Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

4.2.4. App Collections and Delegated App Management

💡 First Principle: A portfolio of hundreds of apps needs curation for users and delegation for admins — collections organize the experience (what users find where), while scoped admin roles and ownership organize the responsibility (who fixes what without owning everything).

App collections group tiles in My Apps (myapps.microsoft.com) — "Finance tools," "New hire essentials" — built from enterprise apps and targeted at users/groups; users see only collections aimed at them, and the same app can appear in several. Low-glamour but a named syllabus bullet: know they're created in the portal (Enterprise applications → Collections / My Apps settings) and exist to tame tile sprawl.

Delegated administration has three tiers. Directory roles: Application Administrator (all apps + App Proxy + consent-relevant credentials) vs Cloud Application Administrator (all apps, no App Proxy) — the 3.1.1 discriminator. Ownership: per-app owners manage their app (SSO config, assignments, certificates) with no directory-wide role — the least-privilege default for line-of-business app teams; audit owners, since owning an app with high-privilege permissions is a privilege-escalation path. Custom roles scoped to app management fill exotic gaps.

One more standing risk deserves its callout: both Application Administrator and app owners can add credentials to an app — and an attacker with that power can authenticate as the app and inherit its permissions. That's why high-permission apps (anything with Graph application permissions like Mail.Read for all mailboxes) should have minimal owners, monitored credential changes (5.4's audit logs), and ideally certificate-only credentials.

⚠️ Exam Trap: "Delegate management of one application with least privilege" is ownership, not Cloud Application Administrator — the role covers every app in the tenant. Reserve the roles for the central team; hand owners the single app.

Reflection Question: An attacker gains a service desk account that happens to own a reporting app holding application permission Mail.Read. Chain the steps to reading the CEO's mailbox — and name the two controls from this section that would have broken the chain.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications