Overview of Microsoft Entra role-based access control (RBAC)
In brief
The documentation now says app instance property lock can be enabled for both single-tenant and multitenant apps.
What Entra admins need to know
Administrators of single-tenant apps can use the lock to help prevent unauthorized changes to sensitive service principal properties.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Overview of Microsoft Entra role-based access control (RBAC)
description: Learn how to understand the parts of a role assignment and restricted scope in Microsoft Entra ID.
ms.topic: overview
ms.date: 06/10/01/2026
ms.reviewer: abhijeetsinha
ms.custom: it-pro, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-image-nochange
ai-usage: ai-assisted
- Apply Conditional Access for workload identities to restrict where and when a service principal can authenticate. This capability requires Workload Identities Premium licenses and applies only to single-tenant service principals registered in your tenant — managed identities and multitenant or third-party SaaS apps aren't in scope.
- Run access reviews of groups and applications to confirm that users assigned to those resources still need their access, and use PIM access reviews to review service principals assigned to Microsoft Entra and Azure resource roles. Reviews of groups and applications require Microsoft Entra ID Governance or Microsoft Entra Suite (some capabilities are available with Microsoft Entra ID P2); for details, see License requirements. Reviews of service principals additionally require Microsoft Entra Workload ID Premium.
- Tag service principals for your registered applications with custom security attributes so you can build a filterable inventory and drive Azure ABAC decisions from business attributes.
- Enable app instance property lock on single-tenant and multitenant apps to prevent unauthorized modification of sensitive properties on the service
principal after the app is provisioned in another tenant.principal.
License requirements
@@ -2,7 +2,7 @@ title: Overview of Microsoft Entra role-based access control (RBAC) description: Learn how to understand the parts of a role assignment and restricted scope in Microsoft Entra ID. ms.topic: overview-ms.date: 06/01/2026+ms.date: 10/01/2026 ms.reviewer: abhijeetsinha ms.custom: it-pro, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-image-nochange ai-usage: ai-assisted@@ -125,7 +125,7 @@ Govern these identities at scale with the same layered controls you apply to use - Apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md) to restrict where and when a service principal can authenticate. This capability requires Workload Identities Premium licenses and applies only to single-tenant service principals registered in your tenant — managed identities and multitenant or third-party SaaS apps aren't in scope. - Run [access reviews of groups and applications](~/id-governance/create-access-review.md) to confirm that users assigned to those resources still need their access, and use [PIM access reviews](~/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review.md) to review service principals assigned to Microsoft Entra and Azure resource roles. Reviews of groups and applications require Microsoft Entra ID Governance or Microsoft Entra Suite (some capabilities are available with Microsoft Entra ID P2); for details, see [License requirements](~/id-governance/access-reviews-overview.md#license-requirements). Reviews of service principals additionally require Microsoft Entra Workload ID Premium. - Tag service principals for your registered applications with [custom security attributes](~/fundamentals/custom-security-attributes-overview.md) so you can build a filterable inventory and drive [Azure ABAC](/azure/role-based-access-control/conditions-custom-security-attributes) decisions from business attributes.-- Enable [app instance property lock](~/identity-platform/howto-configure-app-instance-property-locks.md) on multitenant apps to prevent unauthorized modification of sensitive properties on the service principal after the app is provisioned in another tenant.+- Enable [app instance property lock](~/identity-platform/howto-configure-app-instance-property-locks.md) on single-tenant and multitenant apps to prevent unauthorized modification of sensitive properties on the service principal. ## License requirements 