Skip to main content

Enterprise Applications

Requires Microsoft Graph (Application.ReadWrite.All, Directory.Read.All for write operations; Application.Read.All is enough for Compare-EnterpriseApplication when comparing two files). For full details and examples, run Get-Help <FunctionName> -Detailed.

These four cmdlets let you clone or diff an Enterprise Application (an Entra Application/App Registration plus its Service Principal) between environments in the same tenant — for example, building a production app from a tested one, or the other way around.

What is/isn't copied
  • Copied: display name, sign-in audience, identifier URIs, notes, tags, redirect URIs (Web/SPA/public client), required resource access (API permissions), app roles, exposed API scopes, owners, and — only when requested — App Role Assignments.
  • Never copied: client secrets and certificates. Microsoft Graph never returns their values, so Nebula.Core can only capture and report their metadata (display name, key ID, expiry). You must create new credentials on the destination app yourself after cloning it.

Export-EnterpriseApplication​

Read a source Enterprise Application and write a normalized JSON snapshot to disk.

Syntax

Export-EnterpriseApplication -ApplicationName <String> -OutputPath <String> [-IncludeAppRoleAssignments] [-Force]
Export-EnterpriseApplication -ApplicationId <String> -OutputPath <String> [-IncludeAppRoleAssignments] [-Force]
ParameterTypeDescriptionRequiredDefault
ApplicationNameStringDisplay name of the source Enterprise Application.Yes*-
ApplicationIdStringObject ID of the source Application (use instead of ApplicationName).Yes*-
OutputPathStringDestination JSON file path.Yes-
IncludeAppRoleAssignmentsSwitchAlso export App Role Assignments (users/groups assigned to the app).NoFalse
ForceSwitchOverwrite OutputPath if it already exists.NoFalse

*Use ApplicationName or ApplicationId.

Examples

Export-EnterpriseApplication -ApplicationName "Contoso Test App" -OutputPath .\contoso-test-app.json
Export-EnterpriseApplication -ApplicationName "Contoso Test App" -OutputPath .\contoso-test-app.json -IncludeAppRoleAssignments -Force

Import-EnterpriseApplication​

Create or update an Enterprise Application from a JSON snapshot file produced by Export-EnterpriseApplication. If no app with -TargetDisplayName exists it is created; if it exists, it is updated in place.

Syntax

Import-EnterpriseApplication -InputPath <String> -TargetDisplayName <String> [-IncludeAppRoleAssignments] [-PassThru] [-WhatIf] [-Confirm]
ParameterTypeDescriptionRequiredDefault
InputPathStringPath to the JSON snapshot file.Yes-
TargetDisplayNameStringDisplay name of the destination Enterprise Application.Yes-
IncludeAppRoleAssignmentsSwitchAlso apply App Role Assignments captured in the snapshot.NoFalse
PassThruSwitchEmit the apply-result summary object.NoFalse

Examples

Import-EnterpriseApplication -InputPath .\contoso-test-app.json -TargetDisplayName "Contoso Prod App"
Import-EnterpriseApplication -InputPath .\contoso-test-app.json -TargetDisplayName "Contoso Prod App" -IncludeAppRoleAssignments -PassThru
No credentials are created

The destination app will have no client secret or certificate after import — it cannot authenticate anywhere until you create one for it (Portal, Update-MgApplication, or your own automation).

Copy-EnterpriseApplication​

Clone a source Enterprise Application directly into a new or existing destination, in one step, without writing an intermediate file. Equivalent to Export-EnterpriseApplication followed by Import-EnterpriseApplication, done in memory.

Syntax

Copy-EnterpriseApplication -SourceApplicationName <String> -TargetDisplayName <String> [-IncludeAppRoleAssignments] [-PassThru] [-WhatIf] [-Confirm]
Copy-EnterpriseApplication -SourceApplicationId <String> -TargetDisplayName <String> [-IncludeAppRoleAssignments] [-PassThru] [-WhatIf] [-Confirm]
ParameterTypeDescriptionRequiredDefault
SourceApplicationNameStringDisplay name of the source Enterprise Application.Yes*-
SourceApplicationIdStringObject ID of the source Application (use instead of SourceApplicationName).Yes*-
TargetDisplayNameStringDisplay name of the destination Enterprise Application. Created if missing, updated if it exists.Yes-
IncludeAppRoleAssignmentsSwitchAlso copy App Role Assignments (users/groups assigned to the app).NoFalse
PassThruSwitchEmit the apply-result summary object.NoFalse

*Use SourceApplicationName or SourceApplicationId.

Examples

Copy-EnterpriseApplication -SourceApplicationName "Contoso Test App" -TargetDisplayName "Contoso Prod App"
Copy-EnterpriseApplication -SourceApplicationName "Contoso Test App" -TargetDisplayName "Contoso Prod App" -IncludeAppRoleAssignments -PassThru

Compare-EnterpriseApplication​

Diff two Enterprise Applications — each side can independently be a JSON snapshot file or a live application looked up by name/ID. Returns the differing properties on the pipeline, and can optionally write a JSON or CSV report.

Syntax

Compare-EnterpriseApplication (-ReferencePath <String> | -ReferenceApplicationName <String> | -ReferenceApplicationId <String>) (-DifferencePath <String> | -DifferenceApplicationName <String> | -DifferenceApplicationId <String>) [-IncludeAppRoleAssignments] [-OutputReportPath <String>] [-PassThru]
ParameterTypeDescriptionRequiredDefault
ReferencePathStringJSON snapshot file for the reference ("A") side.Yes**-
ReferenceApplicationNameStringDisplay name of a live application for the reference side.Yes**-
ReferenceApplicationIdStringObject ID of a live application for the reference side.Yes**-
DifferencePathStringJSON snapshot file for the difference ("B") side.Yes**-
DifferenceApplicationNameStringDisplay name of a live application for the difference side.Yes**-
DifferenceApplicationIdStringObject ID of a live application for the difference side.Yes**-
IncludeAppRoleAssignmentsSwitchAlso compare App Role Assignments.NoFalse
OutputReportPathStringOptional report file. Written as JSON if the path ends in .json, otherwise as CSV.No-
PassThruSwitchAccepted for symmetry with the other cmdlets; diff rows are always returned regardless.NoFalse

**Use exactly one of the three Reference parameters, and exactly one of the three Difference parameters. Comparing two files requires no Microsoft Graph connection at all.

Examples

Compare-EnterpriseApplication -ReferencePath .\contoso-test-app.json -DifferenceApplicationName "Contoso Prod App"
Compare-EnterpriseApplication -ReferenceApplicationName "Contoso Test App" -DifferenceApplicationName "Contoso Prod App" -OutputReportPath .\diff.csv
Compare-EnterpriseApplication -ReferencePath .\before.json -DifferencePath .\after.json -OutputReportPath .\diff.json
Secrets/certificates in the report

Compare-EnterpriseApplication reports credential metadata (expiry, key ID) as ordinary diff rows so you can spot an expiring or missing secret between environments — it never compares or reports the secret/certificate values themselves, since Graph doesn't expose them.