GraphApplication¶
Represents Entra ID applications collected from Microsoft Graph.
Labels: :GraphObject:GraphApplication
Properties:
description- Application descriptionnotes- Application notescreatedDateTime- Creation timestampcreatedByAppId- Application ID of the creatorapplicationTemplateId- Application template IDisAuthorizationServiceEnabled- Authorization service flagisDeviceOnlyAuthSupported- Device-only authentication support flagisDisabled- Whether the application is disabledisFallbackPublicClient- Fallback public client flagisManagementRestricted- Management restriction flagnativeAuthenticationApisEnabled- Native authentication API configuration-
defaultRedirectUri- First URI inweb.redirectUris -
odataType- Lowercase@odata.type, when returned by Microsoft Graph -
id- Application object ID (primary key) displayName- Application's display nameappId- Application ID (client ID)publisherDomain- Publisher domainsignInAudience- Sign-in audience configurationidentifierUris- Array of identifier URIsredirectUris- Combined array of all redirect URIs (web + SPA + public client)publicClientRedirectUris- Array of public client redirect URIsspaRedirectUris- Array of single-page application redirect URIswebRedirectUris- Array of web application redirect URIsimplicitAccessToken- Whether implicit grant flow access token issuance is enabledimplicitIdToken- Whether implicit grant flow ID token issuance is enabled
Relationships¶
Incoming¶
-
GraphObject →
CREATED→ GraphApplication - Creator identified bycreatedByAppId -
GraphObject →
OWNS→ GraphApplication - Owners of the application - GraphObject →
APPROLE→ GraphApplication - Objects with app role assignments - ClientSecret →
AUTHENTICATES→ GraphApplication - Client secrets for authentication - Certificate →
AUTHENTICATES→ GraphApplication - Certificates for authentication
Outgoing¶
-
GraphApplication →
CREATED→ GraphServicePrincipal - Service principals created by the application -
GraphApplication →
HAS_APPROLE→ GraphAppRole - App roles defined by the application - GraphApplication →
FEDERATED_CREDENTIAL→ FederatedIdentityCredential - Federated identity credentials
Examples¶
// Find all multi-tenant applications
MATCH (app:GraphApplication)
WHERE app.signInAudience = "AzureADMultipleOrgs"
RETURN app.displayName, app.appId, app.publisherDomain