Microsoft Entra ID
Microsoft identity platform

Supported Accounts Validation

In brief

The documentation now lists a default limit of 700 shared permission definitions for app roles and exposed delegated scopes, plus an aggregate manifest limit of 1,200 collection entries.

What Entra admins need to know

Review applications with large numbers of app roles or permission scopes against these limits; no immediate administrator action is specified.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| Client secrets (passwordCredentials) | No limit* | No limit* | Maximum of two client secrets | | Redirect URIs (replyURLs) | See Redirect URI/reply URL restrictions and limitations for more info. | | | | API permissions (requiredResourceAccess) | No more than 50 total APIs (resource apps), with no more than 10 APIs from other tenants. No more than 400 permissions total across all APIs. | No more than 50 total APIs (resource apps), with no more than 10 APIs from other tenants. No more than 400 permissions total across all APIs. | No more than 50 total APIs (resource apps), with no more than 10 APIs from other tenants. No more than 200 permissions total across all APIs. Maximum of 30 permissions per resource (for example, Microsoft Graph). | | Scopes defined by this API (oauth2Permissions) | Maximum scope name length of 120 characters

No set limit* on the numberDefault limit of scopes defined700 permission definitions, shared with app roles. See App role limits. | Maximum scope name length of 120 characters

No set limit* on the numberDefault limit of scopes defined700 permission definitions, shared with app roles. See App role limits. | Maximum scope name length of 40 characters

Maximum of 100 scopes defineddefined, also subject to the shared app role limit. | | Authorized client applications (preAuthorizedApplications) | No set limit* | No set limit* | Total maximum of 500

Maximum of 100 client apps defined

Maximum of 30 scopes defined per client | | appRoles | Supported
No limit*Default limit of 700 permission definitions, shared with exposed delegated permission scopes. See App role limits. | Supported
No limit*Default limit of 700 permission definitions, shared with exposed delegated permission scopes. See App role limits. | PersonalMicrosoftAccount: Not supported

AzureADandPersonalMicrosoftAccount: Supported
No limit*Supported, subject to the shared app role limit.
App roles are not supported for consumer (MSA) users of the application at runtime | | Front-channel logout URL | https://localhost is allowed

http scheme isn't allowed

Maximum length of 255 characters | https://localhost is allowed

http scheme isn't allowed

Maximum length of 255 characters | https://localhost is allowed, http://localhost fails

http scheme isn't allowed

Maximum length of 255 characters

| | Display name | Maximum length of 120 characters | Maximum length of 120 characters | Maximum length of 90 characters |

* There's a globalan aggregate limit of about 1000 items1,200 entries across all the collection properties onin the app object.application manifest. Individual collection limits also apply. See Manifest limits.

Next steps

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…