Good question, this is admittedly misleading. The answer is yes - any web client registered with your Azure AD agent can receive a token for accessing the web API using the client credential stream described in the sample code.
If you do not want this behavior, you have 2 options:
- -API, (. ). - , "admin" , "full_access". -API . , Azure AD , , .
- - - ACL . appid .
scope. API , API ( ), ( ). .
, , scopeClaim == null. ClaimTypes.NameIdentifier (a.k.a. the sub) POST GET todo, .
, Azure AD -API .
, .