Difference between an application role and scope in Azure AD app registrations
I have created an API that is protected by OAuth using an app registration in Azure. My app registration does not require assignment, but it exposes a number of roles that the underlying API verifies. To my understanding, this accomplishes almost the same thing as requiring approval. So far I've only had user/group roles but now I've added an application rol