Why Choose AppTesting?
AppTesting provides all the powerful testing and analysis capabilities of AppConfig, but operates in read-only mode. Perfect for organizations that require configuration changes to be made through the official Entra portal while still needing comprehensive troubleshooting tools.
Compliance Ready
Meets strict organizational policies requiring configuration changes through official Entra portal only.
Full Analysis Power
Identical testing and troubleshooting capabilities to AppConfig without the ability to modify configurations.
Safe Operation
Analyze, test, and troubleshoot with confidence knowing no accidental configuration changes can occur.
Comprehensive Testing & Analysis Capabilities
Authentication Flow Testing
Test OAuth2, OpenID Connect, and SAML flows with comprehensive token analysis.
Token Decoding & Analysis
Decode and inspect JWT tokens, ID tokens, and access tokens in real-time.
Permission Analysis
Comprehensive API permission analysis and security risk assessment.
Conditional Access Insights
View applied conditional access policies and their impact on authentication.
Graph Explorer Integration
Embedded Microsoft Graph capabilities for deep application analysis.
User Context Testing
Test authentication flows as different users to validate application behavior.
App Role Analysis
Analyze application roles and their assignments without modification capabilities.
Claims Mapping Review
View and analyze claims mapping policies applied to applications.
Session Management Info
Analyze token lifetimes and session management configurations.
What AppTesting Does NOT Include
AppTesting is designed for analysis and testing only. The following configuration capabilities are exclusive to AppConfig:
Configuration Changes Disabled
- • Redirect URI modifications
- • App role creation/deletion
- • API permission changes
- • Optional claims configuration
- • Client secret generation
Management Functions Disabled
- • User provisioning/deprovisioning
- • Application manifest editing
- • Claims mapping policy creation
- • API exposure configuration
- • Backup and restore functions
Need configuration capabilities? Explore AppConfig for full management features.
AppTesting vs AppConfig Comparison
| Capability | AppTesting | AppConfig |
|---|---|---|
| SHARED ANALYSIS & TESTING FEATURES | ||
| Authentication Flow Testing | ||
| Token Analysis & Decoding | ||
| Permission & Attack Surface Analysis | ||
| Graph Explorer & OData Queries | ||
| OAuth Testing & Token Scope Requester | ||
| Service Principal Overview & Certificate Monitoring | ||
| APPCONFIG-ONLY CONFIGURATION FEATURES | ||
| App Configuration & Redirect URI Management | ||
| App Roles & Client Secret Generation | ||
| Claims Mapping & Directory Extensions | ||
| User Provisioning and Token Configuration | ||
| API Exposure Configuration | ||
| Backup & Restore with Lifecycle Management | ||
Perfect for These Scenarios
Strict Change Control
Organizations with policies requiring all configuration changes through official portals only.
Level 2/3 Support
Support teams needing powerful troubleshooting tools without configuration modification risks.
Security Auditing
Security teams performing application analysis and compliance verification without modification capabilities.
Developer Testing
Developers who need to test applications in environments where they don't have configuration permissions.
Compliance Requirements
Industries with regulatory requirements for read-only access to production environments.
Training & Learning
Educational environments where users need to learn without risk of making unintended changes.
Ready to Start Testing?
Get comprehensive Microsoft Entra™ testing capabilities without configuration risks
Request Early Access Compare with AppConfigQuestions About AppTesting?
Want to learn more about read-only testing capabilities? Get in touch with our team.