certslothcertsloth
SC-300/Topic 05

Microsoft / Associate

Application Registrations, Consent and Workload Identities

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Registration defines the app; service principal represents it in a tenant.

Must remember

An app registration defines an application’s identity/configuration; a service principal is its tenant-local representation, commonly managed under enterprise applications. A multitenant app can have service principals in several tenants. Configure redirect URIs, supported accounts, credentials and API permissions deliberately.

Delegated permissions act with a signed-in user under applicable limits; application permissions support app-only access. Consent authorizes requested permissions under tenant policy; admin consent may be required for sensitive scopes. App roles and user/group assignment govern supported application access and should not be confused with directory administrator roles.

Managed identities give supported Azure workloads service identities without application-managed secrets. System-assigned lifecycle follows its resource; user-assigned identities have an independent reusable lifecycle. Use the correct identity and grant downstream access explicitly. A managed identity’s existence does not automatically authorize reading Key Vault or storage.

Enterprise-app integration includes SaaS SSO, provisioning and supported on-premises publishing through Application Proxy connectors. Authentication and provisioning are different: successful SSO does not automatically create all required application entitlements. Collections help organize user-facing applications; lifecycle and assignment remain governed.

Defender for Cloud Apps discovers cloud usage, integrates connected apps and supports access/session/OAuth-app policies. Conditional Access app control can enforce supported session restrictions through its proxy path. Investigate excessive consent, unused credentials and suspicious app behavior; revoke/rotate the actual affected service credentials or grants rather than a random user password.

Choose under exam pressure

Requirement Choice and reason
Azure workload calls a supported service Managed identity plus least-privilege target permissions.
Daemon acts without a user Application permissions with appropriate consent.
Publish supported on-premises web app Application Proxy with connectors and access policy.

Traps

  • App registration and enterprise application are related but different objects.
  • SSO and user provisioning are not the same function.

Active recall

1. What is a service principal?

The application/workload’s identity representation in a tenant.

2. Delegated versus application permissions?

Access with a user versus app-only access.

3. System-assigned versus user-assigned identity?

Resource-coupled lifecycle versus independently managed reusable identity.

4. Why review consent?

An app may retain broad access through granted permissions.

5. Why might a managed identity get Forbidden?

Its target permissions, scope, identity selection or resource policy may be wrong.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.