AD / Entra Terminology Decoder Fast answers for working admins
Enterprise application
Answer: Enterprise application is the portal experience used to manage a service principal in a tenant, including assignment, consent, single sign-on, provisioning, and access controls.
Administrator playbook

Decide, verify, and document

Use the curated answer as a starting point, then prove the outcome against the target tenant or device.

1

What it means

  • The underlying directory object is normally a service principal
  • A multitenant app can have a service principal in many customer tenants
  • Deleting a tenant service principal does not delete the publisher's application object
2

What to check next

  1. Confirm tenant and service-principal object ID
  2. Review assignments, consent grants, SSO, and provisioning separately
  3. Do not rotate app-registration credentials from the Enterprise applications blade by assumption
3

Verify success

  1. Confirm the object type and identifier in the authoritative tenant.
  2. Compare the portal value with Microsoft Graph or the local device state.
  3. Use IDs—not display names—when proving that two references point to the same object.
4

Escalate when

  • Two portals or APIs return conflicting identifiers for the same expected object.
  • The issue crosses tenant or cloud boundaries.
  • A production authorization decision depends on the object relationship.
Copyable admin briefAnswer, next checks, source, and review date
Inspect Microsoft Graph context
Get-MgContext | Select-Object ClientId,TenantId,Account,AuthType,Scopes

Read-only. Useful when a term or identifier is being interpreted in the wrong tenant.

Evidence to preserve

Portal
Enterprise applications
Object
Service principal
Scope
Tenant local
  • Tenant ID and cloud
  • Object type and object ID
  • User, app, or device context
  • Where the value was observed