naming mismatch in azure entra id

Richee Pitchee 20 Reputační body
2026-07-08T14:14:17.36+00:00

This is the search result for phrase Claude SSOObrázek uživatele

and this is found applications that open after click.
Obrázek uživatele Obrázek uživatele

See the confusinon?

First problem
The naming convention Application versus Service Principal in search result: Aplication is the one with blue cube icon. Service PRincipal is the one with green earth icon. What is Application versus Service Principal? whatever it is, it is not, what you get when you click the result, see Second problem

Second problem
When you click the search result you get somewhere else then you expect

  1. first: the blue cube thing called Application opens a page that does not have a type name "Application". it does not have any type name suddently.
  2. second: when you click the green earth called Service principal, you will ge to something called Enterprise application.

Request: in search result I need to see what I will get. Otherwise search functionality has limited usage. Now I have to each time open both, because I cannot remember, what is the one with Users and groups on it.

(sorry, I am not capable to use the Add picture editor here, to insert pictures in the right place ot the text. it is so confusing. Why you make editor with new behavior, when all other editors are alredy invented and functional? this one is not.
Sorry 2: in azure, there is a link that leads here for community content. However, it does not seem to be here. Still I will place it here

Windows pro firmy | Windows 365 Enterprise
Počet komentářů: 0 Žádné komentáře

Odpověď přijatá autorem otázky
Tracy Le 13,290 Reputační body Nezávislý poradce
2026-07-08T15:01:13.5133333+00:00

Hi Richee Pitchee,

This visual and naming distinction in Microsoft Entra ID stems from the core architecture of how identity objects are managed. The item labeled Application with the blue cube icon represents an App Registration, which is the global template and definition of your application configuration. The item labeled Service Principal with the green earth icon represents an Enterprise Application, which is the actual local instance of that application created within your specific tenant to manage access, single sign-on, and user assignments.

This architecture explains why you land on different management blades when clicking each search result. When you need to manage permissions, user assignments, or access controls, you should always select the Service Principal or green earth icon, as this opens the Enterprise Application blade containing the Users and groups menu you are looking for. The App Registration blade opened by the blue cube icon is primarily used by developers to configure application properties like redirect URIs, certificates, and API permissions, which is why it does not explicitly display an enterprise service type banner.

I hope the response provided some helpful insight. If it clarified the issue for you, please consider marking it as Accept Answer so others with the same issue can find the solution. Feel free to leave a comment if you need further information.

Tracy Le.

Byla tato odpověď užitečná?

Počet osob, které tuto odpověď považovaly za užitečnou: 1.

Odpověď doporučená moderátorem
Tracy Le 13,290 Reputační body Nezávislý poradce
2026-07-08T16:39:09.9366667+00:00

Hi Richee Pitchee,

To clarify why these separate objects exist, the item labeled Application with the blue cube icon strictly represents an Application Registration template within your directory. It does not represent other distinct object types in this search context because its sole architectural purpose is to serve as the global blueprint for an identity, defining core attributes like the application ID, multi-tenant status, and requested API permissions.

In contrast, the item labeled Service Principal with the green earth icon can represent several different functional instances beyond standard third-party Enterprise Applications. For example, it represents Managed Identities used by Azure resources like virtual machines or function apps to authenticate securely without storing credentials in code.

It also represents core Microsoft first-party services like Microsoft Graph, as well as multi-tenant applications registered in external organizations that your local users have consented to use. In all these cases, the green icon indicates that an active security principal is executing permissions in your local tenant, which is why the operational configurations like user assignments always reside there.

Byla tato odpověď užitečná?

Počet komentářů: 0 Žádné komentáře

1 další odpověď

Seřadit podle: Nejužitečnější
  1. Kazzan 1,301 Reputační body MVP Dobrovolný moderátor
    2026-09-01T14:03:32.6333333+00:00

    I think that https://ericonidentity.com/2023/03/11/entra-app-registrations-and-enterprise-applications-the-definitive-guide/ describes it nicely with needed technical detail of each resource you see in portal.

    Byla tato odpověď užitečná?

    Počet komentářů: 0 Žádné komentáře

Vaše odpověď

Odpovědi můžou být autorem otázky označeny jako „Přijaté“ a moderátory jako „Doporučené“, což uživatelům pomůže zjistit, že odpověď vyřešila problém autora.