How can a Tenant admin programmatically enumerate exact permissions requested by a newly created multitenant service principal before consent?

Raghav Thapa 0 Reputation points
2026-09-04T00:15:07.1666667+00:00

I’m trying to understand the exact Microsoft Entra / Microsoft Graph object model for reviewing permissions on an external multitenant application before granting tenant-wide admin consent.

Scenario:

  • Tenant A is the publisher/home tenant.
  • Tenant A owns a multitenant App Registration.
  • Tenant B is the consuming/customer tenant.
  • As an administrator in Tenant B, I explicitly create the foreign service principal using Microsoft Graph:
POST https://graph.microsoft.com/v1.0/servicePrincipals { "appId": "<publisher-app-client-id>" }

The service principal now exists in Tenant B under Enterprise Applications.

No user or administrator consent has been granted yet.

Before granting admin consent, I want to programmatically review the exact permissions the application will request, including:

Resource/API: Microsoft Graph
Permission type: Delegated
Permission: User.Read
Permission ID: <GUID>
Resource/API: Custom API
Permission type: Delegated
Permission: Some.Scope
Permission ID: <GUID>

I am not trying to enumerate permissions that have already been granted.

For example:

GET /servicePrincipals/{id}/oauth2PermissionGrants

only shows delegated permission grants that already exist, so it does not answer the pre-consent question.

I understand that the publisher Application object contains requiredResourceAccess, but Tenant B does not own that Application object. Tenant B only has the foreign service principal.

My question is:

Is there a supported Microsoft Graph or Entra API that allows a Tenant B administrator to obtain the exact static API permissions requested by a foreign multitenant application after its service principal has been created, but before any consent has been granted?

Specifically, is this information available through:

  • a property or relationship on servicePrincipal;
  • another Microsoft Graph endpoint;
  • a consent-related API;
  • a cross-tenant application metadata endpoint;
  • Microsoft Graph beta;
  • or another supported Entra API?

If not, does the Entra consent service internally resolve the publisher Application object's requiredResourceAccess in a way that is not exposed to the consuming tenant through Microsoft Graph?

I’m looking for a deterministic API-based method suitable for enterprise application onboarding and permission review, rather than relying only on the interactive admin-consent dialog.

An authoritative Microsoft reference confirming either the supported method or the limitation would be very helpful.

Microsoft Security | Microsoft Graph
0 comments No comments

1 answer

Sort by: Most helpful
  1. Vasil Michev 127.8K Reputation points MVP Volunteer Moderator
    2026-09-04T14:22:06.5733333+00:00

    Generally speaking, you cannot. The admin consent process is designed to be interactive and you review the requested permissions as part of the flow.

    If instead you are provisioning the app (service principal) programmatically, you need to know beforehand what permissions to grant. You can obtain said information from the publisher (via their documentation/support/whatever), or in some cases via the appRoles and publishedPermissionScopes properties on the SP, though both methods are not guaranteed to even be available.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.