Owners
The Owners section is available in the application detail view for both App Registrations and Enterprise Applications. It provides a single page to view and manage all ownership assignments for the selected application.
The page is divided into three separated sections, following the same visual structure and interaction pattern:
- Business Owners
- Technical Owners
- Application Owners
Each of these sections contains a list of users and/or service principals that are assigned an ownership role, and they are sortable by name.
Adding an owner
To add an owner, click on the "+" sign in the upper-right corner of the table. A side panel will show up where users can be searched and selected. Once you have selected the user, click the "Let's do it" button to assign them the role.
Removing an owner
Owners can be removed individually by clicking on the trash can icon in the corresponding row. Before the actual deletion, a confirmation modal is shown to prevent users to delete owners by mistake.
When a removal is refused
An application must keep the number of owners that its assigned policy requires. EasyLife 365 Identity refuses any removal that would take the application below that minimum, for application owners, technical owners and business owners alike.
- While a section is already at its minimum, the trash can icon in that section is disabled. Hovering it explains why: The policy requires at least N owners. Remove one only after adding a replacement.
- If a removal still reaches the service, for example from a script calling the API, the service refuses it. The App reports the refusal in an error message: This app has to keep a minimum number of owners. Removing this one would take it below that minimum. The owner stays in place.
To replace an owner, add the new owner first, then remove the old one.
Owners that never counted towards the minimum are not protected by this rule. The service still accepts their removal even when the application is already short of owners. This applies to service principals listed as application owners, and to security groups, Microsoft 365 groups and guest accounts listed as technical or business owners. See Which owners count.
The page is stricter than the service here: while a section is at its minimum, its trash can icons are disabled for every entry in that section, including the entries that do not count.