This article explains how Microsoft 365 enterprise apps work with Azure AD and what permissions they need. It walks through a generic app authorization as a Global Administrator and covers common security misconceptions. It then explains in more technical depth how a service account gets authorized and connected to Robin.
Read it if you want to know: "How do we let people sign in to Robin with Microsoft 365 without letting everyone authenticate with any app on the internet?"
Service Principal and Application objects
When you authorize the Robin app for the first time, it registers a Service Principal object in your Azure directory. This is your "install" of the Robin app, and you manage it directly. Robin maintains the Application object itself, so Robin can develop and maintain the app for all customers in one place.
Think of the Service Principal as an installed version of software, and the Application as the most recent version. If the Application changes (for example, it adds or removes a permission for features), you can authorize the most recent version again to update the Service Principal. This is very rare, and Robin does not need it to run.
This diagram from Microsoft shows the workflow:
Add new applications in Microsoft 365
Microsoft sets this requirement for Global Administrators and applications in Azure AD:
Only global administrators can:
- Add apps from the Azure AD app gallery (pre-integrated 3rd Party Apps)
- Publish an app using the Azure AD Application Proxy
The first time you sign in to Robin's app, you must be a Global administrator, unless your tenant lets all users register new applications. Robin does not recommend this.
During sign up/in users are asked to give permission to the app to access their profile and other permissions. The first person to give consent causes a service principal representing the app to be added to the directory.
After you add the app to your directory, you no longer need the Global Administrator role to manage its settings.
User consent settings
When you enable "Users can consent to apps accessing company data on their behalf", regular users assigned to the app can sign in to existing service principals. It does not grant users the right to create new service principals (other apps you have not approved). The "Users can add gallery apps to their Access Panel" option controls new apps, and it can stay disabled.
In other words, the first option lets your users authorize only pre-approved apps. The second option lets them authorize any app they choose.
References
- Who has permission to add applications to my Azure AD instance? Global Admins + App Registration (Microsoft)
- https://docs.microsoft.com/en-us/azure/active-directory/application-access-assignment-how-to-add-assignment
- https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-devhowto-multi-tenant-overview
- https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-scopes
- Manage your Azure Enterprise Apps (Azure Portal)
- https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-application-objects