ST-2026-015 · Authentication & identity
Microsoft Entra blocks remaining service-principal-less app-only authentication
Microsoft Entra ID is retiring service-principal-less authentication for the remaining non-Microsoft multitenant application exceptions, requiring every affected app to have a service principal in each resource tenant where it authenticates.
Previous state
A small remaining set of non-Microsoft multitenant applications could obtain app-only tokens in a resource tenant without a service-principal object in that tenant.
Current state
Microsoft Entra blocks app-only authentication for non-Microsoft multitenant applications that do not have a service principal in the tenant where they authenticate.
Affected users
Who needs to care
Tenant administrators and application owners whose non-Microsoft multitenant apps appear in service-principal sign-in logs with the all-zero service-principal identifier.
Required response
What to do
Inspect service-principal sign-in logs for the all-zero identifier, decide whether each application should retain access, create a service principal in the resource tenant, and verify that later sign-ins carry the new object identifier.
Evidence boundary
What the source does not prove
The retirement applies to non-Microsoft multitenant app-only authentication without a service principal. Microsoft applications and ordinary user sign-ins can appear without a service principal and do not require the same mitigation. Microsoft also states that most non-Microsoft applications were already blocked before the final enforcement date.
Connected NeoLinks intelligence
Related evidence across the network
Curated because the records share a publisher, platform, control, sector or procurement context. Each destination keeps its own evidence boundary.
CISO-as-a-Service and cyber-governance procurement
The Entra authentication change is a technical control event; ContractLens shows a procurement-side demand signal for governance, risk and security advisory capability.
Lifecycle history
Dated event sequence
- Mitigation guidance updated
Microsoft documented the remaining exception population, log query and service-principal creation steps.
- Mitigation deadline
Affected applications needed a service principal to avoid app-only authentication disruption.
Evidence ledger
First-party sources
- 01Microsoft Learn — Retirement of service principal-less authentication
Official retirement and tenant-mitigation guidance · 2025-07-15
Open official source ↗