application resource type


APIs under the /beta version in Microsoft Graph are subject to change. Use of these APIs in production applications is not supported.

Represents an application. Any application that outsources authentication to Azure Active Directory (Azure AD) must be registered in a directory. Application registration involves telling Azure AD about your application, including the URL where it's located, the URL to send replies after authentication, the URI to identify your application, and more. For more information, see Basics of Registering an Application in Azure AD. Inherits from directoryObject.

Note: Changes to the application resource type are currently in development. For more information, see known issues with Microsoft Graph.

This resource supports:

  • Using delta query to track incremental additions, deletions, and updates, by providing a delta function.


Method Return Type Description
Get application application Read properties and relationships of application object.
Create application application Creates (registers) a new application.
List applications application Retrieve the list of applications in the organization.
Update application application Update application object.
Delete application None Delete application object.
List assigned policies policy collection Get all policies assigned to this object.
Create owner directoryObject Create a new owner by posting to the owners collection.
List owners directoryObject collection Get an owner object collection.
delta application collection Get incremental changes for applications.
Create call call Create a new call by posting to the calls collection.
Create online meeting onlineMeeting Create a new online meeting by posting to the onlineMeetings collection.


Property Type Description
api apiApplication Specifies settings for an API application.
appId String The unique identifier for the application that is assigned to an application by Azure AD. Not nullable. Read-only.
appRoles appRole collection The collection of application roles that an application may declare. These roles can be assigned to users, groups, or service principals. Not nullable.
createdDateTime DateTimeOffset The date and time the application was registered.
deletedDateTime DateTimeOffset The date and time the application was deleted.
displayName String The display name for the application.
id String The unique identifier for the application. Inherited from directoryObject. Key. Not nullable. Read-only.
identifierUris String collection The URIs that identify the application. For more information see, Application Objects and Service Principal Objects. The any operator is required for filter expressions on multi-valued properties. Not nullable.
info informationalUrl Basic profile information of the application.
isFallbackPublicClient Boolean Specifies the fallback app type as public client, such as an installed app running on a mobile device. The default value is false which means the fallback app type is confidential client such as web app. There are certain scenarios where Azure AD cannot determine the client app type (e.g. ROPC flow where it is configured without specifying a redirect URI). In those cases Azure AD will interpret the app type based on the value of this property.
keyCredentials keyCredential collection The collection of key credentials associated with the application Not nullable.
logo Stream The main logo for the application. Not nullable.
optionalClaims optionalClaims Reserved for future use.
orgRestrictions String collection Reserved for future use.
parentalControlSettings parentalControlSettings collection Specifies parental control settings for an application.
passwordCredentials passwordCredential collection The collection of password credentials associated with the application. Not nullable.
publicClient publicClientApplication Specifies settings for installed clients such as desktop or mobile devices.
publisherDomain String The verified publisher domain for the application. Read-only.
requiredResourceAccess requiredResourceAccess collection Specifies resources that this application requires access to and the set of OAuth permission scopes and application roles that it needs under each of those resources. This pre-configuration of required resource access drives the consent experience. Not nullable.
signInAudience String Specifies what Microsoft accounts are supported for the current application. Supported values are:
  • AzureADMyOrg: Users with a Microsoft work or school account in my organization’s Azure AD tenant (i.e. single tenant)
  • AzureADMultipleOrgs: Users with a Microsoft work or school account in any organization’s Azure AD tenant (i.e. multi-tenant)
  • AzureADandPersonalMicrosoftAccount: Users with a personal Microsoft account, or a work or school account in any organization’s Azure AD tenant
tags String collection Custom strings that can be used to categorize and identify the application.
web webApplication Specifies settings for a web application.


Relationship Type Description
calls call collection Read-only. Nullable.
connectorGroup connectorGroup The connectorGroup the application is using with Azure AD Application Proxy. Nullable.
createdOnBehalfOf directoryObject Read-only.
onlineMeetings onlineMeeting collection Read-only. Nullable.
owners directoryObject collection Directory objects that are owners of the application. The owners are a set of non-admin users who are allowed to modify this object. Requires version 2013-11-08 or newer. Read-only. Nullable.
policy policy collection The policies assigned to this application.

JSON representation

The following is a JSON representation of the resource.

  "api": {"@odata.type": "microsoft.graph.apiApplication"},
  "appId": "String",
  "appRoles": [{"@odata.type": "microsoft.graph.appRole"}],
  "createdDateTime": "String (timestamp)",
  "deletedDateTime": "String (timestamp)",
  "displayName": "String",
  "id": "String (identifier)",
  "identifierUris": ["String"],
  "info": {"@odata.type": "microsoft.graph.informationalUrl"},
  "isFallbackPublicClient": true,
  "keyCredentials": [{"@odata.type": "microsoft.graph.keyCredential"}],
  "logo": "Stream",
  "optionalClaims": {"@odata.type": "microsoft.graph.optionalClaims"},
  "orgRestrictions": ["Guid"],
  "parentalControlSettings": [{"@odata.type": "microsoft.graph.parentalControlSettings"}],
  "passwordCredentials": [{"@odata.type": "microsoft.graph.passwordCredential"}],
  "preAuthorizedApplications": [{"@odata.type": "microsoft.graph.preAuthorizedApplication"}],
  "publicClient": {"@odata.type": "microsoft.graph.publicClientApplication"},
  "publisherDomain": "String",
  "requiredResourceAccess": [{"@odata.type": "microsoft.graph.requiredResourceAccess"}],
  "signInAudience": "String",
  "tags": ["String"],
  "web": {"@odata.type": "microsoft.graph.webApplication"}