdown" data-page-action-item="overflow-all" data-copy-markdown="" data-copy-state="idle" data-check-hidden="true">
					<span class="icon color-primary" aria-hidden="true">
						<span data-show-when="idle" class="docon docon-code-lang"></span>
						<span data-show-when="loading" class="loader" hidden=""></span>
						<span data-show-when="success" class="docon docon-check-mark" hidden=""></span>
					</span>
					<span>Copy Markdown</span>
				</button>
		   
				<button class="button button-block button-clear button-sm justify-content-flex-start text-align-left inner-focus" type="button" data-bi-name="print" data-page-action-item="overflow-all" data-popover-close="" data-print-page="" data-check-hidden="true">
					<span class="icon color-primary" aria-hidden="true">
						<span class="docon docon-print"></span>
					</span>
					<span>Print</span>
				</button>
		  
	
				</div>
			</details>
		</div>
	
			</div>
		</div>
	  
		<!-- privateUnauthorizedTemplate is hidden by default -->
		<div unauthorized-private-section="" data-bi-name="permission-content-unauthorized-private" hidden="">
			<hr class="hr margin-top-xs margin-bottom-sm">
			<div class="notification notification-info">
				<div class="notification-content">
					<p class="margin-top-none notification-title">
						<span class="icon" aria-hidden="true"><span class="docon docon-exclamation-circle-solid"></span></span>
						<span>Note</span>
					</p>
					<p class="margin-top-none authentication-determined not-authenticated">
						Access to this page requires authorization. You can try <a class="docs-sign-in" href="#" data-bi-name="permission-content-sign-in">signing in</a> or <a class="docs-change-directory" data-bi-name="permisson-content-change-directory">changing directories</a>.
					</p>
					<p class="margin-top-none authentication-determined authenticated">
						Access to this page requires authorization. You can try <a class="docs-change-directory" data-bi-name="permisson-content-change-directory">changing directories</a>.
					</p>
				</div>
			</div>
		</div>
	
					<div class="content"><h1 id="microsoft-identity-platform-and-the-oauth-20-client-credentials-flow">Microsoft identity platform and the OAuth 2.0 client credentials flow</h1></div>
					
		<div id="article-metadata" data-bi-name="article-metadata" data-test-id="article-metadata" class="page-metadata-container display-flex gap-xxs justify-content-space-between align-items-center flex-wrap-wrap">
			 
				<div id="user-feedback" class="margin-block-xxs display-none display-none-print" hidden="" data-hide-on-archived="">
					
		<button id="user-feedback-button" data-test-id="conceptual-feedback-button" class="button button-sm button-clear button-primary display-none" type="button" data-bi-name="user-feedback-button" data-user-feedback-button="" hidden="">
			<span class="icon" aria-hidden="true">
				<span class="docon docon-like"></span>
			</span>
			<span>Feedback</span>
		</button>
	
				</div>
		  
		</div>
	 
		<div data-id="ai-summary" class="display-none-print">
			<div id="ms--ai-summary-cta" class="margin-top-xs display-flex align-items-center">
				<span class="icon" aria-hidden="true">
					<span class="docon docon-sparkle-fill gradient-text-vivid"></span>
				</span>
				<button id="ms--ai-summary" type="button" class="tag tag-sm tag-suggestion margin-left-xxs" data-test-id="ai-summary-cta" data-bi-name="ai-summary-cta" data-an="ai-summary">
					<span class="ai-summary-cta-text">
						Summarize this article for me
					</span>
				</button>
			</div>
			<!-- Slot where the client will render the summary card after the user clicks the CTA -->
			<div id="ms--ai-summary-header" class="margin-top-xs"></div>
		</div>
	 
		<nav id="center-doc-outline" class="doc-outline display-none-desktop display-none-print margin-bottom-sm" data-bi-name="intopic toc" aria-label="In this article"><!----><h2 id="ms--in-this-article" class="title is-6 margin-block-xs"><!---->In this article<!----></h2><ol id="content-well-in-this-article-list" class="border-left padding-left-xxs"><!----><!----><li class=" "><a href="#protocol-diagram" class=""><!---->Protocol diagram<!----></a></li><!----><li class=" "><a href="#get-direct-authorization" class=""><!---->Get direct authorization<!----></a></li><!----><li class=" "><a href="#get-a-token" class=""><!---->Get a token<!----></a></li><!----><li class=" "><a href="#use-a-token" class=""><!---->Use a token<!----></a></li><!----><li class=" "><a href="#code-samples-and-other-documentation" class=""><!---->Code samples and other documentation<!----></a></li><!----><!----></ol> <!----></nav>
	
					<div class="content"><p>The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. The grant specified in <a href="https://tools.ietf.org/html/rfc6749#section-4.4" data-linktype="external">RFC 6749</a>, sometimes called <em>two-legged OAuth</em>, can be used to access web-hosted resources by using the identity of an application. This type is commonly used for server-to-server interactions that must run in the background, without immediate interaction with a user, and is often referred to as <em>daemons</em> or <em>service accounts</em>.</p>
<div class="alert is-info">
<p class="alert-title"><span class="icon" aria-hidden="true"><span class="docon docon-status-error-outline"></span></span> Note</p>
<p>When you configure machine-to-machine (M2M) authentication for <a href="/en-us/entra/external-id/external-identities-overview" data-linktype="absolute-path">Microsoft Entra External ID</a>, you must use the <a href="https://www.microsoft.com/security/pricing/microsoft-entra-external-id/" data-linktype="external">M2M Premium add‑on</a>. Review your organization’s premium add‑on usage policy to understand cost implications and ensure the implementation complies with internal governance and licensing guidelines.</p>
</div>
<p>In the client credentials flow, permissions are granted directly to the application itself by an administrator. When the app presents a token to a resource, the resource enforces that the app itself has authorization to perform an action since there is no user involved in the authentication. This article covers both the steps needed to:</p>
<ul>
<li><a href="#application-permissions" data-linktype="self-bookmark">Authorize an application to call an API</a></li>
<li><a href="#get-a-token" data-linktype="self-bookmark">How to get the tokens needed to call that API</a>.</li>
</ul>
<p>This article describes how to program directly against the protocol in your application. When possible, we recommend you use the supported Microsoft Authentication Libraries (MSAL) instead to <a href="authentication-flows-app-scenarios#scenarios-and-supported-authentication-flows" data-linktype="relative-path">acquire tokens and call secured web APIs</a>. You can also refer to the <a href="sample-v2-code" data-linktype="relative-path">sample apps that use MSAL</a>. As a side note, refresh tokens will never be granted with this flow as <code>client_id</code> and <code>client_</code> (which would be required to obtain a refresh token) can be used to obtain an access token instead.</p>
<p>For a higher level of assurance, the Microsoft identity platform also allows the calling service to authenticate using a <a href="#second-case-access-token-request-with-a-certificate" data-linktype="self-bookmark">certificate</a> or federated credential instead of a shared secret.  Because the application's own credentials are being used, these credentials must be kept safe. <em>Never</em> publish that credential in your source code, embed it in web pages, or use it in a widely distributed native application. Authentication requests using the client credentials flow pages will not be allowed.</p>
<div class="heading-wrapper" data-heading-level="h2"><a class="anchor-link docon docon-link" href="#protocol-diagram" aria-label="Section titled: Protocol diagram"></a><h2 id="protocol-diagram" class="heading-anchor">Protocol diagram</h2></div>
<p>The entire client credentials flow looks similar to the following diagram. We describe each of the steps later in this article.</p>
<p><img src="media/v2-oauth2-client-creds-grant-flow/convergence-scenarios-client-creds.svg" alt="Diagram showing the client credentials flow" data-linktype="relative-path"></p>
<div class="heading-wrapper" data-heading-level="h2"><a class="anchor-link docon docon-link" href="#get-direct-authorization" aria-label="Section titled: Get direct authorization"></a><h2 id="get-direct-authorization" class="heading-anchor">Get direct authorization</h2></div>
<p>An app typically receives direct authorization to access a resource in one of two ways:</p>
<ul>
<li><a href="#access-control-lists" data-linktype="self-bookmark">Through an access control list (ACL) at the resource</a></li>
<li><a href="#application-permissions" data-linktype="self-bookmark">Through application permission assignment in Microsoft Entra ID</a></li>
</ul>
<p>These two methods are the most common in Microsoft Entra ID and we recommend them for clients and resources that perform the client credentials flow. A resource can also choose to authorize its clients in other ways. Each resource server can choose the method that makes the most sense for its application.</p>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#access-control-lists" aria-label="Section titled: Access control lists"></a><h3 id="access-control-lists" class="heading-anchor">Access control lists</h3></div>
<p>A resource provider might enforce an authorization check based on a list of application (client) IDs that it knows and grants a specific level of access to. When the resource receives a token from the Microsoft identity platform, it can decode the token and extract the client's application ID from the <code>appid</code> and <code>iss</code> claims. Then it compares the application against an access control list (ACL) that it maintains. The ACL's granularity and method might vary substantially between resources.</p>
<p>A common use case is to use an ACL to run tests for a web application or for a web API. The web API might grant only a subset of full permissions to a specific client. To run end-to-end tests on the API, you can create a test client that acquires tokens from the Microsoft identity platform and then sends them to the API. The API then checks the ACL for the test client's application ID for full access to the API's entire functionality. If you use this kind of ACL, be sure to validate not only the caller's <code>appid</code> value but also validate that the <code>iss</code> value of the token is trusted.</p>
<p>This type of authorization is common for daemons and service accounts that need to access data owned by consumer users who have personal Microsoft accounts. For data owned by organizations, we recommend that you get the necessary authorization through application permissions.</p>
<div class="heading-wrapper" data-heading-level="h4"><a class="anchor-link docon docon-link" href="#controlling-tokens-without-the-roles-claim" aria-label="Section titled: Controlling tokens without the roles claim"></a><h4 id="controlling-tokens-without-the-roles-claim" class="heading-anchor">Controlling tokens without the <code>roles</code> claim</h4></div>
<p>In order to enable this ACL-based authorization pattern, Microsoft Entra ID doesn't require that applications be authorized to get tokens for another application. Thus, app-only tokens can be issued without a <code>roles</code> claim. Applications that expose APIs must implement permission checks in order to accept tokens.</p>
<p>If you'd like to prevent applications from getting role-less app-only access tokens for your application, <a href="../identity/enterprise-apps/what-is-access-management#requiring-user-assignment-for-an-app" data-linktype="relative-path">ensure that assignment requirements are enabled for your app</a>. This will block users and applications without assigned roles from being able to get a token for this application.</p>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#application-permissions" aria-label="Section titled: Application permissions"></a><h3 id="application-permissions" class="heading-anchor">Application permissions</h3></div>
<p>Instead of using ACLs, you can use APIs to expose a set of <strong>application permissions</strong>. These are granted to an application by an organization's administrator, and can be used only to access data owned by that organization and its employees. For example, Microsoft Graph exposes several application permissions to do the following:</p>
<ul>
<li>Read mail in all mailboxes</li>
<li>Read and write mail in all mailboxes</li>
<li>Send mail as any user</li>
<li>Read directory data</li>
</ul>
<p>To use app roles (application permissions) with your own API (as opposed to Microsoft Graph), you must first <a href="howto-add-app-roles-in-apps" data-linktype="relative-path">expose the app roles</a> in the API's app registration in the Microsoft Entra admin center. Then, <a href="howto-add-app-roles-in-apps#assign-app-roles-to-applications" data-linktype="relative-path">configure the required app roles</a> by selecting those permissions in your client application's app registration. If you haven't exposed any app roles in your API's app registration, you won't be able to specify application permissions to that API in your client application's app registration in the Microsoft Entra admin center.</p>
<p>When authenticating as an application (as opposed to with a user), you can't use <em>delegated permissions</em> because there is no user for your app to act on behalf of. You must use application permissions, also known as app roles, that are granted by an admin or by the API's owner.</p>
<p>For more information about application permissions, see <a href="permissions-consent-overview#types-of-permissions" data-linktype="relative-path">Permissions and consent</a>.</p>
<div class="heading-wrapper" data-heading-level="h4"><a class="anchor-link docon docon-link" href="#recommended-sign-the-admin-into-your-app-to-have-app-roles-assigned" aria-label="Section titled: Recommended: Sign the admin into your app to have app roles assigned"></a><h4 id="recommended-sign-the-admin-into-your-app-to-have-app-roles-assigned" class="heading-anchor">Recommended: Sign the admin into your app to have app roles assigned</h4></div>
<p>Typically, when you build an application that uses application permissions, the app requires a page or view on which the admin approves the app's permissions. This page can be part of the app's sign-in flow, part of the app's settings, or a dedicated <em>connect</em> flow. It often makes sense for the app to show this <em>connect</em> view only after a user has signed in with a work or school Microsoft account.</p>
<p>If you sign the user into your app, you can identify the organization to which the user belongs to before you ask the user to approve the application permissions. Although not strictly necessary, it can help you create a more intuitive experience for your users. To sign the user in, follow the <a href="v2-protocols" data-linktype="relative-path">Microsoft identity platform protocol tutorials</a>.</p>
<div class="heading-wrapper" data-heading-level="h4"><a class="anchor-link docon docon-link" href="#request-the-permissions-from-a-directory-admin" aria-label="Section titled: Request the permissions from a directory admin"></a><h4 id="request-the-permissions-from-a-directory-admin" class="heading-anchor">Request the permissions from a directory admin</h4></div>
<p>When you're ready to request permissions from the organization's admin, you can redirect the user to the Microsoft identity platform <em>admin consent endpoint</em>.</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-0" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" data-language="HTTP"><code class="lang-HTTP"><span>// <span class="hljs-attribute">Line breaks are for legibility only.

GET https://login.microsoftonline.com/{tenant}/adminconsent?
client_id=00001111-aaaa-2222-bbbb-3333cccc4444
&amp;state=12345
&amp;redirect_uri=http://localhost/myapp/permissions
</span></span></code></pre>
<p>Pro tip: Try pasting the following request in a browser.</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-1" data-bi-name="code-header"><!----><span class="code-block-header-language"><!----><!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language=""><code>https://login.microsoftonline.com/common/adminconsent?client_id=00001111-aaaa-2222-bbbb-3333cccc4444&amp;state=12345&amp;redirect_uri=http://localhost/myapp/permissions
</code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Request the permissions from a directory admin" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Condition</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>tenant</code></td>
<td>Required</td>
<td>The directory tenant that you want to request permission from. This can be in GUID or friendly name format. If you don't know which tenant the user belongs to and you want to let them sign in with any tenant, use <code>common</code>.</td>
</tr>
<tr>
<td><code>client_id</code></td>
<td>Required</td>
<td>The <strong>Application (client) ID</strong> that the <a href="https://go.microsoft.com/fwlink/?linkid=2083908" data-linktype="external">Microsoft Entra admin center – App registrations</a> experience assigned to your app.</td>
</tr>
<tr>
<td><code>redirect_uri</code></td>
<td>Required</td>
<td>The redirect URI where you want the response to be sent for your app to handle. It must exactly match one of the redirect URIs that you registered in the portal, except that it must be URL-encoded, and it can have additional path segments.</td>
</tr>
<tr>
<td><code>state</code></td>
<td>Recommended</td>
<td>A value that's included in the request that's also returned in the token response. It can be a string of any content that you want. The state is used to encode information about the user's state in the app before the authentication request occurred, such as the page or view they were on.</td>
</tr>
</tbody>
</table></div>
<p>At this point, Microsoft Entra ID enforces that only a tenant administrator can sign in to complete the request. The administrator will be asked to approve all the direct application permissions that you have requested for your app in the app registration portal.</p>
<div class="heading-wrapper" data-heading-level="h5"><a class="anchor-link docon docon-link" href="#successful-response" aria-label="Section titled: Successful response"></a><h5 id="successful-response" class="heading-anchor">Successful response</h5></div>
<p>If the admin approves the permissions for your application, the successful response looks like this:</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-2" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-attribute">GET http://localhost/myapp/permissions?tenant=aaaabbbb-0000-cccc-1111-dddd2222eeee&amp;state=state=12345&amp;admin_consent=True
</span></span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Successful response" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>tenant</code></td>
<td>The directory tenant that granted your application the permissions that it requested, in GUID format.</td>
</tr>
<tr>
<td><code>state</code></td>
<td>A value that is included in the request that also is returned in the token response. It can be a string of any content that you want. The state is used to encode information about the user's state in the app before the authentication request occurred, such as the page or view they were on.</td>
</tr>
<tr>
<td><code>admin_consent</code></td>
<td>Set to <strong>True</strong>.</td>
</tr>
</tbody>
</table></div>
<div class="heading-wrapper" data-heading-level="h5"><a class="anchor-link docon docon-link" href="#error-response" aria-label="Section titled: Error response"></a><h5 id="error-response" class="heading-anchor">Error response</h5></div>
<p>If the admin does not approve the permissions for your application, the failed response looks like this:</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-3" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-attribute">GET http://localhost/myapp/permissions?error=permission_denied&amp;error_description=The+admin+canceled+the+request
</span></span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Error response" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>error</code></td>
<td>An error code string that you can use to classify types of errors, and which you can use to react to errors.</td>
</tr>
<tr>
<td><code>error_description</code></td>
<td>A specific error message that can help you identify the root cause of an error.</td>
</tr>
</tbody>
</table></div>
<p>After you've received a successful response from the app provisioning endpoint, your app has gained the direct application permissions that it requested. Now you can request a token for the resource that you want.</p>
<div class="heading-wrapper" data-heading-level="h2"><a class="anchor-link docon docon-link" href="#get-a-token" aria-label="Section titled: Get a token"></a><h2 id="get-a-token" class="heading-anchor">Get a token</h2></div>
<p>After you've acquired the necessary authorization for your application, proceed with acquiring access tokens for APIs. To get a token by using the client credentials grant, send a POST request to the <code>/token</code> Microsoft identity platform. There are a few different cases:</p>
<ul>
<li><a href="#first-case-access-token-request-with-a-shared-secret" data-linktype="self-bookmark">Access token request with a shared secret</a></li>
<li><a href="#second-case-access-token-request-with-a-certificate" data-linktype="self-bookmark">Access token request with a certificate</a></li>
<li><a href="#third-case-access-token-request-with-a-federated-credential" data-linktype="self-bookmark">Access token request with a federated credential</a></li>
</ul>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#first-case-access-token-request-with-a-shared-secret" aria-label="Section titled: First case: Access token request with a shared secret"></a><h3 id="first-case-access-token-request-with-a-shared-secret" class="heading-anchor">First case: Access token request with a shared secret</h3></div>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-4" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-attribute">POST /{tenant}/oauth2/v2.0/token HTTP/1.1           //Line breaks for clarity
Host</span>: login.microsoftonline.com:443
<span class="hljs-attribute">Content-Type</span>: application/x-www-form-urlencoded

<span class="bicep"><span class="hljs-variable">client_id</span>=<span class="hljs-number">00001111</span>-<span class="hljs-variable">aaaa</span>-<span class="hljs-number">2222</span>-<span class="hljs-variable">bbbb</span>-<span class="hljs-number">3333</span>cccc<span class="hljs-number">4444</span>
&amp;<span class="hljs-variable">scope</span>=<span class="hljs-variable">https</span>%<span class="hljs-number">3</span>A%<span class="hljs-number">2</span>F%<span class="hljs-number">2</span>Fgraph.<span class="hljs-variable">microsoft</span>.<span class="hljs-variable">com</span>%<span class="hljs-number">2</span>F.<span class="hljs-variable">default</span>
&amp;<span class="hljs-variable">client_secret</span>=<span class="hljs-variable">A1bC2dE3fH4iJ5kL6mN7oP8qR9sT0u</span>
&amp;<span class="hljs-variable">grant_type</span>=<span class="hljs-variable">client_credentials</span>
</span></span></code></pre>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-5" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->Bash<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="bash"><code class="lang-bash"><span><span class="hljs-comment"># Replace {tenant} with your tenant!</span>
curl -X POST -H <span class="hljs-string">"Content-Type: application/x-www-form-urlencoded"</span> -d <span class="hljs-string">'client_id=00001111-aaaa-2222-bbbb-3333cccc4444&amp;scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&amp;client_secret=A1bC2dE3f...&amp;grant_type=client_credentials'</span> <span class="hljs-string">'https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token'</span>
</span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="First case: Access token request with a shared secret" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Condition</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>tenant</code></td>
<td>Required</td>
<td>The directory tenant the application plans to operate against, in GUID or domain-name format.</td>
</tr>
<tr>
<td><code>client_id</code></td>
<td>Required</td>
<td>The application ID that's assigned to your app. You can find this information in the portal where you registered your app.</td>
</tr>
<tr>
<td><code>scope</code></td>
<td>Required</td>
<td>The value passed for the <code>scope</code> parameter in this request should be the resource identifier (application ID URI) of the resource you want, suffixed with <code>.default</code>. All scopes included must be for a single resource. Including scopes for multiple resources will result in an error. <br>For the Microsoft Graph example, the value is <code>https://graph.microsoft.com/.default</code>. This value tells the Microsoft identity platform that of all the direct application permissions you have configured for your app, the endpoint should issue a token for the ones associated with the resource you want to use. To learn more about the <code>/.default</code> scope, see the <a href="scopes-oidc#the-default-scope" data-linktype="relative-path">consent documentation</a>.</td>
</tr>
<tr>
<td><code>client_secret</code></td>
<td>Required</td>
<td>The client secret that you generated for your app in the app registration portal. The client secret must be URL-encoded before being sent. The Basic auth pattern of instead providing credentials in the Authorization header, per <a href="https://datatracker.ietf.org/doc/html/rfc6749#section-2.3.1" data-linktype="external">RFC 6749</a> is also supported.</td>
</tr>
<tr>
<td><code>grant_type</code></td>
<td>Required</td>
<td>Must be set to <code>client_credentials</code>.</td>
</tr>
</tbody>
</table></div>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#second-case-access-token-request-with-a-certificate" aria-label="Section titled: Second case: Access token request with a certificate"></a><h3 id="second-case-access-token-request-with-a-certificate" class="heading-anchor">Second case: Access token request with a certificate</h3></div>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-6" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-attribute">POST /{tenant}/oauth2/v2.0/token HTTP/1.1               // Line breaks for clarity
Host</span>: login.microsoftonline.com:443
<span class="hljs-attribute">Content-Type</span>: application/x-www-form-urlencoded

<span class="bicep"><span class="hljs-variable">scope</span>=<span class="hljs-variable">https</span>%<span class="hljs-number">3</span>A%<span class="hljs-number">2</span>F%<span class="hljs-number">2</span>Fgraph.<span class="hljs-variable">microsoft</span>.<span class="hljs-variable">com</span>%<span class="hljs-number">2</span>F.<span class="hljs-variable">default</span>
&amp;<span class="hljs-variable">client_id</span>=<span class="hljs-number">11112222</span>-<span class="hljs-variable">bbbb</span>-<span class="hljs-number">3333</span>-<span class="hljs-variable">cccc</span>-<span class="hljs-number">4444</span>dddd<span class="hljs-number">5555</span>
&amp;<span class="hljs-variable">client_assertion_type</span>=<span class="hljs-variable">urn</span>%<span class="hljs-number">3</span>Aietf%<span class="hljs-number">3</span>Aparams%<span class="hljs-number">3</span>Aoauth%<span class="hljs-number">3</span>Aclient-<span class="hljs-variable">assertion</span>-<span class="hljs-variable">type</span>%<span class="hljs-number">3</span>Ajwt-<span class="hljs-variable">bearer</span>
&amp;<span class="hljs-variable">client_assertion</span>=<span class="hljs-variable">eyJhbGciOiJSUzI1NiIsIng1dCI6Imd4OHRHeXN5amNScUtqRlBuZDdSRnd2d1pJMCJ9</span>.<span class="hljs-variable">eyJ</span>{<span class="hljs-property">a</span> <span class="hljs-property">lot</span> <span class="hljs-property">of</span> <span class="hljs-property">characters</span> <span class="hljs-property">here</span>}<span class="hljs-variable">M8U3bSUKKJDEg</span>
&amp;<span class="hljs-variable">grant_type</span>=<span class="hljs-variable">client_credentials</span>
</span></span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Second case: Access token request with a certificate" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Condition</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>tenant</code></td>
<td>Required</td>
<td>The directory tenant the application plans to operate against, in GUID or domain-name format.</td>
</tr>
<tr>
<td><code>client_id</code></td>
<td>Required</td>
<td>The application (client) ID that's assigned to your app.</td>
</tr>
<tr>
<td><code>scope</code></td>
<td>Required</td>
<td>The value passed for the <code>scope</code> parameter in this request should be the resource identifier (application ID URI) of the resource you want, suffixed with <code>.default</code>. All scopes included must be for a single resource. Including scopes for multiple resources will result in an error. <br>For the Microsoft Graph example, the value is <code>https://graph.microsoft.com/.default</code>. This value tells the Microsoft identity platform that of all the direct application permissions you have configured for your app, the endpoint should issue a token for the ones associated with the resource you want to use. To learn more about the <code>/.default</code> scope, see the <a href="scopes-oidc#the-default-scope" data-linktype="relative-path">consent documentation</a>.</td>
</tr>
<tr>
<td><code>client_assertion_type</code></td>
<td>Required</td>
<td>The value must be set to <code>urn:ietf:params:oauth:client-assertion-type:jwt-bearer</code>.</td>
</tr>
<tr>
<td><code>client_assertion</code></td>
<td>Required</td>
<td>An assertion (a JSON web token) that you need to create and sign with the certificate you registered as credentials for your application. Read about <a href="certificate-credentials" data-linktype="relative-path">certificate credentials</a> to learn how to register your certificate and the format of the assertion.</td>
</tr>
<tr>
<td><code>grant_type</code></td>
<td>Required</td>
<td>Must be set to <code>client_credentials</code>.</td>
</tr>
</tbody>
</table></div>
<p>The parameters for the certificate-based request differ in only one way from the shared secret-based request: the <code>client_secret</code> parameter is replaced by the <code>client_assertion_type</code> and <code>client_assertion</code> parameters.</p>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#third-case-access-token-request-with-a-federated-credential" aria-label="Section titled: Third case: Access token request with a federated credential"></a><h3 id="third-case-access-token-request-with-a-federated-credential" class="heading-anchor">Third case: Access token request with a federated credential</h3></div>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-7" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-attribute">POST /{tenant}/oauth2/v2.0/token HTTP/1.1               // Line breaks for clarity
Host</span>: login.microsoftonline.com:443
<span class="hljs-attribute">Content-Type</span>: application/x-www-form-urlencoded

<span class="bicep"><span class="hljs-variable">scope</span>=<span class="hljs-variable">https</span>%<span class="hljs-number">3</span>A%<span class="hljs-number">2</span>F%<span class="hljs-number">2</span>Fgraph.<span class="hljs-variable">microsoft</span>.<span class="hljs-variable">com</span>%<span class="hljs-number">2</span>F.<span class="hljs-variable">default</span>
&amp;<span class="hljs-variable">client_id</span>=<span class="hljs-number">11112222</span>-<span class="hljs-variable">bbbb</span>-<span class="hljs-number">3333</span>-<span class="hljs-variable">cccc</span>-<span class="hljs-number">4444</span>dddd<span class="hljs-number">5555</span>
&amp;<span class="hljs-variable">client_assertion_type</span>=<span class="hljs-variable">urn</span>%<span class="hljs-number">3</span>Aietf%<span class="hljs-number">3</span>Aparams%<span class="hljs-number">3</span>Aoauth%<span class="hljs-number">3</span>Aclient-<span class="hljs-variable">assertion</span>-<span class="hljs-variable">type</span>%<span class="hljs-number">3</span>Ajwt-<span class="hljs-variable">bearer</span>
&amp;<span class="hljs-variable">client_assertion</span>=<span class="hljs-variable">eyJhbGciOiJSUzI1NiIsIng1dCI6Imd4OHRHeXN5amNScUtqRlBuZDdSRnd2d1pJMCJ9</span>.<span class="hljs-variable">eyJ</span>{<span class="hljs-property">a</span> <span class="hljs-property">lot</span> <span class="hljs-property">of</span> <span class="hljs-property">characters</span> <span class="hljs-property">here</span>}<span class="hljs-variable">M8U3bSUKKJDEg</span>
&amp;<span class="hljs-variable">grant_type</span>=<span class="hljs-variable">client_credentials</span>
</span></span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Third case: Access token request with a federated credential" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Condition</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>client_assertion</code></td>
<td>Required</td>
<td>An assertion (a JWT, or JSON web token) that your application gets from another identity provider outside of Microsoft identity platform, like  Kubernetes. The specifics of this JWT must be registered on your application as a <a href="../workload-id/workload-identity-federation-create-trust" data-linktype="relative-path">federated identity credential</a>. Read about <a href="../workload-id/workload-identity-federation" data-linktype="relative-path">workload identity federation</a> to learn how to setup and use assertions generated from other identity providers.</td>
</tr>
</tbody>
</table></div>
<p>Everything in the request is the same as the certificate-based flow, with the crucial exception of the source of the <code>client_assertion</code>. In this flow, your application does not create the JWT assertion itself.  Instead, your app uses a JWT created by another identity provider.  This is called <em><a href="../workload-id/workload-identity-federation" data-linktype="relative-path">workload identity federation</a></em>, where your apps identity in another identity platform is used to acquire tokens inside the Microsoft identity platform.  This is best suited for cross-cloud scenarios, such as hosting your compute outside Azure but accessing APIs protected by Microsoft identity platform.  For information about the required format of JWTs created by other identity providers, read about the <a href="certificate-credentials#assertion-format" data-linktype="relative-path">assertion format</a>.</p>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#successful-response-1" aria-label="Section titled: Successful response"></a><h3 id="successful-response-1" class="heading-anchor">Successful response</h3></div>
<p>A successful response from any method looks like this:</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-8" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->JSON<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="json"><code class="lang-json"><span>{
  <span class="hljs-attr">"token_type"</span>: <span class="hljs-string">"Bearer"</span>,
  <span class="hljs-attr">"expires_in"</span>: <span class="hljs-number">3599</span>,
  <span class="hljs-attr">"access_token"</span>: <span class="hljs-string">"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik1uQ19WWmNBVGZNNXBP..."</span>
}
</span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Successful response" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>access_token</code></td>
<td>The requested access token. The app can use this token to authenticate to the secured resource, such as to a web API.</td>
</tr>
<tr>
<td><code>token_type</code></td>
<td>Indicates the token type value. The only type that the Microsoft identity platform supports is <code>bearer</code>.</td>
</tr>
<tr>
<td><code>expires_in</code></td>
<td>The amount of time that an access token is valid (in seconds).</td>
</tr>
</tbody>
</table></div>
<div class="alert is-warning">
<p class="alert-title"><span class="icon" aria-hidden="true"><span class="docon docon-status-warning-outline"></span></span> Warning</p>
<p>Don't attempt to validate or read tokens for any API you don't own, including the tokens in this example, in your code. Tokens for Microsoft services can use a special format that will not validate as a JWT, and may also be encrypted for consumer (Microsoft account) users. While reading tokens is a useful debugging and learning tool, do not take dependencies on this in your code or assume specifics about tokens that aren't for an API you control.</p>
</div>
<div class="heading-wrapper" data-heading-level="h3"><a class="anchor-link docon docon-link" href="#error-response-1" aria-label="Section titled: Error response"></a><h3 id="error-response-1" class="heading-anchor">Error response</h3></div>
<p>An error response (400 Bad Request) looks like this:</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-9" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->JSON<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="json"><code class="lang-json"><span>{
  <span class="hljs-attr">"error"</span>: <span class="hljs-string">"invalid_scope"</span>,
  <span class="hljs-attr">"error_description"</span>: <span class="hljs-string">"AADSTS70011: The provided value for the input parameter 'scope' is not valid. The scope https://foo.microsoft.com/.default is not valid.\r\nTrace ID: 0000aaaa-11bb-cccc-dd22-eeeeee333333\r\nCorrelation ID: aaaa0000-bb11-2222-33cc-444444dddddd\r\nTimestamp: 2016-01-09 02:02:12Z"</span>,
  <span class="hljs-attr">"error_codes"</span>: [
    <span class="hljs-number">70011</span>
  ],
  <span class="hljs-attr">"timestamp"</span>: <span class="hljs-string">"YYYY-MM-DD HH:MM:SSZ"</span>,
  <span class="hljs-attr">"trace_id"</span>: <span class="hljs-string">"0000aaaa-11bb-cccc-dd22-eeeeee333333"</span>,
  <span class="hljs-attr">"correlation_id"</span>: <span class="hljs-string">"aaaa0000-bb11-2222-33cc-444444dddddd"</span>
}
</span></code></pre>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Error response" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Parameter</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>error</code></td>
<td>An error code string that you can use to classify types of errors that occur, and to react to errors.</td>
</tr>
<tr>
<td><code>error_description</code></td>
<td>A specific error message that might help you identify the root cause of an authentication error.</td>
</tr>
<tr>
<td><code>error_codes</code></td>
<td>A list of STS-specific error codes that might help with diagnostics.</td>
</tr>
<tr>
<td><code>timestamp</code></td>
<td>The time when the error occurred.</td>
</tr>
<tr>
<td><code>trace_id</code></td>
<td>A unique identifier for the request to help with diagnostics.</td>
</tr>
<tr>
<td><code>correlation_id</code></td>
<td>A unique identifier for the request to help with diagnostics across components.</td>
</tr>
</tbody>
</table></div>
<div class="heading-wrapper" data-heading-level="h2"><a class="anchor-link docon docon-link" href="#use-a-token" aria-label="Section titled: Use a token"></a><h2 id="use-a-token" class="heading-anchor">Use a token</h2></div>
<p>Now that you've acquired a token, use the token to make requests to the resource. When the token expires, repeat the request to the <code>/token</code> endpoint to acquire a fresh access token.</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-10" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->HTTP<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" data-language="HTTP"><code class="lang-HTTP"><span><span class="hljs-keyword">GET</span> <span class="hljs-string">/v1.0/users</span> HTTP/1.1
<span class="hljs-attribute">Host</span>: graph.microsoft.com:443
<span class="hljs-attribute">Authorization</span>: Bearer eyJ0eXAiOiJKV1QiLCJhbG...
</span></code></pre>
<p>Try the following command in your terminal, ensuring to replace the token with your own.</p>
<div class="code-block-header margin-top-sm" data-code-block-header="" id="code-try-11" data-bi-name="code-header"><!----><span class="code-block-header-language"><!---->Bash<!----></span><div class="code-block-header-action-bar"><!----><button type="button" class="button display-none-print" data-bi-name="copy" data-code-header-copy-button=""><span class="icon" aria-hidden="true"><span class="docon docon-edit-copy overflow-hidden"></span><span data-copy-button-success-indicator="" class="successful-copy-alert position-absolute is-transparent docon docon-check-mark"></span></span><span><!---->Copy<!----></span></button> <!----></div><!----></div><pre class="inner-focus" role="group" aria-label="Horizontally scrollable code" tabindex="0" data-language="bash"><code class="lang-bash"><span>curl -X GET -H <span class="hljs-string">"Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbG..."</span> <span class="hljs-string">'https://graph.microsoft.com/v1.0/users'</span>
</span></code></pre>
<div class="heading-wrapper" data-heading-level="h2"><a class="anchor-link docon docon-link" href="#code-samples-and-other-documentation" aria-label="Section titled: Code samples and other documentation"></a><h2 id="code-samples-and-other-documentation" class="heading-anchor">Code samples and other documentation</h2></div>
<p>Read the <a href="https://aka.ms/msal-net-client-credentials" data-linktype="external">client credentials overview documentation</a> from the Microsoft Authentication Library</p>
<div class="buttons buttons-right margin-bottom-none margin-top-sm"><!----><button class="button button-clear button-sm display-flex gap-xxs"><span class="icon" aria-hidden="true"><span class="docon docon-expand color-primary"></span></span><span><!---->Expand table<!----></span></button><!----></div><div class="inner-focus"><table aria-label="Code samples and other documentation" class="table table-sm margin-top-none">
<thead>
<tr>
<th>Sample</th>
<th>Platform</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://github.com/Azure-Samples/active-directory-dotnetcore-daemon-v2" data-linktype="external">active-directory-dotnetcore-daemon-v2</a></td>
<td>.NET 6.0+</td>
<td>An ASP.NET Core application that displays the users of a tenant querying the Microsoft Graph using the identity of the application, instead of on behalf of a user. The sample also illustrates the variation using certificates for authentication.</td>
</tr>
<tr>
<td><a href="https://github.com/Azure-Samples/active-directory-dotnet-daemon-v2" data-linktype="external">active-directory-dotnet-daemon-v2</a></td>
<td>ASP.NET MVC</td>
<td>A web application that syncs data from the Microsoft Graph using the identity of the application, instead of on behalf of a user.</td>
</tr>
<tr>
<td><a href="https://github.com/Azure-Samples/ms-identity-javascript-nodejs-console" data-linktype="external">ms-identity-javascript-nodejs-console</a></td>
<td>Node.js Console</td>
<td>A Node.js application that displays the users of a tenant by querying the Microsoft Graph using the identity of the application</td>
</tr>
</tbody>
</table></div>
</div>
					
		<div id="ms--inline-notifications" class="margin-block-xs" data-bi-name="inline-notification"></div>
	 
		<div id="assertive-live-region" role="alert" aria-live="assertive" class="visually-hidden" aria-relevant="additions" aria-atomic="true"><div role="none">Reading mode disabled</div></div>
		<div id="polite-live-region" role="status" aria-live="polite" class="visually-hidden" aria-relevant="additions" aria-atomic="true"></div>
	
					
		<!-- feedback section -->
		<section id="site-user-feedback-footer" class="font-size-sm margin-top-md display-none-print display-none-desktop" data-test-id="site-user-feedback-footer" data-bi-name="site-feedback-section">
			<hr class="hr">
			<h2 id="ms--feedback" class="title is-3">Feedback</h2>
			<div class="display-flex flex-wrap-wrap align-items-center">
				<p class="font-weight-semibold margin-xxs margin-left-none">
					Was this page helpful?
				</p>
				<div class="buttons">
					<button class="thumb-rating-button like button button-primary button-sm" data-test-id="footer-rating-yes" data-binary-rating-response="rating-yes" type="button" title="This article is helpful" data-bi-name="button-rating-yes" aria-pressed="false">
						<span class="icon" aria-hidden="true">
							<span class="docon docon-like"></span>
						</span>
						<span>Yes</span>
					</button>
					<button class="thumb-rating-button dislike button button-primary button-sm" id="standard-rating-no-button" data-test-id="footer-rating-no" data-binary-rating-response="rating-no" type="button" title="This article is not helpful" data-bi-name="button-rating-no" aria-pressed="false">
						<span class="icon" aria-hidden="true">
							<span class="docon docon-dislike"></span>
						</span>
						<span>No</span>
					</button>
					<details class="popover popover-top" id="mobile-help-popover" data-test-id="footer-feedback-popover" hidden="">
						<summary class="thumb-rating-button dislike button button-primary button-sm" data-test-id="details-footer-rating-no" data-binary-rating-response="rating-no" title="This article is not helpful" data-bi-name="button-rating-no" aria-pressed="false" data-bi-an="feedback-unhelpful-popover">
							<span class="icon" aria-hidden="true">
								<span class="docon docon-dislike"></span>
							</span>
							<span>No</span>
						</summary>
						<div class="popover-content width-200 width-300-tablet" role="dialog" aria-labelledby="popover-heading" aria-describedby="popover-description">
							<p id="popover-heading" class="font-size-lg margin-bottom-xxs font-weight-semibold">
								Need help with this topic?
							</p>
							<p id="popover-description" class="font-size-sm margin-bottom-xs">
								Want to try using Ask Learn to clarify or guide you through this topic?
							</p>
							
		<div class="buttons flex-direction-row flex-wrap justify-content-center gap-xxs">
			<div>
		<button class="button button-sm border inner-focus display-none margin-right-xxs" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-test-id="ask-learn-assistant-modal-entry-mobile-feedback" data-ask-learn-modal-entry-feedback="" data-bi-an="feedback-unhelpful-popover" type="button" style="min-width: max-content;" aria-expanded="false" aria-label="Ask Learn" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
		</button>
		<button class="button button-sm display-inline-flex display-none-desktop flex-shrink-0 margin-right-xxs border-color-ask-learn margin-right-xxs" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-bi-an="feedback-unhelpful-popover" data-test-id="ask-learn-assistant-modal-entry-tablet-feedback" data-ask-learn-modal-entry-feedback="" type="button" style="min-width: max-content;" aria-expanded="false" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
		<button class="button button-sm display-none flex-shrink-0 display-inline-flex-desktop margin-right-xxs border-color-ask-learn" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-bi-an="feedback-unhelpful-popover" data-test-id="ask-learn-assistant-flyout-entry-feedback" data-ask-learn-flyout-entry-show-only="" data-flyout-button="toggle" type="button" style="min-width: max-content;" aria-expanded="false" aria-controls="ask-learn-flyout" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
	</div>
			<button type="button" class="button button-sm margin-right-xxs" data-help-option="suggest-fix" data-bi-name="feedback-suggest" data-bi-an="feedback-unhelpful-popover" data-test-id="suggest-fix">
				<span class="icon" aria-hidden="true">
					<span class="docon docon-feedback"></span>
				</span>
				<span> Suggest a fix? </span>
			</button>
		</div>
	
						</div>
					</details>
				</div>
			</div>
		</section>
		<!-- end feedback section -->
	
				</div>
				
		<div id="ms--additional-resources-mobile" class="display-none-print">
			<hr class="hr" hidden="">
			<h2 id="ms--additional-resources-mobile-heading" class="title is-3" hidden="">
				Additional resources
			</h2>
			 
		<section id="right-rail-training-mobile" class="" data-bi-name="learning-resource-card" hidden=""></section>
	 
		<section id="right-rail-events-mobile" class="" data-bi-name="events-card" hidden=""></section>
	
		</div>
	 
		<div id="article-metadata-footer" data-bi-name="article-metadata-footer" data-test-id="article-metadata-footer" class="page-metadata-container">
			<hr class="hr">
			<ul class="metadata page-metadata" data-bi-name="page info" lang="en-us" dir="ltr">
				<li class="visibility-hidden-visual-diff">
			<span class="badge badge-sm text-wrap-pretty">
				<span>Last updated on <local-time format="twoDigitNumeric" datetime="2026-01-30T08:00:00.000Z" data-article-date-source="calculated" class="">01/30/2026</local-time></span>
			</span>
		</li>
			</ul>
		</div>
	
			</div>
			
		<div id="action-panel" role="region" aria-label="Action Panel" class="action-panel" tabindex="-1"></div>
	
		
				</main>
				<aside id="layout-body-aside" class="layout-body-aside  " data-bi-name="aside" aria-label="Additional resources">
					
		<div id="ms--additional-resources" class="right-container padding-sm display-none display-block-desktop height-full" data-bi-name="pageactions">
			<div id="affixed-right-container" data-bi-name="right-column" class="position-sticky" style="top: 8px; max-height: 11444px; height: calc(-124px + 100vh);">
				
		<nav id="side-doc-outline" class="doc-outline border-bottom padding-bottom-xs margin-bottom-xs scrollbar-width-thin" data-bi-name="intopic toc" aria-label="In this article" style="overflow: auto; max-height: calc(100% - 40.5px);"><!----><h2 class="title is-6 margin-top-xxs margin-bottom-xs"><!---->In this article<!----></h2><ol id="right-rail-in-this-article-list" class="padding-right-xxs"><!----><!----><li class="border-left-md border-color-transparent padding-left-xxs "><a href="#protocol-diagram" class="color-text-subtle"><!---->Protocol diagram<!----></a></li><!----><li class="border-left-md border-color-transparent padding-left-xxs "><a href="#get-direct-authorization" class="color-text-subtle"><!---->Get direct authorization<!----></a></li><!----><li class="border-left-md border-color-transparent padding-left-xxs "><a href="#get-a-token" class="color-text-subtle"><!---->Get a token<!----></a></li><!----><li class="border-left-md border-color-transparent padding-left-xxs "><a href="#use-a-token" class="color-text-subtle"><!---->Use a token<!----></a></li><!----><li class="border-left-md border-color-transparent padding-left-xxs "><a href="#code-samples-and-other-documentation" class="color-text-subtle"><!---->Code samples and other documentation<!----></a></li><!----><!----></ol> <!----></nav>
	
				<!-- Feedback -->
				
		<section id="ms--site-user-feedback-right-rail" class="font-size-sm display-none-print" data-test-id="site-user-feedback-right-rail" data-bi-name="site-feedback-right-rail">
			<div class="display-flex flex-wrap-wrap align-items-center">
				<p class="font-weight-semibold margin-xxs margin-left-none">
					Was this page helpful?
				</p>
				<div class="display-flex flex-wrap-nowrap">
					<button class="thumb-rating-button like inner-focus" data-test-id="right-rail-rating-yes" data-binary-rating-response="rating-yes" type="button" title="This article is helpful" aria-label="This article is helpful" data-bi-name="button-rating-yes" aria-pressed="false">
						<span class="icon" aria-hidden="true">
							<span class="docon docon-like"></span>
						</span>
					</button>
					<button class="thumb-rating-button dislike inner-focus" id="right-rail-no-button" data-test-id="right-rail-rating-no" data-binary-rating-response="rating-no" type="button" title="This article is not helpful" aria-label="This article is not helpful" data-bi-name="button-rating-no" aria-pressed="false">
						<span class="icon" aria-hidden="true">
							<span class="docon docon-dislike"></span>
						</span>
					</button>
					<details class="popover popover-right" id="help-popover" data-test-id="feedback-popover" hidden="">
						<summary tabindex="0" class="thumb-rating-button dislike inner-focus" data-test-id="details-right-rail-rating-no" data-binary-rating-response="rating-no" title="This article is not helpful" aria-label="This article is not helpful" data-bi-name="button-rating-no" aria-pressed="false" data-bi-an="feedback-unhelpful-popover">
							<span class="icon" aria-hidden="true">
								<span class="docon docon-dislike"></span>
							</span>
						</summary>
						<div class="popover-content width-200 width-300-tablet" role="dialog" aria-labelledby="popover-heading-right-rail" aria-describedby="popover-description-right-rail">
							<p id="popover-heading-right-rail" class="font-size-lg margin-bottom-xxs font-weight-semibold">
								Need help with this topic?
							</p>
							<p id="popover-description-right-rail" class="font-size-sm margin-bottom-xs">
								Want to try using Ask Learn to clarify or guide you through this topic?
							</p>
							
		<div class="buttons flex-direction-row flex-wrap justify-content-center gap-xxs">
			<div>
		<button class="button button-sm border inner-focus display-none margin-right-xxs" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-test-id="ask-learn-assistant-modal-entry-mobile-feedback" data-ask-learn-modal-entry-feedback="" data-bi-an="feedback-unhelpful-popover" type="button" style="min-width: max-content;" aria-expanded="false" aria-label="Ask Learn" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
		</button>
		<button class="button button-sm display-inline-flex display-none-desktop flex-shrink-0 margin-right-xxs border-color-ask-learn margin-right-xxs" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-bi-an="feedback-unhelpful-popover" data-test-id="ask-learn-assistant-modal-entry-tablet-feedback" data-ask-learn-modal-entry-feedback="" type="button" style="min-width: max-content;" aria-expanded="false" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
		<button class="button button-sm display-none flex-shrink-0 display-inline-flex-desktop margin-right-xxs border-color-ask-learn" data-bi-name="ask-learn-assistant-entry-troubleshoot" data-bi-an="feedback-unhelpful-popover" data-test-id="ask-learn-assistant-flyout-entry-feedback" data-ask-learn-flyout-entry-show-only="" data-flyout-button="toggle" type="button" style="min-width: max-content;" aria-expanded="false" aria-controls="ask-learn-flyout" hidden="">
			<span class="icon font-size-lg" aria-hidden="true">
				<span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span>
			</span>
			<span>Ask Learn</span>
		</button>
	</div>
			<button type="button" class="button button-sm margin-right-xxs" data-help-option="suggest-fix" data-bi-name="feedback-suggest" data-bi-an="feedback-unhelpful-popover" data-test-id="suggest-fix">
				<span class="icon" aria-hidden="true">
					<span class="docon docon-feedback"></span>
				</span>
				<span> Suggest a fix? </span>
			</button>
		</div>
	
						</div>
					</details>
				</div>
			</div>
		</section>
	
			</div>
		</div>
	
			  </aside> <section id="layout-body-flyout" class="layout-body-flyout " data-bi-name="flyout">
					 <div class="height-full border-left background-color-body-medium" id="ask-learn-flyout"><!----><article class="chat-container  position-sticky top-0 " data-chat-container-name="ask-learn-flyout" data-test-id="chat-login-ask-learn-flyout"><div class="chat-container-header"><header class="display-flex justify-content-center align-items-center padding-xs"><h2 class="font-size-md padding-right-xxs"><!----><div class="font-weight-semibold"><span class="icon" aria-hidden="true"><span class="docon docon-chat-sparkle-fill gradient-ask-learn-logo"></span></span><span><!---->Ask Learn<!----></span></div><!----></h2><span class="badge badge-filled badge-sm"><!---->Preview<!----></span><div class="margin-left-auto display-flex flex-wrap-no-wrap align-items-stretch"><!----><button type="button" class="button button-clear inner-focus modal-close" data-flyout-button="close" data-autofocus="" data-bi-an="ask-learn-assistant" data-bi-name="close-chat" aria-label="Close"><span class="icon" aria-hidden="true"><span class="docon docon-navigate-close"></span></span></button><!----></div></header></div><div class="text-align-center padding-top-xl padding-inline-md"><p class="margin-bottom-lg"><!---->Ask Learn is an AI assistant that can answer questions, clarify concepts, and define terms using trusted Microsoft documentation.<!----></p><p class="margin-bottom-lg"><!---->Please sign in to use Ask Learn.<!----></p><a href="#" class="docs-sign-in button button-primary button-filled button-sm"><!---->Sign in<!----></a></div></article><!----></div>
			  </section> <div class="layout-body-footer " data-bi-name="layout-footer">
		<footer id="footer" data-test-id="footer" data-bi-name="footer" class="footer-layout padding-xs padding-sm-desktop has-default-focus border-top" role="contentinfo">
			<div class="display-flex gap-xs flex-wrap-wrap is-full-height padding-right-lg-desktop">
				
		<a data-mscc-ic="false" href="/en-us/locale?target=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fidentity-platform%2Fv2-oauth2-client-creds-grant-flow" data-bi-name="select-locale" class="locale-selector-link flex-shrink-0 button button-sm button-clear external-link-indicator" id="" title="" aria-label="Content language selector. Currently set to English (United States)."><span class="icon" aria-hidden="true"><span class="docon docon-world"></span></span><span class="local-selector-link-text">English (United States)</span></a>
	 <div class="ccpa-privacy-link" data-ccpa-privacy-link="">
		
		<a data-mscc-ic="false" href="https://aka.ms/yourcaliforniaprivacychoices" data-bi-name="your-privacy-choices" class="button button-sm button-clear flex-shrink-0 external-link-indicator" id="" title="">
		<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 30 14" xml:space="preserve" height="16" width="43" aria-hidden="true" focusable="false">
			<path d="M7.4 12.8h6.8l3.1-11.6H7.4C4.2 1.2 1.6 3.8 1.6 7s2.6 5.8 5.8 5.8z" style="fill-rule:evenodd;clip-rule:evenodd;fill:#fff"></path>
			<path d="M22.6 0H7.4c-3.9 0-7 3.1-7 7s3.1 7 7 7h15.2c3.9 0 7-3.1 7-7s-3.2-7-7-7zm-21 7c0-3.2 2.6-5.8 5.8-5.8h9.9l-3.1 11.6H7.4c-3.2 0-5.8-2.6-5.8-5.8z" style="fill-rule:evenodd;clip-rule:evenodd;fill:#06f"></path>
			<path d="M24.6 4c.2.2.2.6 0 .8L22.5 7l2.2 2.2c.2.2.2.6 0 .8-.2.2-.6.2-.8 0l-2.2-2.2-2.2 2.2c-.2.2-.6.2-.8 0-.2-.2-.2-.6 0-.8L20.8 7l-2.2-2.2c-.2-.2-.2-.6 0-.8.2-.2.6-.2.8 0l2.2 2.2L23.8 4c.2-.2.6-.2.8 0z" style="fill:#fff"></path>
			<path d="M12.7 4.1c.2.2.3.6.1.8L8.6 9.8c-.1.1-.2.2-.3.2-.2.1-.5.1-.7-.1L5.4 7.7c-.2-.2-.2-.6 0-.8.2-.2.6-.2.8 0L8 8.6l3.8-4.5c.2-.2.6-.2.9 0z" style="fill:#06f"></path>
		</svg>
	
			<span>Your Privacy Choices</span></a>
	
	</div>
				<div class="flex-shrink-0">
		<div class="dropdown has-caret-up">
			<button data-test-id="theme-selector-button" class="dropdown-trigger button button-clear button-sm inner-focus theme-dropdown-trigger" aria-controls="{{ themeMenuId }}" aria-haspopup="true" aria-expanded="false" data-bi-name="theme">
				<span class="icon" aria-hidden="true"><span class="docon docon-sun"></span></span>
				<span>Theme</span>
				<span class="icon expanded-indicator" aria-hidden="true">
					<span class="docon docon-chevron-down-light"></span>
				</span>
			</button>
			<div class="dropdown-menu" id="{{ themeMenuId }}" role="menu">
				<ul class="theme-selector padding-xxs" data-test-id="theme-dropdown-menu" role="none">
					<li class="theme display-block" role="none">
						<button class="button button-clear button-sm theme-control button-block justify-content-flex-start text-align-left is-selected" role="menuitemradio" aria-checked="true" data-theme-to="light" tabindex="-1">
							<span class="theme-light margin-right-xxs">
								<span class="theme-selector-icon border display-inline-block has-body-background" aria-hidden="true">
									<svg class="svg" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 22 14">
										<rect width="22" height="14" class="has-fill-body-background"></rect>
										<rect x="5" y="5" width="12" height="4" class="has-fill-secondary"></rect>
										<rect x="5" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="8" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="11" y="2" width="3" height="1" class="has-fill-secondary"></rect>
										<rect x="1" y="1" width="2" height="2" class="has-fill-secondary"></rect>
										<rect x="5" y="10" width="7" height="2" rx="0.3" class="has-fill-primary"></rect>
										<rect x="19" y="1" width="2" height="2" rx="1" class="has-fill-secondary"></rect>
									</svg>
								</span>
							</span>
							<span> Light </span>
						</button>
					</li>
					<li class="theme display-block" role="none">
						<button class="button button-clear button-sm theme-control button-block justify-content-flex-start text-align-left" role="menuitemradio" aria-checked="false" data-theme-to="dark" tabindex="-1">
							<span class="theme-dark margin-right-xxs">
								<span class="border theme-selector-icon display-inline-block has-body-background" aria-hidden="true">
									<svg class="svg" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 22 14">
										<rect width="22" height="14" class="has-fill-body-background"></rect>
										<rect x="5" y="5" width="12" height="4" class="has-fill-secondary"></rect>
										<rect x="5" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="8" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="11" y="2" width="3" height="1" class="has-fill-secondary"></rect>
										<rect x="1" y="1" width="2" height="2" class="has-fill-secondary"></rect>
										<rect x="5" y="10" width="7" height="2" rx="0.3" class="has-fill-primary"></rect>
										<rect x="19" y="1" width="2" height="2" rx="1" class="has-fill-secondary"></rect>
									</svg>
								</span>
							</span>
							<span> Dark </span>
						</button>
					</li>
					<li class="theme display-block" role="none">
						<button class="button button-clear button-sm theme-control button-block justify-content-flex-start text-align-left" role="menuitemradio" aria-checked="false" data-theme-to="high-contrast" tabindex="-1">
							<span class="theme-high-contrast margin-right-xxs">
								<span class="border theme-selector-icon display-inline-block has-body-background" aria-hidden="true">
									<svg class="svg" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 22 14">
										<rect width="22" height="14" class="has-fill-body-background"></rect>
										<rect x="5" y="5" width="12" height="4" class="has-fill-secondary"></rect>
										<rect x="5" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="8" y="2" width="2" height="1" class="has-fill-secondary"></rect>
										<rect x="11" y="2" width="3" height="1" class="has-fill-secondary"></rect>
										<rect x="1" y="1" width="2" height="2" class="has-fill-secondary"></rect>
										<rect x="5" y="10" width="7" height="2" rx="0.3" class="has-fill-primary"></rect>
										<rect x="19" y="1" width="2" height="2" rx="1" class="has-fill-secondary"></rect>
									</svg>
								</span>
							</span>
							<span> High contrast </span>
						</button>
					</li>
				</ul>
			</div>
		</div>
	</div>
			</div>
			<ul class="links" data-bi-name="footerlinks">
				<li class="manage-cookies-holder" hidden=""></li>
				<li>
		
		<a data-mscc-ic="false" href="https://learn.microsoft.com/en-us/principles-for-ai-generated-content" data-bi-name="aiDisclaimer" class=" external-link-indicator" id="" title="">AI Disclaimer</a>
	
	</li><li>
		
		<a data-mscc-ic="false" href="https://learn.microsoft.com/en-us/previous-versions/" data-bi-name="archivelink" class=" external-link-indicator" id="" title="">Previous Versions</a>
	
	</li> <li>
		
		<a data-mscc-ic="false" href="https://techcommunity.microsoft.com/t5/microsoft-learn-blog/bg-p/MicrosoftLearnBlog" data-bi-name="bloglink" class=" external-link-indicator" id="" title="">Blog</a>
	
	</li> <li>
		
		<a data-mscc-ic="false" href="https://learn.microsoft.com/en-us/contribute" data-bi-name="contributorGuide" class=" external-link-indicator" id="" title="">Contribute</a>
	
	</li><li>
		
		<a data-mscc-ic="false" href="https://go.microsoft.com/fwlink/?LinkId=521839" data-bi-name="privacy" class=" external-link-indicator" id="" title="">Privacy</a>
	
	</li><li>
		
		<a data-mscc-ic="false" href="https://go.microsoft.com/fwlink/?linkid=2259814" data-bi-name="consumer-health-privacy" class=" external-link-indicator" id="" title="">Consumer Health Privacy</a>
	
	</li><li>
		
		<a data-mscc-ic="false" href="https://learn.microsoft.com/en-us/legal/termsofuse" data-bi-name="termsofuse" class=" external-link-indicator" id="" title="">Terms of Use</a>
	
	</li><li>
		
		<a data-mscc-ic="false" href="https://www.microsoft.com/legal/intellectualproperty/Trademarks/" data-bi-name="trademarks" class=" external-link-indicator" id="" title="">Trademarks</a>
	
	</li>
				<li>© Microsoft 2026</li>
			</ul>
		</footer>
	
			
		</div></body></html>