For the complete documentation index, see llms.txt. This page is also available as Markdown.

Application Templates

Application templates capture how an application should be deployed to a tenant: which application, which kind of deployment, and which permissions to grant. They are stored in CIPP rather than in any tenant, so a template written once can be deployed to any number of tenants from Application Approval.

Templates are created by hand from this page, and also automatically by the Create Template from App actions on Enterprise Applications and App Registrations.

Page Actions

Add Template opens the App Approval Template form, where you choose the application type and the application, and for enterprise app templates the permission set to grant.

Deploy Template opens Application Approval, where a saved template can be deployed to one or more tenants.

Table Details

Column
Description

Template Name

The name given to the template, used when selecting it for deployment.

App Type

Which kind of deployment the template performs: EnterpriseApp consents a multi-tenant application by its application ID, GalleryTemplate instantiates an application from the Entra application gallery, and ApplicationManifest recreates a single-tenant application from a captured manifest. Templates saved before these types existed have no value here and are treated as enterprise app templates.

App Id

The application (client) ID of the application the template deploys.

App Name

The display name of that application.

Permission Set Name

The permission set whose permissions the template grants. Only enterprise app templates reference one, so the column is empty for gallery and manifest templates, whose permissions come from the gallery consent or from the manifest itself.

Updated By

The CIPP user who last edited the template. This is only stamped when an existing template is saved again, so a template that has never been edited since creation shows nothing here.

Timestamp

When the template was last written.

Table Actions

Action
Description
Bulk Action Available

Edit Template

Opens the selected template in Edit App Approval Template so its application, type and permission set can be changed.

Copy Template

Opens Add App Approval Template with the selected template's settings pre-filled, ready to be saved as a new template.

Save to GitHub

Uploads the selected template(s) to a GitHub repository you have write access to, prompting for the repository and a commit message. Only available when the GitHub integration is enabled.

Delete Template

Deletes the selected template(s), after a confirmation prompt naming the template.

More Info

Opens the Extended Info flyout with the full details for the selected row.

Extended Info Flyout

Alongside the usual row details, the flyout renders a preview of what the template will deploy, which differs by application type:

  • Permission Preview, for enterprise app templates, listing the application and delegated permissions the template grants, grouped by the API that publishes them.

  • Gallery Template Info, for gallery templates, showing the application's description, publisher, categories, and its supported single sign-on and provisioning modes.

  • Application Manifest, for manifest templates, showing the captured sign-in audience, redirect URIs and requested permissions.

Templates are held at partner level rather than per tenant, so this table shows the same rows whichever tenant is selected.


Feature Requests/Ideas

We value your feedback and ideas. Please raise any feature requests on GitHub.

Last updated

Was this helpful?