Azure AD Graph Resource ID in OAuth 2.0 Authentication

InfraSolutions 811 Reputation points
2026-10-06T12:24:16.53+00:00

Hi Support,

We are reviewing a legacy mobile application that authenticates against Microsoft Entra ID using OAuth 2.0 Authorization Code Flow.

Historically, the application operated successfully when excluded from Conditional Access policies. After Conditional Access requirements such as MFA and device compliance began applying to the application, authentication is no longer successful.

The application uses OAuth 2.0 Authorization Code Flow and does not support OIDC-based authentication workflows.

During our investigation, a proposed solution was to include the Azure AD Graph resource identifier:

00000002-0000-0000-c000-000000000000 within the OAuth authentication request.

The application does not call Azure AD Graph APIs (graph.windows.net) or Microsoft Graph APIs as part of the sign-in process. The identifier is used only during token acquisition and user authentication.

My confusion is that the Microsoft Identity Platform documentation for OAuth 2.0 Authorization Code Flow primarily discusses scopes, OpenID Connect (OIDC), PKCE, and access to resources such as Microsoft Graph. I cannot find any documentation explaining the use of the Azure AD Graph resource identifier within a modern OAuth flow, particularly given that Azure AD Graph has been deprecated and Microsoft recommends using Microsoft Graph instead.

Could someone help clarify,

Is it technically valid to use the Azure AD Graph resource identifier (00000002-0000-0000-c000-000000000000) purely as part of the OAuth authentication request without making Azure AD Graph API calls?

How does specifying this resource identifier influence token issuance and Conditional Access evaluation for MFA and device compliance?

Is there any Microsoft documentation explaining this behaviour?

Is this considered a supported authentication pattern for legacy OAuth-based applications that do not consume Microsoft APIs directly?

Any guidance would be greatly appreciated.

Thanks in Advance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Vasil Michev 128.3K Reputation points MVP Volunteer Moderator
    2026-10-06T12:42:00.1966667+00:00

    If it works for your scenario, use it. There are still a handful of operations within the Azure portal that do not have a Graph API based analogue, and thus require the use of such unsupported methods. And yes, they are unsupported, if anything breaks or Microsoft suddenly pulls the plug, you're on your own.

    You might also consider voting this Feedback item up, and leaving your comment therein: https://feedbackportal.microsoft.com/feedback/idea/1b538889-b084-f011-8151-7c1e529deacc

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.