This application client id of the Azure Application that is used by Active Roles to access a tenant can be queried using the following cmdlet in the Active Roles Management Shell:
(Get-QADObject -Type edsAzureTenant -SearchRoot "CN=Azure Tenants,CN=Azure Configuration,CN=Azure,CN=Configuration" -Proxy -IncludedProperties edsaazureclientid).edsaazureclientid