Mint an Entra client secret for an app registration and vault it, without anyone seeing the value
connections_provision_signing_credentialGive a connected Microsoft app registration a usable CLIENT SECRET and store it in this company's vault, in one server-side act. The point is a machine that can authenticate AS that app without a human holding a credential: the canonical case is Azure Artifact Signing, where a desktop signs an .exe with SignTool and the Artifact Signing dlib, which reads AZURE_TENANT_ID / AZURE_CLIENT_ID / AZURE_CLIENT_SECRET through EnvironmentCredential - no repository, no CI, no az login. Pass appId (the app's public CLIENT id; for signing, the app holding the Artifact Signing Certificate Profile Signer role). The secret lands as its own connected instance (default 'artifact-signing'), and the reply carries the connection name plus the lease shape for handing that secret to a command - the secret's own value is not part of the reply, a log line, or an error. Expiry defaults to 6 months because a standing secret is a standing signing capability; revoke early with graph_remove_application_password and the returned keyId.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| appId | Yes | The app registration's CLIENT id (public). graph_list_applications lists them. | |
| instance | No | Which Microsoft connection to mint THROUGH (see connections_accounts). Defaults to 'default'. | |
| displayName | No | Label Azure shows on the password. Defaults to 'connections-vaulted'. | |
| instanceName | No | Name for the NEW connected instance the secret is stored as. Defaults to 'artifact-signing'. | |
| lifetimeMonths | No | How long the secret lives, 1 to 24. Defaults to 6 - a standing secret is a standing capability. |