Setting Up an App Registration for OSDU
This guide covers how to create and configure an app registration in Microsoft Entra ID to communicate with the OSDU Data Platform (ADME).
1. Create an app registration
Register a new application in the Azure Portal, or reuse an existing one if your team already has one.
Tip
To create an app registration, you need the Application Developer role. Apply for it in AccessIT if you don't already have it.
See the Omnia documentation for general guidance on creating app registrations at Equinor.
2. Add the ADME API permission
Your app registration needs an API permission to communicate with ADME.
For delegated access (authorization code flow — App + User)
Use this if your app signs in as a user (e.g. a web app or CLI tool that prompts for login).
- Go to your app registration in the Azure Portal → API permissions
- Click Add a permission → APIs my organization uses
- Search for "Azure Data Manager for Energy"
- Select the one with client ID
bd0c9d90-89ad-4bb3-97bc-d787b9f69cdc - Choose Delegated permissions → select
access_as_user→ Add permissions - Request admin consent by emailing AADAppConsent@equinor.com with your app registration name and client ID
- Wait for admin consent to be granted before using the new scope
Admin consent is required
The access_as_user permission requires admin consent. Without it, Entra ID will show an "Approval required" page when users try to sign in. Email AADAppConsent@equinor.com to request consent.
Once consent is granted, update your old scope with the new one — New Scope: https://energy.azure.com/.default
If you previously had user_impersonation on the old per-instance resource (dffa82c7-...), you can remove it for all environments (Development, Test, and Production). See the Entra ID Migration Checklist for details.
For application access (client credentials flow — App only)
Use this if your app authenticates as itself without a user (e.g. a pipeline or background service).
All environments now use the new unified scope for client credentials.
| Environment | Scope |
|---|---|
| Development | https://energy.azure.com/.default |
| Test | https://energy.azure.com/.default |
| Production | https://energy.azure.com/.default |
See How to Connect to a Specific Environment for code examples using these scopes.
Your app registration's service principal must also be added directly as a member of the required OSDU entitlement groups. See the Platform Access guide for how to request read or write access for your application.
3. Configure authentication
Add a redirect URI under Authentication in your app registration:
- For local development:
http://localhost:<port>(e.g.http://localhost:53100) - For web apps: your application's callback URL
If using client credentials flow, create a client secret or certificate under Certificates & secrets.
4. Request platform access
Once your app registration is set up, request the access level you need for each environment. See the Platform Access guide for detailed instructions on requesting read or write access.
Access is per environment
You need to submit a separate request for each environment (Development, Test, Production).
Need help?
If you're unsure about any of these steps, contact the OSDU Platform Team: