Microsoft Entra ID Governance
Microsoft identity platform

Privileged Identity Management Custom Extensions

In brief

The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.

What Entra admins need to know

Administrators consulting these examples should use the updated identifiers when configuring PIM custom extensions.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Open the app registration and go to Expose an API.

  2. Select Set next to Application ID URI.

  3. Enter a value that represents your API. The URI must end with the Application (client) ID of the app registration. For example, if your custom extension endpoint is https://api.contoso.com/webhooks/entra-role-assignments and the Application (client) ID is aaaabbbb-0000-cccc-1111-dddd2222eeee00001111-aaaa-2222-bbbb-3333cccc4444, set the Application ID URI to: api://api.contoso.com/aaaabbbb-0000-cccc-1111-dddd2222eeee00001111-aaaa-2222-bbbb-3333cccc4444

  4. Select Save. :::image type="content" source="media/privileged-identity-management-custom-extensions/app-registration-expose-api.png" alt-text="Screenshot of the app registration to expose API page." lightbox="media/privileged-identity-management-custom-extensions/app-registration-expose-api.png"::: }, "authenticationConfiguration": { "@odata.type": "#microsoft.graph.azureAdTokenAuthentication", "resourceId": "api://api.contoso.com/aaaabbbb-0000-a0a0a0a0-bbbb-cccc-1111-dddd2222eeeedddd-e1e1e1e1e1e1" }, "resourceType": "entraGroups", "customAttributes": []

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…