Disable AAD Applications
Overview
The Disable AAD Applications action switches all enabled Microsoft Entra (Azure Active Directory) application registrations to Disabled. It is intended to be run right after a sandbox is refreshed from production, so external integrations stop authenticating against the new environment.
How It Works
- Available from the Admin Hub via the Disable AAD Applications action.
- Lets you choose to disable AAD applications across all companies or only the current company.
- Includes a safeguard that blocks execution in production environments.
- Restricted to users on the Allowed Users list.
Important: This action cannot be run in a Production environment. The corresponding Disable AAD Applications report is intentionally not part of the standard Elevate Admin permission sets — assign it explicitly to the administrators who need to run it, and only on non-production environments.
User Guide
- Open the Admin Hub in Business Central.
- Click the Disable AAD Applications action in the ribbon.
- Fill in the request page:
| Field | Description |
|---|---|
| Disable AAD Applications | Switch all enabled Azure AD application registrations to Disabled. |
| Run For | Scope of the operation — All Companies or Current Company. |
- Click OK to run the process.
- A confirmation message appears when the process completes.
Recommended workflow after a sandbox refresh
- Run Update Company Information to apply a sandbox prefix and badge.
- Run Disable AAD Applications to stop production integrations from connecting.
- Sign out and back in to confirm the new badge and that integrations are no longer authenticating.