Reference
Enterprise Application
All registered Enterprise Applications in Entra ID
Part of the Entra ID inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Monthly | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Account Enabled | Boolean | true if the service principal account is enabled; otherwise, false. | {{EnterpriseApplication.AccountEnabled}} |
| App Description | String | The description exposed by the associated application. | {{EnterpriseApplication.AppDescription}} |
| App Display Name | String | The display name exposed by the associated application. | {{EnterpriseApplication.AppDisplayName}} |
| App Id | String | The unique identifier for the associated application (its appId property). | {{EnterpriseApplication.AppId}} |
| App Owner Organization Id | String | Contains the tenant id where the application is registered. This is applicable only to service principals backed by applications. | {{EnterpriseApplication.AppOwnerOrganizationId}} |
| App Role Assignment Required | String | Specifies whether users or other service principals need to be granted an app role assignment for this service principal before users can sign in or apps can get tokens. | {{EnterpriseApplication.AppRoleAssignmentRequired}} |
| Creation Date | DateTime | The date and time the application was registered. The DateTimeOffset type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z. | {{EnterpriseApplication.CreatedDateTime}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{EnterpriseApplication.CreatedTime}} |
| Description | String | Free text field to provide an internal end-user facing description of the service principal. End-user portals such MyApps will display the application description in this field. | {{EnterpriseApplication.Description}} |
| Display Name | String | {{EnterpriseApplication.DisplayName}} | |
| Id | String | The unique identifier for the application. | {{EnterpriseApplication.EnterpriseApplicationId}} |
| Home Page | String | Home page or landing page of the application. | {{EnterpriseApplication.HomePage}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{EnterpriseApplication.LastModifiedTime}} |
| Last Sign-In | DateTime | Date and time last sign-in to the application. This date is calculated by last-sign in found for the application and can be caused by User sign-ins (interactive and non-interactive), Service principal sign-ins or Managed identity sign-ins. Default scanning interval: Never. | {{EnterpriseApplication.LastSignIn}} |
| Login Url | String | Specifies the URL where the service provider redirects the user to Entra ID to authenticate. Entra ID uses the URL to launch the application from Microsoft 365 or the Entra ID My Apps. When blank, Entra ID performs IdP-initiated sign-on for applications configured with SAML-based single sign-on. The user launches the application from Microsoft 365, the Entra ID My Apps, or the Entra ID SSO URL. | {{EnterpriseApplication.LoginUrl}} |
| Logo Url | String | CDN URL to the application's logo. | {{EnterpriseApplication.LogoUrl}} |
| Logout Url | String | Specifies the URL that will be used by Microsoft's authorization service to logout an user using OpenId Connect front-channel, back-channel or SAML logout protocols. | {{EnterpriseApplication.LogoutUrl}} |
| Marketing Url | String | Link to the application's marketing page. | {{EnterpriseApplication.MarketingUrl}} |
| Application Notes | String | Free text field to capture information about the service principal, typically used for operational purposes. | {{EnterpriseApplication.Notes}} |
| Notification Email Addresses | String[] | Specifies the list of email addresses where Entra ID sends a notification when the active certificate is near the expiration date. This is only for the certificates used to sign the SAML token issued for Entra ID Gallery applications. | {{EnterpriseApplication.NotificationEmailAddresses}} |
| Privacy Statement Url | String | Link to the application's privacy statement. | {{EnterpriseApplication.PrivacyStatementUrl}} |
| Risk Score | Int32 | Stores risk score | {{EnterpriseApplication.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{EnterpriseApplication.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{EnterpriseApplication.RiskScoreValue}} |
| Service Principal Type | String | Indicates the type of service principal, set by Microsoft Entra ID internally. Values: Application (represents an app or service), ManagedIdentity (can be granted access but can't be modified directly), Legacy (created before app registrations, no associated app registration), ServiceIdentity (represents an agent identity), SocialIdp (internal use). | {{EnterpriseApplication.ServicePrincipalType}} |
| Sign In Audience | String | Specifies the Microsoft accounts that are supported for the current application. | {{EnterpriseApplication.SignInAudience}} |
| Support Url | String | Link to the application's support page. | {{EnterpriseApplication.SupportUrl}} |
| Terms Of Service Url | String | Link to the application's terms of service statement. | {{EnterpriseApplication.TermsOfServiceUrl}} |
| Verified Publisher | Enterprise Application Verified Publisher | The ID of the verified publisher. | {{EnterpriseApplication.VerifiedPublisher}} |
| Verified Publisher name | String | The display name of the verified publisher. | {{EnterpriseApplication.VerifiedPublisherName}} |
| Visible To Users | Boolean | If this option is set to true, then assigned users will see the application on My Apps and O365 app launcher. If this option is set to false, then no users will see this application on their My Apps and O365 launcher. | {{EnterpriseApplication.VisibleToUsers}} |
Relations
| Relation | Service | Description |
|---|---|---|
| App Role Assignment | Entra ID | App Role Assignment where Enterprise Application is a resource |
| App Role Assignment | Entra ID | App Role Assignment where Enterprise Application is service principal |
| App Role | Entra ID | |
| Directory Audits | AzureAD | All directory audit logs generated by Entra ID |
| Enterprise Registration Certificate | Entra ID | All enterprise application registration certificate of Entra ID |
| Enterprise App Client secret | Entra ID | All enterprise applications client secrets registered in Entra ID |
| Enterprise Application Verified Publisher | Entra ID | All verified publishers of enterprise applications in Entra ID |
| Enterprise Application Verified Publisher | Entra ID | All verified publishers of enterprise applications in Entra ID |
| Enterprise Application OAuth2 Permission Scope | Entra ID | All enterprise application OAuth2 permission scopes in Entra ID |
| OAuth2 Permission Grant | Entra ID | OAuth2 Permission Grant where Enterprise Application is a client |
| OAuth2 Permission Grant | Entra ID | OAuth2 Permission Grant where Enterprise Application is a resorce |
| OAuth2 Permission Scope | Entra ID | All OAuth permission scopes in Entra ID |
| Copilot Agent | Copilot Studio | Agents created inside Copilot Studio. |
| User | Microsoft 365 |
Segments
This object does currently not have any segments.
Actions
This object does currently not have any actions.
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Enterprise Applications Using Exchange Web Services (EWS) | High | This policy detects app registrations in Microsoft Entra ID with the EWS.AccessAsUser.All delegated API permission, which will be deprecated by Microsoft in October 2026. |
| Enterprise applications that use SharePoint Online permissions | Information | Shows Enterprise applications that use SharePoint Online permissions |
| Enterprise applications with Full Control or Write permissions | Medium | Shows Enterprise applications with permissions that contain the words FullControl or Write |
| Enterprise Applications without owners | Medium | Shows Enterprise Applications without owners (excluding first-party Microsoft apps) |
| Enterprise applications (SharePoint Add-Ins) with certificates or client secrets | Medium | Shows Enterprise applications with certificates or client secrets. In most cases these applications are SharePoint Add-Ins |
| Enterprise applications that use Microsoft Graph permissions | Information | Shows Entra ID apps that use Microsoft Graph permissions |
| Enterprise applications (SharePoint Add-Ins) with expired certificates or client secrets | Medium | Shows Enterprise applications with expired certificates or client secrets. In most cases these applications are SharePoint Add-Ins |