Support for creating AAD App registration using Bicep/ARM

NSimpraga 141 Reputation points


is there still not support for creating AAD App registrations using Bicep/ARM? It is quite ridiculous that 3rd party IAC like Terraform have this capability, while Micosoft's own - Bicep - doesn't.

I've read that the alternative is to use deployment scripts in Bicep, but there's a huge problem with this - I would need to access the created App's secrets using output, which is considered insecure even by Microsoft!

There might be some workaround by putting the secret in a key vault and retrieving it, but that complicates things a lot.

Any suggestions for this?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
17,509 questions
{count} votes

4 answers

Sort by: Most helpful
  1. Lee Richardson 121 Reputation points MVP

    It's January 2023, are App Registrations still not supported in Bicep? Jon Reginbald's workaround is fine, but like OP said terraform has had support for this feature for years, and the whole point of the Bicep DSL is to avoid writing imperative style code.

    5 people found this answer helpful.
    0 comments No comments

  2. Hugo R. Bohorquez 6 Reputation points

    Any updates on this? Thanks!

    1 person found this answer helpful.
    0 comments No comments

  3. risolis 8,691 Reputation points

    Hello @NSimpraga

    Thank you for sharing this question on this community space.

    I would like to gather the next articles which fits into your previous statement the one you were describing previously.... So please direct yourself down below:

    I hope you can find this useful to overcome your concern.

    Looking forward to your feedback,


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

  4. Jose Aviles 0 Reputation points

    The aws identity service does support IaC...

    0 comments No comments