Skip to content
Skip to main content
Cloud Services Technical Explainer

Can an application access the cloud account on the user’s behalf?

Yes. With delegated authority, an application can request permitted cloud resources in a user's context. The user or an administrator grants consent; the identity platform issues tokens; the application may then act interactively or in the background without receiving the user's password.

Dave authorises Northstar Archive to read his OneDrive files. Entra records consent for a defined permission and creates the application's local service-principal relationship. At 02:15 the archive service presents a token to Microsoft Graph and reads tender-notes.docx automatically.

Obtain both sides of the event

The cloud identity provider may hold the application ID, service-principal object, consent actor, permission grant and token/sign-in context. The resource provider holds the operation and object. The application provider may hold the schedule, feature, operator and request logs explaining why the call occurred.

Permission shows what the application could request; the resource event shows what it did. A user may have consented once without initiating each later action. An administrator may also grant access across a tenant, so do not assume every affected user saw a consent screen.

Microsoft application consent - checked 2 September 2026

Microsoft defines consent as a user or administrator granting an application authorization to access protected resources. In Entra, an application object describes the software and a service principal represents its local identity in a tenant; consent can create that local relationship and its permissions.

The point to remember

Separate the consent, application identity, issued authority and resource event. Together they show what the application was allowed to do and what it actually did on the user's behalf.

Reference: CLD-033Cloud Services