You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is a role that should be assigned only to legacy applications that do not support the [Consent Framework](../develop/quickstart-v1-integrate-apps-with-azure-ad.md). Don't assign it to users.
169
+
Users in this role can read basic directory information. This role should be used for:
170
+
* Granting a specific set of guest users read access instead of granting it to all guest users.
171
+
* Granting a specific set of non-admin users access to Azure Portal when “Restrict access to Azure AD portal to admins only” is set to “Yes”.
172
+
* Granting service principals access to directory where Directory.Read.All is not an option.
0 commit comments