Attempting to use Get-AzureADServiceAppRoleAssignment to retrieve the Users and Groups of a Enterprise Application with a Service Principal instead returns API permissions of the associated App registration
A colleague of mine recently reached out to me to ask why my script from this post: PowerShell script to assign users in an on-premise AD group to an Azure Enterprise Application’s Users and Groups