Reference

App Role Assignment

All app role assignments in Entra ID

Part of the Entra ID inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
MonthlyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
App Role App Role The identifier (id) for the app role which is assigned to the principal. {{AppRoleAssignment.AppRole}}
Id String A unique identifier for the appRoleAssignment key. {{AppRoleAssignment.AppRoleAssignmentId}}
App Role Id String The identifier (id) for the app role which is assigned to the principal. {{AppRoleAssignment.AppRoleId}}
App Role Name String Display name for the permission that appears in the app role assignment and consent experiences. {{AppRoleAssignment.AppRoleName}}
Creation Date DateTime The time when the app role assignment was created. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. {{AppRoleAssignment.CreatedDateTime}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{AppRoleAssignment.CreatedTime}}
Display Name String {{AppRoleAssignment.DisplayName}}
Group Principal Group The unique identifier (id) for the group being granted the app role. {{AppRoleAssignment.GroupPrincipal}}
Group Principal Name String The display name of the group that was granted the app role assignment. {{AppRoleAssignment.GroupPrincipalName}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{AppRoleAssignment.LastModifiedTime}}
Principal Display Name String The display name of the user, group, or service principal that was granted the app role assignment. {{AppRoleAssignment.PrincipalDisplayName}}
Principal Type String The type of the assigned principal. This can either be User, Group, or ServicePrincipal. {{AppRoleAssignment.PrincipalType}}
Resource String The unique identifier (id) for the resource service principal for which the assignment is made. {{AppRoleAssignment.Resource}}
Resource Display Name String The display name of the resource app's service principal to which the assignment is made. {{AppRoleAssignment.ResourceDisplayName}}
Resource Name String The display name of the resource app's service principal to which the assignment is made. {{AppRoleAssignment.ResourceName}}
Risk Score Int32 Stores risk score {{AppRoleAssignment.RiskScore}}
Risk Score Update DateTime Stores risk score update {{AppRoleAssignment.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{AppRoleAssignment.RiskScoreValue}}
Service Principal String The unique identifier (id) for the service principal being granted the app role. {{AppRoleAssignment.ServicePrincipal}}
Service Principal Name String The display name of the service principal that was granted the app role assignment. {{AppRoleAssignment.ServicePrincipalName}}
User Principal String App role assignments of the user {{AppRoleAssignment.UserPrincipal}}
User Principal Name String The name displayed in the address book for the user. This is usually the combination of the user's first name, middle initial and last name. {{AppRoleAssignment.UserPrincipalName}}

Relations

Relation Service Description
App Role Entra ID All app roles in Entra ID
Enterprise Application Entra ID
Enterprise Application Entra ID
Group Microsoft 365 All Entra ID groups in your Tenant (Security groups, Microsoft 365 groups)
User Microsoft 365

Segments

This object does currently not have any segments.

Actions

This object does currently not have any actions.

Last updated: 7/19/2026