[metadata]
asset_id: identity-platform/app-objects-and-service-principals
author: cilwerner
breadcrumb_path: /entra/breadcrumb/toc.json
cmProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/5fc61396-d075-4560-aece-fdbda73d243f
cmProducts: https://microsoft-devrel.poolparty.biz/DevRelOfferingOntology/1433a524-c01f-4b87-beab-670c040dea4f
cmProducts: https://microsoft-devrel.poolparty.biz/DevRelOfferingOntology/57eae307-c3a1-4cac-b645-1a899934bac8
color-scheme: light dark
depot_name: MSDN.entra-docs
description: Learn about the relationship between application and service principal objects in Microsoft Entra ID.
document_id: 6c12e139-8cb6-dd6d-2e08-89d4f22c7eef
document_version_independent_id: 675b5ee9-bfe6-344f-7b39-ca0e2bc18b9b
feedback_product_url: /entra/identity-platform/developer-support-help-options
feedback_system: Standard
git_commit_id: a4be4ac419c4e857b1c4de7dee22c9f7e0c750f9
gitcommit: https://github.com/MicrosoftDocs/entra-docs-pr/blob/a4be4ac419c4e857b1c4de7dee22c9f7e0c750f9/docs/identity-platform/app-objects-and-service-principals.md
github_feedback_content_git_url: https://github.com/MicrosoftDocs/entra-docs/blob/main/docs/identity-platform/app-objects-and-service-principals.md
item_type: Content
locale: en-us
manager: pmwongera
markdown_url: https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals?accept=text/markdown
ms.author: cwerner
ms.custom: has-azure-ad-ps-ref, sfi-image-nochange
ms.date: 2024-10-01T00:00:00Z
ms.reviewer: sureshja
ms.service: identity-platform
ms.topic: concept-article
og:description: Learn about the relationship between application and service principal objects in Microsoft Entra ID.
og:image: https://learn.microsoft.com/en-us/media/open-graph-image.png
og:image:alt: Microsoft Learn
og:title: Apps & service principals in Microsoft Entra ID - Microsoft identity platform
og:type: website
og:url: https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals
original_content_git_url: https://github.com/MicrosoftDocs/entra-docs-pr/blob/live/docs/identity-platform/app-objects-and-service-principals.md
page_type: conceptual
platform_id: e040fdd9-7e32-61c8-e479-2a87fb23d591
previous_tlsh_hash: 07024B02DD0E4A15FA932D0B66AAA74076E1D1C27DB0D51820166A53A09A0D77CF748C97F3D7ABC6D7B243F762EFA80D81C1F77F042C16F72D98D6B8C4AC115366D87631CA
schema: Conceptual
scope: Microsoft Entra
site_name: Docs
source_path: docs/identity-platform/app-objects-and-service-principals.md
spProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/ad9437c1-8cda-4537-ad69-b4b263652e13
spProducts: https://microsoft-devrel.poolparty.biz/DevRelOfferingOntology/312f1f05-a431-4193-8a4d-e6245d5966de
spProducts: https://microsoft-devrel.poolparty.biz/DevRelOfferingOntology/ee561821-1ac7-45a8-9409-6ba5eb7a5b97
toc_rel: toc.json
twitter:card: summary_large_image
twitter:site: @MicrosoftLearn
uhfHeaderId: MSDocsHeader-Entra
updated_at: 2026-06-15T17:40:00Z
viewport: width=device-width, initial-scale=1.0
word_count: 1415

[canonical-links]
https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals

[document-links]
AI Disclaimer: https://learn.microsoft.com/en-us/principles-for-ai-generated-content
Admin center: https://entra.microsoft.com/
Agent ID: /en-us/entra/agent-id/
Agents: /en-us/agents/
All product documentation: /en-us/docs/
All questions: /en-us/answers/questions/
All training: /en-us/training/
Analytics: https://learn.microsoft.com/en-us/users/me/analytics/
Application entity: /en-us/graph/api/resources/application
Application model: https://learn.microsoft.com/en-us/entra/identity-platform/application-model
Applications and service principals: https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals
Artificial intelligence: /en-us/ai/
Ask a question: /en-us/answers/questions/ask/
Assessments: /en-us/assessments/
Azure documentation: /en-us/azure/?product=popular
Azure questions: /en-us/answers/tags/133/azure/
Azure training: /en-us/training/browse/?products=azure
Blog: https://techcommunity.microsoft.com/t5/microsoft-learn-blog/bg-p/MicrosoftLearnBlog
Career paths: /en-us/training/career-paths/
Code samples: /en-us/samples/
Consumer Health Privacy: https://go.microsoft.com/fwlink/?linkid=2259814
Contribute: https://learn.microsoft.com/en-us/contribute
Credentials: /en-us/credentials/
DevOps: /en-us/devops/
Download Microsoft Edge: https://go.microsoft.com/fwlink/p/?LinkID=2092881
Dynamics 365 documentation: /en-us/dynamics365/
Dynamics 365 training: /en-us/training/browse/?products=dynamics-365
Edit: https://github.com/MicrosoftDocs/entra-docs/blob/main/docs/identity-platform/app-objects-and-service-principals.md
Educator center: /en-us/training/educator-center/
English (United States): /en-us/locale?target=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fidentity-platform%2Fapp-objects-and-service-principals%3Ftabs%3Dbrowser
External ID: /en-us/entra/external-id/
Global Secure Access: /en-us/entra/global-secure-access/
How and why apps are added: https://learn.microsoft.com/en-us/entra/identity-platform/how-applications-are-added
ID Governance: /en-us/entra/id-governance/
Identity platform best practices: https://learn.microsoft.com/en-us/entra/identity-platform/identity-platform-integration-checklist
Labs: /en-us/labs/
Learn for Organizations: /en-us/training/organizations/
Learn: /en-us/
Learn: https://learn.microsoft.com/en-us/
Microsoft 365 documentation: /en-us/microsoft-365/
Microsoft 365 questions: /en-us/answers/tags/9/m365/
Microsoft 365 training: /en-us/training/browse/?products=m365
Microsoft Copilot documentation: /en-us/copilot/
Microsoft Copilot training: /en-us/training/browse/?products=ms-copilot
Microsoft Entra ID: /en-us/entra/identity/
Microsoft Entra admin center: https://entra.microsoft.com
Microsoft Entra: /en-us/entra
Microsoft Entra: https://learn.microsoft.com/en-us/entra/
Microsoft Graph Explorer: https://developer.microsoft.com/graph/graph-explorer
Microsoft Ignite | November 17-20, 2026: https://ignite.microsoft.com/home?wt.mc_ID=msignite26_gmee_corp_np_oo_MSLearnRegLaunch
Microsoft Outlook questions: /en-us/answers/tags/131/office-outlook/
Microsoft Power Platform training: /en-us/training/browse/?products=power-platform
Microsoft Security documentation: /en-us/security/
Microsoft Teams questions: /en-us/answers/tags/108/office-teams/
Microsoft identity platform: https://learn.microsoft.com/en-us/entra/identity-platform/
More info about Internet Explorer and Microsoft Edge: https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge
Popular tags: /en-us/answers/tags/
Power Platform documentation: /en-us/power-platform/
Previous Versions: https://learn.microsoft.com/en-us/previous-versions/
Privacy: https://go.microsoft.com/fwlink/?LinkId=521839
Profile: https://learn.microsoft.com/en-us/users/me/activity/
Read in English: https://learn.microsoft.com/en-us/entra/identity-platform/app-objects-and-service-principals?tabs=browser
Samples: https://learn.microsoft.com/en-us/entra/identity-platform/sample-v2-code
Security: /en-us/security/
ServicePrincipal entity: /en-us/graph/api/resources/serviceprincipal
Settings: https://learn.microsoft.com/en-us/users/me/settings/
Single-tenant and multitenant apps: https://learn.microsoft.com/en-us/entra/identity-platform/single-and-multi-tenant-apps
Startups hub: /en-us/startups/
Student hub: /en-us/training/student-hub/
Suggestions will filter as you type: /en-us/search/
Terms of Use: https://learn.microsoft.com/en-us/legal/termsofuse
Trademarks: https://www.microsoft.com/legal/intellectualproperty/Trademarks/
Troubleshooting documentation: /en-us/troubleshoot/
Troubleshooting: /en-us/troubleshoot/entra/welcome-entra
Using Azure CLI: /en-us/cli/azure/azure-cli-sp-tutorial-1
Using Azure PowerShell: howto-authenticate-service-principal-powershell
Using Microsoft Graph: /en-us/graph/api/serviceprincipal-post-serviceprincipals
Using the Microsoft Entra admin center: howto-create-service-principal-portal
What is the Microsoft identity platform?: https://learn.microsoft.com/en-us/entra/identity-platform/v2-overview
What's new in docs?: https://learn.microsoft.com/en-us/entra/identity-platform/whats-new-docs
Windows questions: /en-us/answers/tags/60/windows/
Workload identities: https://learn.microsoft.com/en-us/entra/workload-id/workload-identities-overview
Your Privacy Choices: https://aka.ms/yourcaliforniaprivacychoices
app registration quickstart: quickstart-register-app
deactivate the application: ../identity/enterprise-apps/deactivate-application-portal
delete and recover applications and service principal objects: ../identity/enterprise-apps/delete-recover-faq
https://www.microsoft.com
managed identity: ../identity/managed-identities-azure-resources/overview
multitenant: single-and-multi-tenant-apps#who-can-sign-in-to-your-app
redirect URI: reply-url
single tenant: single-and-multi-tenant-apps#who-can-sign-in-to-your-app

[structured-data]
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","item":"https://learn.microsoft.com/en-us/","name":"Learn","position":1},{"@type":"ListItem","item":"https://learn.microsoft.com/en-us/entra/","name":"Microsoft Entra","position":2},{"@type":"ListItem","item":"https://learn.microsoft.com/en-us/entra/identity-platform/","name":"Microsoft identity platform","position":3}]}

[content]
Apps & service principals in Microsoft Entra ID - Microsoft identity platform | Microsoft Learn
Skip to main content
Skip to Ask Learn chat experience
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Download Microsoft Edge
More info about Internet Explorer and Microsoft Edge
Learn
Suggestions will filter as you type
Sign in
Profile
Analytics
Settings
Sign out
Learn
Documentation
All product documentation
Azure documentation
Dynamics 365 documentation
Microsoft Copilot documentation
Microsoft 365 documentation
Power Platform documentation
Code samples
Troubleshooting documentation
Register now
Microsoft Ignite | November 17-20, 2026
Interactive learning, certifications, and direct access to experts all in one place.
Training & Labs
All training
Azure training
Dynamics 365 training
Microsoft Copilot training
Microsoft 365 training
Microsoft Power Platform training
Labs
Credentials
Career paths
Register now
Microsoft Ignite | November 17-20, 2026
Interactive learning, certifications, and direct access to experts all in one place.
Q&A
Ask a question
Azure questions
Windows questions
Microsoft 365 questions
Microsoft Outlook questions
Microsoft Teams questions
Popular tags
All questions
Register now
Microsoft Ignite | November 17-20, 2026
Interactive learning, certifications, and direct access to experts all in one place.
Topics
Agents
Key concepts and resources for agentic computing
Artificial intelligence
Curated resources for AI fluency with apps and services
DevOps
DevOps practices, Git version control and Agile methods
Learn for Organizations
Curated offerings from Microsoft to boost your team’s technical skills
Security
Guidance to help you tackle security challenges
Startups hub
Technical guidance to move toward enterprise readiness
Assessments
Interactive guidance with custom recommendations
Student hub
Self-paced and interactive training for students
Educator center
Resources for educators to bring technical innovation in their classroom
Register now
Microsoft Ignite | November 17-20, 2026
Interactive learning, certifications, and direct access to experts all in one place.
Suggestions will filter as you type
Sign in
Profile
Analytics
Settings
Sign out
Microsoft Entra
Microsoft Entra ID
Agent ID
External ID
Global Secure Access
ID Governance
Microsoft Security documentation
Troubleshooting
More
Microsoft Entra ID
Agent ID
External ID
Global Secure Access
ID Governance
Microsoft Security documentation
Troubleshooting
Admin center
Search
Suggestions will filter as you type
Microsoft identity platform
Overview
What is the Microsoft identity platform?
What's new in docs?
Samples
Concepts
Basics of the identity platform
Permissions and access
App registrations and workload identities
Application model
Workload identities
Applications and service principals
How and why apps are added
Single-tenant and multitenant apps
Customization and extensibility
Security
Identity platform best practices
Single-page app (SPA)
Web app
Web API
Desktop
Mobile
Service, daemon, script
Command-line interface (CLI) app
How-to
Reference
Resources
Download PDF
Table of contents
Exit editor mode
Learn
Microsoft Entra
Microsoft identity platform
Learn
Microsoft Entra
Microsoft identity platform
Ask Learn
Ask Learn
Reading mode
Table of contents
Read in English
Add to Collections
Add to Plans
Edit
Copy Markdown
Print
Note
Access to this page requires authorization. You can try
signing in
or
changing directories
.
Access to this page requires authorization. You can try
changing directories
.
Application and service principal objects in Microsoft Entra ID
Feedback
Summarize this article for me
In this article
Application registration
Application object
Service principal object
Relationship between application objects and service principals
Example
Next steps
Show 2 more
This article describes application registration, application objects, and service principals in Microsoft Entra ID, what they are, how they're used, and how they're related to each other. A multitenant example scenario is also presented to illustrate the relationship between an application's application object and corresponding service principal objects.
Application registration
To delegate identity and access management functions to Microsoft Entra ID, an application must be registered with a Microsoft Entra tenant. When you register your application with Microsoft Entra ID, you're creating an identity configuration for your application that allows it to integrate with Microsoft Entra ID. When you register an app, you choose whether it's a
single tenant
, or
multitenant
, and can optionally set a
redirect URI
. For step-by-step instructions on registering an app, see the
app registration quickstart
.
When you've completed the app registration, you have a globally unique instance of the app (the application object) that lives within your home tenant or directory. You also have a globally unique ID for your app (the app/client ID). You can add secrets or certificates and scopes to make your app work, customize the branding of your app in the sign-in dialog, and more.
If you register an application, an application object and a service principal object are automatically created in your home tenant. If you register/create an application using the Microsoft Graph APIs, creating the service principal object is a separate step.
Application object
A Microsoft Entra application is defined by its one and only application object, which resides in the Microsoft Entra tenant where the application was registered (known as the application's "home" tenant). An application object is used as a template or blueprint to create one or more service principal objects. A service principal is created in every tenant where the application is used. Similar to a class in object-oriented programming, the application object has some static properties that are applied to all the created service principals (or application instances).
The application object describes three aspects of an application:
How the service can issue tokens in order to access the application
The resources that the application might need to access
The actions that the application can take
You can use the
App registrations
page in the
Microsoft Entra admin center
to list and manage the application objects in your home tenant.
The Microsoft Graph
Application entity
defines the schema for an application object's properties.
Service principal object
To access resources that are secured by a Microsoft Entra tenant, the entity that requires access must be represented by a security principal. This requirement is true for both users (user principal) and applications (service principal). The security principal defines the access policy and permissions for the user/application in the Microsoft Entra tenant. This enables core features such as authentication of the user/application during sign-in, and authorization during resource access.
There are three types of service principal:
Application
- This type of service principal is the local representation, or application instance, of a global application object in a single tenant or directory. In this case, a service principal is a concrete instance created from the application object and inherits certain properties from that application object. A service principal is created in each tenant where the application is used and references the globally unique app object. The service principal object defines what the app can actually do in the specific tenant, who can access the app, and what resources the app can access.
When an application is given permission to access resources in a tenant (upon registration or consent), a service principal object is created. When you register an application, a service principal is created automatically. You can also create service principal objects in a tenant using Azure PowerShell, Azure CLI, Microsoft Graph, and other tools.
Managed identity
- This type of service principal is used to represent a
managed identity
. Managed identities eliminate the need for developers to manage credentials. Managed identities provide an identity for applications to use when connecting to resources that support Microsoft Entra authentication. When a managed identity is enabled, a service principal representing that managed identity is created in your tenant. Service principals representing managed identities can be granted access and permissions, but can't be updated or modified directly. A service principal representing a managed identity doesn't have an associated app object (unlike the Application type above).
Legacy
- This type of service principal represents a legacy app, which is an app created before app registrations were introduced or an app created through legacy experiences. A legacy service principal can have credentials, service principal names, reply URLs, and other properties that an authorized user can edit, but doesn't have an associated app registration. The service principal can only be used in the tenant where it was created.
The Microsoft Graph
ServicePrincipal entity
defines the schema for a service principal object's properties.
You can use the
Enterprise applications
page in the Microsoft Entra admin center to list and manage the service principals in a tenant. You can see the service principal's permissions, user consented permissions, which users have done that consent, sign in information, and more.
Relationship between application objects and service principals
The application object is the
global
representation of your application for use across all tenants, and the service principal is the
local
representation for use in a specific tenant. The application object serves as the template from which common and default properties are
derived
for use in creating corresponding service principal objects.
An application object has:
A one-to-one relationship with the software application, and
A one-to-many relationship with its corresponding service principal objects
A service principal must be created in each tenant where the application is used, enabling it to establish an identity for sign-in and/or access to resources being secured by the tenant. A single-tenant application has only one service principal (in its home tenant), created and consented for use during application registration. A multitenant application also has a service principal created in each tenant where a user from that tenant has consented to its use.
List service principals associated with an app
You can find the service principals associated with an application object.
Browser
PowerShell
Azure CLI
In the Microsoft Entra admin center, navigate to the application registration overview. Select
Managed application in local directory
.
Using Microsoft Graph PowerShell:
Azure PowerShell
Copy
Get-MgServicePrincipal
-Filter
"appId eq '{AppId}'"
Using Azure CLI:
Azure CLI
Copy
az ad sp list
--filter
"appId eq '{AppId}'"
Consequences of modifying and deleting applications
Any changes that you make to your application object are also reflected in its service principal object in the application's home tenant only (the tenant where it was registered). This means that deleting an application object will also delete its home tenant service principal object. However, restoring that application object through the app registrations UI won't restore its corresponding service principal.
For applications that need temporary suspension rather than permanent deletion, you can
deactivate the application
. Deactivation prevents new token issuance while preserving the application object and service principal for investigation or future reactivation.
For more information on deletion and recovery of applications and their service principal objects, see
delete and recover applications and service principal objects
.
Example
The following diagram illustrates the relationship between an application's application object and corresponding service principal objects in the context of a sample multitenant application called
HR app
. There are three Microsoft Entra tenants in this example scenario:
Adatum
- The tenant used by the company that developed the
HR app
Contoso
- The tenant used by the Contoso organization, which is a consumer of the
HR app
Fabrikam
- The tenant used by the Fabrikam organization, which also consumes the
HR app
In this example scenario:
Expand table
Step
Description
1
The process of creating the application and service principal objects in the application's home tenant.
2
When Contoso and Fabrikam administrators complete consent, a service principal object is created in their company's Microsoft Entra tenant and assigned the permissions that the administrator granted. Also note that the HR app could be configured/designed to allow consent by users for individual use.
3
The consumer tenants of the HR application (Contoso and Fabrikam) each have their own service principal object. Each represents their use of an instance of the application at runtime, governed by the permissions consented by the respective administrator.
Next steps
Learn how to create a service principal:
Using the Microsoft Entra admin center
Using Azure PowerShell
Using Azure CLI
Using Microsoft Graph
and then use
Microsoft Graph Explorer
to query both the application and service principal objects.
Reading mode disabled
Feedback
Was this page helpful?
Yes
No
No
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Ask Learn
Ask Learn
Suggest a fix?
Additional resources
Last updated on
10/01/2024
In this article
Application registration
Application object
Service principal object
Relationship between application objects and service principals
Example
Next steps
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Ask Learn
Ask Learn
Suggest a fix?
Ask Learn
Preview
Ask Learn is an AI assistant that can answer questions, clarify concepts, and define terms using trusted Microsoft documentation.
Please sign in to use Ask Learn.
Sign in
English (United States)
Your Privacy Choices
Theme
Light
Dark
High contrast
AI Disclaimer
Previous Versions
Blog
Contribute
Privacy
Consumer Health Privacy
Terms of Use
Trademarks
© Microsoft 2026
