Hi Support,
We are reviewing a legacy mobile application that authenticates against Microsoft Entra ID using OAuth 2.0 Authorization Code Flow.
Historically, the application operated successfully when excluded from Conditional Access policies. After Conditional Access requirements such as MFA and device compliance began applying to the application, authentication is no longer successful.
The application uses OAuth 2.0 Authorization Code Flow and does not support OIDC-based authentication workflows.
During our investigation, a proposed solution was to include the Azure AD Graph resource identifier:
00000002-0000-0000-c000-000000000000 within the OAuth authentication request.
The application does not call Azure AD Graph APIs (graph.windows.net) or Microsoft Graph APIs as part of the sign-in process. The identifier is used only during token acquisition and user authentication.
My confusion is that the Microsoft Identity Platform documentation for OAuth 2.0 Authorization Code Flow primarily discusses scopes, OpenID Connect (OIDC), PKCE, and access to resources such as Microsoft Graph. I cannot find any documentation explaining the use of the Azure AD Graph resource identifier within a modern OAuth flow, particularly given that Azure AD Graph has been deprecated and Microsoft recommends using Microsoft Graph instead.
Could someone help clarify,
Is it technically valid to use the Azure AD Graph resource identifier (00000002-0000-0000-c000-000000000000) purely as part of the OAuth authentication request without making Azure AD Graph API calls?
How does specifying this resource identifier influence token issuance and Conditional Access evaluation for MFA and device compliance?
Is there any Microsoft documentation explaining this behaviour?
Is this considered a supported authentication pattern for legacy OAuth-based applications that do not consume Microsoft APIs directly?
Any guidance would be greatly appreciated.
Thanks in Advance.