Can a client secret created with an app registration in Azure be used multiple times?

Minh 1 Reputation point
2021-04-05T16:55:27.047+00:00

Can a client secret created with an app registration in Azure be used multiple times?

If a person has the client ID and the Client Secret, can that be compromised that way?

Microsoft Entra
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 95,836 Reputation points MVP
    2021-04-05T18:11:26.723+00:00

    Yes, it can, on both questions. Think of the client secret as just a very long password... that gives you access to potentially everything within the tenant. Do not share it, do not store it in plain text, or better yet switch to using certificates instead.

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more