Portal guidance / live auth

MSC app registration and consent

This experience is designed to feel explicit, reviewable, and secure. The portal uses the app registration only when a supported live-auth scenario needs it, and it keeps the customer in control of the decision.

System status
Optional • explicit • reviewable
A secure path for supported customer workflows.

What the customer is consenting to

The app registration is optional and it does not change the portal's core security model.

When an organization chooses to use the MSC app registration, the portal requests the minimum Microsoft Graph permissions needed for the selected scenario. The consent remains narrow, purpose-bound, and limited to the workflow that is actually running.

Security overview
  • Consent is granted by an authorized administrator in the customer tenant.
  • The portal uses OAuth 2.0 Authorization Code + PKCE rather than an implicit flow.
  • The app registration is scoped to the permissions required for the active scenario.
  • When the bundle is not configured or unavailable, the portal continues with the existing auth path.

How the flow works

A clean path from scenario selection to controlled execution.

1
Select the scenario
The portal identifies the supported live-auth workflow and prepares the minimum scope required for that path.
2
Review the consent scope
An authorized administrator can inspect the requested permissions before the workflow continues.
3
Proceed with explicit access
The app registration is used only when the scenario needs it, and the activity is bounded to the approved workflow.
4
Stay on the safe fallback path
If the bundle is not available, the portal continues with the existing authentication path without disruption.

What is granted

Read access to the Microsoft Graph resources required for validation and inventory checks.

What stays the same

The portal does not force a new path when the bundle is unavailable, and no tenant-wide change is implied.

What the customer controls

Consent is granted by an authorized administrator in the customer tenant, with the workflow limited to the approved scenario.
Customer promise
The experience stays explicit, reviewable, and reversible — and you can always stay on the existing path if that is your preference.
Requires a customer Global Administrator. One-time consent per tenant.