SOLVED
Home

Administrative Control Of Application Ownership

%3CLINGO-SUB%20id%3D%22lingo-sub-262884%22%20slang%3D%22en-US%22%3EAdministrative%20Control%20Of%20Application%20Ownership%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-262884%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20any%20way%20for%20a%20tenant%20admin%20to%20reclaim%20a%20registered%20application%20if%20the%20individual%20who%20registered%20it%20has%20left%20the%20company%3F%20I%20understand%20that%20more%20than%20one%20person%20should%20be%20designated%20as%20the%20owner.%20And%20there%20are%20a%20number%20of%20work-arounds%20available.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EIf%20the%20AD%2FAzure%20AD%20account%20has%20simply%20been%20disabled%2C%20an%20admin%20can%20re-enable%20the%20account%2C%20change%20the%20password%2C%20and%20log%20in%20under%20those%20credentials.%20Since%20the%20app%20continues%20to%20function%20when%20the%20owners%20account%20has%20been%20disabled%2C%20I%20foresee%20instances%20where%20the%20account%20has%20been%20deleted%20and%20its%20tombstone%20aged%20out.%3C%2FLI%3E%3CLI%3ERegister%20a%20new%20application%20under%20another%20user's%20ID%20and%20update%20the%20project%20with%20this%20new%20ID%2Fsecret%20(although%20this%20requires%20figuring%20out%20what%20the%20proper%20app%20settings%20should%20be).%3C%2FLI%3E%3C%2FUL%3E%3CP%3EIt%20would%20be%20nice%20if%20a%20quick%2Feasy%20option%20were%20available%20for%20someone%20to%20reassign%20ownership%20of%20orphaned%20applications%20(and%20view%20a%20list%20of%20applications%20registered%20in%20their%20tenant).%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-263214%22%20slang%3D%22en-US%22%3ERe%3A%20Administrative%20Control%20Of%20Application%20Ownership%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-263214%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20for%20the%20response%20...%20I%20am%20looking%20for%20item%20%232%20in%20the%20linked%20post%2C%20so%20it%20looks%20like%20the%20answer%20is%20essentially%20%22it's%20on%20the%20roadmap%22.%20I'll%20ask%20out%20account%20rep%20to%20keep%20us%20updated.%3C%2FP%3E%3CP%3E--L%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-263151%22%20slang%3D%22en-US%22%3ERe%3A%20Administrative%20Control%20Of%20Application%20Ownership%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-263151%22%20slang%3D%22en-US%22%3E%3CDIV%3EHi%20Lisa%2C%3C%2FDIV%3E%0A%3CDIV%3EYou%20bring%20up%20an%20interesting%20issue%2C%20I%20found%20a%20question%20similar%20to%20yours%20on%20%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fquestions%2F44271214%2Fwho-owns-a-registered-microsoft-application-registration-portal-app%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Estackoverflow%3C%2FA%3E%20that%20may%20help.%20It%20looks%20like%20there%20is%20a%20solution%20to%20your%20issue%20in%20the%20comments%20section.%3C%2FDIV%3E%0A%3CDIV%3EIf%20this%20doesn't%20answer%20your%20question%20try%20reaching%20out%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevelop%2Fv2-overview%23help-and-support%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20AD%20Team%3C%2FA%3E.%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Lisa Rushworth
New Contributor

Is there any way for a tenant admin to reclaim a registered application if the individual who registered it has left the company? I understand that more than one person should be designated as the owner. And there are a number of work-arounds available.

 

  • If the AD/Azure AD account has simply been disabled, an admin can re-enable the account, change the password, and log in under those credentials. Since the app continues to function when the owners account has been disabled, I foresee instances where the account has been deleted and its tombstone aged out.
  • Register a new application under another user's ID and update the project with this new ID/secret (although this requires figuring out what the proper app settings should be).

It would be nice if a quick/easy option were available for someone to reassign ownership of orphaned applications (and view a list of applications registered in their tenant). 

2 Replies
Highlighted
Solution
Hi Lisa,
You bring up an interesting issue, I found a question similar to yours on stackoverflow that may help. It looks like there is a solution to your issue in the comments section.
If this doesn't answer your question try reaching out to the Azure AD Team
 

Thank you for the response ... I am looking for item #2 in the linked post, so it looks like the answer is essentially "it's on the roadmap". I'll ask out account rep to keep us updated.

--L