azureazure-active-directorymicrosoft-entra-idazure-entra-id

Should deleted application in Enterprise app be also deleted in App registration within Azure AD?


I've deleted an existing application in Enterprise application and it was not in the list to confirm but it's still available in App Registration when I search it. Could someone enlighten me?


Solution

  • A service principal is a representation of the app registration at the directory level, allowing the application to be recognized and authorized within the Azure AD.

    When you create an app registration through the Azure Portal, the process includes assigning "User.Read" permission, without any manual intervention like this:

    enter image description here

    This automatically creates service principal under "Enterprise applications" with same name as App registration:

    enter image description here

    When you delete the application in Enterprise applications, service principal only will be deleted but app registration still exists. But if you delete app registration, application in "Enterprise applications" (service principal) will also be deleted along with App registration.

    Reference: Apps & service principals in Microsoft Entra ID