How to get token from MS identity without passing a scope
Gagandeep Singh
0
Reputation points
I'm trying to secure Azure functions with easy authentication. .V1 version of MS identity gives us the ability to request token without providing the scope or resource but it sets the aud claim to GUID : 00000002-0000-0000-c000-000000000000 (which i believe is the default GUID for Entra id)
I'm trying to understand the implications if I add this GUID to the allowed audience of function app. For context request is being made from a SAAS application that does not send scope while getting token from provider.
Sign in to answer