You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
184
-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
183
+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
184
+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
185
185
> | microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials | Read password single sign-on credentials on service principals |
186
186
> | microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin | Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph |
187
187
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
@@ -524,8 +524,8 @@ This role also grants the ability to consent for delegated permissions and appli
524
524
> | microsoft.directory/servicePrincipals/enable | Enable service principals |
525
525
> | microsoft.directory/servicePrincipals/getPasswordSingleSignOnCredentials | Manage password single sign-on credentials on service principals |
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning syncronization jobs |
528
-
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning syncronization jobs and schema |
527
+
> | microsoft.directory/servicePrincipals/synchronizationJobs/manage | Start, restart, and pause application provisioning synchronization jobs |
528
+
> | microsoft.directory/servicePrincipals/synchronizationSchema/manage | Create and manage application provisioning synchronization jobs and schema |
529
529
> | microsoft.directory/servicePrincipals/managePasswordSingleSignOnCredentials | Read password single sign-on credentials on service principals |
530
530
> | microsoft.directory/servicePrincipals/managePermissionGrantsForAll.microsoft-application-admin | Grant consent for application permissions and delegated permissions on behalf of any user or all users, except for application permissions for Microsoft Graph |
531
531
> | microsoft.directory/servicePrincipals/appRoleAssignedTo/update | Update service principal role assignments |
@@ -807,8 +807,8 @@ Users in this role can read and update basic information of users, groups, and s
@@ -977,6 +977,10 @@ Users with this role have access to all administrative features in Azure Active
977
977
> | microsoft.directory/directoryRoles/allProperties/allTasks | Create and delete directory roles, and read and update all properties |
978
978
> | microsoft.directory/directoryRoleTemplates/allProperties/allTasks | Create and delete Azure AD role templates, and read and update all properties |
979
979
> | microsoft.directory/domains/allProperties/allTasks | Create and delete domains, and read and update all properties |
980
+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
> | microsoft.directory/domains/federationConfiguration/create | Create federation configuration for domains |
983
+
> | microsoft.directory/domains/federationConfiguration/delete | Delete federation configuration for domains |
980
984
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Azure AD entitlement management |
981
985
> | microsoft.directory/groups/allProperties/allTasks | Create and delete groups, and read and update all properties |
982
986
> | microsoft.directory/groupsAssignableToRoles/create | Create role-assignable groups |
@@ -1134,6 +1138,7 @@ Users with this role **cannot** do the following:
1134
1138
> | microsoft.directory/directoryRoles/allProperties/read | Read all properties of directory roles |
1135
1139
> | microsoft.directory/directoryRoleTemplates/allProperties/read | Read all properties of directory role templates |
1136
1140
> | microsoft.directory/domains/allProperties/read | Read all properties of domains |
1141
+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
1137
1142
> | microsoft.directory/entitlementManagement/allProperties/read | Read all properties in Azure AD entitlement management |
1138
1143
> | microsoft.directory/groups/allProperties/read | Read all properties (including privileged properties) on Security groups and Microsoft 365 groups, including role-assignable groups |
1139
1144
> | microsoft.directory/groupSettings/allProperties/read | Read all properties of group settings |
@@ -1300,6 +1305,10 @@ Users in this role can create, manage and deploy provisioning configuration setu
1300
1305
> | microsoft.directory/deletedItems.applications/restore | Restore soft deleted applications to original state |
1301
1306
> | microsoft.directory/domains/allProperties/read | Read all properties of domains |
1302
1307
> | microsoft.directory/domains/federation/update | Update federation property of domains |
1308
+
> | microsoft.directory/domains/federationConfiguration/standard/read | Read standard properties of federation configuration for domains |
0 commit comments