Share via

Application.ReadWrite.OwnedBy granting permissions for non-created/owned apps?

Steve 6 Reputation points
2021-10-27T19:48:01.693+00:00

I granted an application (App A, an Azure Automation Account) the following permission and provided Admin consent:

Application.ReadWrite.OwnedBy

I then added that application (App A) as an owner to another application (App B). I was then able to Get/Start provisioning using the Graph API for App B.

However, I noticed I was able to use App A to Get/Start provisioning for another application (App C) that it is NOT an Owner of.

Any theories as to why this is? Prior to granting the above permission, everything threw a 403, as expected.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Graph

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.