organizations — works for any work/school account across all tenants.
51fb1b02-5c75-445f-9225-807e50623cd422720fe1-6437-4a23-819c-55cd6e69c7f32269e636-3dc1-46aa-aff6-0b4a40cc31bad7e8c2c2-4dee-4a43-b04a-a80ceab0417b app permissionaud = this resource ID, proving they are authorized to access it.
https://adapps.mavimcloud.com/mavim.cloud.identity.core
—
—
—
—
api.access is an Application-type permission used by daemon/backend services with a client secret — a browser SPA cannot acquire it in a token.aud = this client ID is the verification.
The api.access admin consent status must be verified separately (e.g. via Graph API or the Azure Portal).
—
—