Least privilege to create Service Principal from a multi-tenant app in another Azure AD tenant

แชร์
ฝัง
  • เผยแพร่เมื่อ 15 พ.ย. 2024

ความคิดเห็น • 3

  • @phaneendhraajaythota1025
    @phaneendhraajaythota1025 ปีที่แล้ว

    Hello @Arsen, one Question here, when we create a multi tenant application and let user sign in to our website , We can request for permissions listed in our application with '/.default' scope that will automatically reflects granted permissions in the client's Enterprise Applications.
    but the service principal requires to be in specific role like let's say 'Application Administrator' ..
    I could only think of one way and that is to seek permission such as 'Directory.AccessAsUser' and make all necessary changes the clients tenant after successful consent.
    would you suggest any alternative?

  • @meirarasual7921
    @meirarasual7921 2 ปีที่แล้ว

    p̾r̾o̾m̾o̾s̾m̾ 🤔

    • @ArsenVlad
      @ArsenVlad  2 ปีที่แล้ว

      Hi Meira! Can you please clarify the question? :)