Skip to content

Commit c9830d2

Browse files
Update directory-assign-admin-roles.md
Update the description of Directory Readers.
1 parent 25fb827 commit c9830d2

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

articles/active-directory/users-groups-roles/directory-assign-admin-roles.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -166,7 +166,10 @@ This role is available for assignment only as an additional local administrator
166166

167167
### [Directory Readers](#directory-readers-permissions)
168168

169-
This is a role that should be assigned only to legacy applications that do not support the [Consent Framework](../develop/quickstart-v1-integrate-apps-with-azure-ad.md). Don't assign it to users.
169+
Users in this role can read basic directory information. This role should be used for:
170+
* Granting a specific set of guest users read access instead of granting it to all guest users.
171+
* Granting a specific set of non-admin users access to Azure Portal when “Restrict access to Azure AD portal to admins only” is set to “Yes”.
172+
* Granting service principals access to directory where Directory.Read.All is not an option.
170173

171174
### [Directory Synchronization Accounts](#directory-synchronization-accounts-permissions)
172175

0 commit comments

Comments
 (0)