API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-015 · Authentication & identity

Microsoft Entra blocks remaining service-principal-less app-only authentication

Microsoft Entra ID is retiring service-principal-less authentication for the remaining non-Microsoft multitenant application exceptions, requiring every affected app to have a service principal in each resource tenant where it authenticates.

Microsoft Entra IDservice principalapp-only authenticationmultitenant appsConditional Access

Previous state

A small remaining set of non-Microsoft multitenant applications could obtain app-only tokens in a resource tenant without a service-principal object in that tenant.

Current state

Microsoft Entra blocks app-only authentication for non-Microsoft multitenant applications that do not have a service principal in the tenant where they authenticate.

Who needs to care

Tenant administrators and application owners whose non-Microsoft multitenant apps appear in service-principal sign-in logs with the all-zero service-principal identifier.

What to do

Inspect service-principal sign-in logs for the all-zero identifier, decide whether each application should retain access, create a service principal in the resource tenant, and verify that later sign-ins carry the new object identifier.

What the source does not prove

The retirement applies to non-Microsoft multitenant app-only authentication without a service principal. Microsoft applications and ordinary user sign-ins can appear without a service principal and do not require the same mitigation. Microsoft also states that most non-Microsoft applications were already blocked before the final enforcement date.

Related evidence across the network

Curated because the records share a publisher, platform, control, sector or procurement context. Each destination keeps its own evidence boundary.

ContractLens · identity control · procurement demand

CISO-as-a-Service and cyber-governance procurement

The Entra authentication change is a technical control event; ContractLens shows a procurement-side demand signal for governance, risk and security advisory capability.

Lifecycle history

Dated event sequence

  1. Mitigation guidance updated

    Microsoft documented the remaining exception population, log query and service-principal creation steps.

  2. Mitigation deadline

    Affected applications needed a service principal to avoid app-only authentication disruption.

Evidence ledger

First-party sources

  1. 01
    Microsoft Learn — Retirement of service principal-less authentication

    Official retirement and tenant-mitigation guidance · 2025-07-15

    Open official source ↗