A multi-tenant ticketing vendor’s app registration lives in the vendor tenant, but the grain elevator must assign Azure RBAC and review grants locally. Where should the security engineer work?
Select an answer to reveal the explanation.
Short Explanation
The vendor owns the blueprint in their tenant; you own the local badge. That badge is the service principal—enterprise app—in the grain elevator’s directory. Assign RBAC and review grants there, not by cloning the vendor’s app registration.
Full Explanation
For multi-tenant applications, the application object typically remains in the publisher tenant while each customer tenant gets a service principal (enterprise application) after consent or provisioning. Customer-tenant RBAC assignments and OAuth grant review target that local service principal. Creating a duplicate app registration is not the default representation of the vendor app. Secrets in mailboxes and assigning roles to a foreign application object without a local principal are incorrect.