GUIDE 2 • AUTHENTICATION

Get credentials for Store Submission Manager

Register a Microsoft Entra application, create a client credential, give the application access to Partner Center, and enter the resulting values in the app.

Store Submission Manager uses the Microsoft identity platform's application-only flow. You need a directory tenant ID, an application client ID, and either a registered certificate or a client-secret value.

Video walkthrough placeholder The ShipToStore YouTube video will be embedded here.

1. Confirm the account and tenant

Use the Microsoft Entra tenant associated with the Partner Center account that owns the Store products you want to manage. You may need a Partner Center Owner or Manager and a Microsoft Entra administrator to complete every step.

  • Sign in to Partner Center and confirm that the expected publisher account is selected.
  • Confirm which Microsoft Entra directory is associated with that account.
  • Ask the appropriate administrators to perform or approve steps you cannot access.
Screenshot placeholder Partner Center account and tenant association.

2. Register a Microsoft Entra application

  1. Open the Microsoft Entra admin center.
  2. Go to Applications > App registrations and select New registration.
  3. Enter a recognizable name such as Store Submission Manager.
  4. Select accounts in your organizational directory only unless your administrator requires a different configuration.
  5. Leave the redirect URI empty; the client-credentials flow does not use an interactive redirect.
  6. Select Register.
Screenshot placeholder Microsoft Entra app registration.

3. Record the tenant ID and client ID

On the application's Overview page, copy the two IDs. They map directly to the login fields:

Directory (tenant) ID Tenant ID in Store Submission Manager
Application (client) ID Client ID in Store Submission Manager
Secret value or certificate Selected authentication credential

Do not use the object ID in place of the client ID. These identifiers are not passwords, but you should still store your configuration carefully.

4. Create a client credential

Recommended: certificate

Certificates avoid copying a reusable secret into the app. Create or obtain an RSA certificate with a private key, install it in the Windows Current User or Local Machine certificate store, and upload the public certificate to the Entra application under Certificates & secrets > Certificates.

In Store Submission Manager, choose Client certificate, select the matching Windows certificate, and use Test before connecting.

Alternative: client secret

  1. Open Certificates & secrets > Client secrets.
  2. Select New client secret, enter a description, and choose an expiration.
  3. Select Add.
  4. Copy the secret's Value immediately. Do not copy the Secret ID.
  5. Store the value securely and record its expiration date for rotation.
Screenshot placeholder Certificate upload and client-secret value.

5. Give the application Partner Center access

  1. Open Partner Center.
  2. Go to Account settings > User management.
  3. Open the Microsoft Entra applications tab.
  4. Add the existing Entra application you registered.
  5. Assign the Manager role required to manage Store submissions, then save.

If the application is missing from the picker, verify that Partner Center and the app registration use the same Microsoft Entra tenant.

Screenshot placeholder Partner Center Microsoft Entra application and Manager role.

6. Connect Store Submission Manager

  1. Enter the directory tenant ID and application client ID.
  2. Select client certificate or client secret and provide the matching credential.
  3. Choose whether the encrypted connection details should be remembered on this Windows account.
  4. Select Connect.

An authentication error usually means an ID, secret value, certificate, or expiration is incorrect. A forbidden response usually means the Entra application has not been added to the correct Partner Center account or does not have the required role.

Keep credentials secure

  • Prefer a certificate for long-lived or production access.
  • Never share a client-secret value in screenshots, support requests, source control, or chat.
  • Rotate credentials before expiration and remove credentials that are no longer used.
  • Remove the Entra application's Partner Center role when access is no longer required.

For current platform details, see Microsoft's Partner Center Entra application guide and credential-management guide.