Skip to content

Commit 486a83d

Browse files
committed
Weekly Permissions sync 2026-03-31
1 parent 095864f commit 486a83d

2 files changed

Lines changed: 188 additions & 102 deletions

File tree

permissions/new/permissions.json

Lines changed: 124 additions & 70 deletions
Original file line numberDiff line numberDiff line change
@@ -3491,8 +3491,8 @@
34913491
"privilegeLevel": 3
34923492
},
34933493
"Application": {
3494-
"adminDisplayName": "",
3495-
"adminDescription": "",
3494+
"adminDisplayName": "Read the trusted certificate authority configuration for applications",
3495+
"adminDescription": "Allows the app to read the trusted certificate authority configuration which can be used to restrict application certificates based on their issuing authority, without a signed-in user.",
34963496
"requiresAdminConsent": true,
34973497
"privilegeLevel": 4
34983498
}
@@ -3504,50 +3504,12 @@
35043504
"Application"
35053505
],
35063506
"methods": [
3507-
"PATCH"
3508-
],
3509-
"paths": {
3510-
"/certificateauthoritypath/certificatebasedapplicationconfigurations/{id}": "least=DelegatedWork,Application"
3511-
}
3512-
},
3513-
{
3514-
"schemeKeys": [
3515-
"DelegatedWork",
3516-
"Application"
3517-
],
3518-
"methods": [
3519-
"GET",
3520-
"POST"
3521-
],
3522-
"paths": {
3523-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations": "least=DelegatedWork,Application",
3524-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities": "least=DelegatedWork,Application"
3525-
}
3526-
},
3527-
{
3528-
"schemeKeys": [
3529-
"DelegatedWork",
3530-
"Application"
3531-
],
3532-
"methods": [
3533-
"DELETE",
35343507
"GET"
35353508
],
35363509
"paths": {
3537-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}": "least=DelegatedWork,Application"
3538-
}
3539-
},
3540-
{
3541-
"schemeKeys": [
3542-
"DelegatedWork",
3543-
"Application"
3544-
],
3545-
"methods": [
3546-
"DELETE",
3547-
"GET",
3548-
"PATCH"
3549-
],
3550-
"paths": {
3510+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations": "least=DelegatedWork,Application",
3511+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}": "least=DelegatedWork,Application",
3512+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities": "least=DelegatedWork,Application",
35513513
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities/{id}": "least=DelegatedWork,Application"
35523514
}
35533515
}
@@ -3568,8 +3530,8 @@
35683530
"privilegeLevel": 3
35693531
},
35703532
"Application": {
3571-
"adminDisplayName": "",
3572-
"adminDescription": "",
3533+
"adminDisplayName": "Read and write the trusted certificate authority configuration for applications",
3534+
"adminDescription": "Allows the app to create, read, update and delete the trusted certificate authority configuration which can be used to restrict application certificates based on their issuing authority, without a signed-in user.",
35733535
"requiresAdminConsent": true,
35743536
"privilegeLevel": 4
35753537
}
@@ -3581,24 +3543,13 @@
35813543
"Application"
35823544
],
35833545
"methods": [
3584-
"PATCH"
3585-
],
3586-
"paths": {
3587-
"/certificateauthoritypath/certificatebasedapplicationconfigurations/{id}": ""
3588-
}
3589-
},
3590-
{
3591-
"schemeKeys": [
3592-
"DelegatedWork",
3593-
"Application"
3594-
],
3595-
"methods": [
3596-
"GET",
3597-
"POST"
3546+
"GET"
35983547
],
35993548
"paths": {
36003549
"/directory/certificateauthorities/certificatebasedapplicationconfigurations": "",
3601-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities": ""
3550+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}": "",
3551+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities": "",
3552+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities/{id}": ""
36023553
}
36033554
},
36043555
{
@@ -3607,11 +3558,11 @@
36073558
"Application"
36083559
],
36093560
"methods": [
3610-
"DELETE",
3611-
"GET"
3561+
"POST"
36123562
],
36133563
"paths": {
3614-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}": ""
3564+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations": "least=DelegatedWork,Application",
3565+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities": "least=DelegatedWork,Application"
36153566
}
36163567
},
36173568
{
@@ -3621,11 +3572,11 @@
36213572
],
36223573
"methods": [
36233574
"DELETE",
3624-
"GET",
36253575
"PATCH"
36263576
],
36273577
"paths": {
3628-
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities/{id}": ""
3578+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}": "least=DelegatedWork,Application",
3579+
"/directory/certificateauthorities/certificatebasedapplicationconfigurations/{id}/trustedcertificateauthorities/{id}": "least=DelegatedWork,Application"
36293580
}
36303581
}
36313582
],
@@ -5098,11 +5049,11 @@
50985049
"/reports/conditionalaccess/protectedapps": "least=DelegatedWork,Application",
50995050
"/reports/conditionalaccess/securityalerts": "least=DelegatedWork,Application",
51005051
"/reports/conditionalaccess/unprotectedapps": "least=DelegatedWork,Application",
5052+
"/reports/correlations": "",
5053+
"/reports/correlations/{id}": "",
5054+
"/reports/correlations/{id}/identities": "",
5055+
"/reports/correlations/{id}/identities/{id}": "",
51015056
"/reports/getAppManagementAuditSummary": "least=DelegatedWork,Application",
5102-
"/reports/identityCorrelation": "least=DelegatedWork,Application",
5103-
"/reports/identityCorrelation/{id}": "least=DelegatedWork,Application",
5104-
"/reports/identityCorrelation/{id}/identities": "least=DelegatedWork,Application",
5105-
"/reports/identityCorrelation/{id}/identities/{id}": "least=DelegatedWork,Application",
51065057
"/reports/reconciliations/provisioning": "least=DelegatedWork,Application",
51075058
"/reports/reconciliations/provisioning/{id}": "least=DelegatedWork,Application",
51085059
"/reports/reconciliations/provisioning/{id}/identities": "least=DelegatedWork,Application",
@@ -23099,6 +23050,105 @@
2309923050
"ownerSecurityGroup": "igaelmlivesite"
2310023051
}
2310123052
},
23053+
"EntraBackup.Read.All": {
23054+
"authorizationType": "oAuth2",
23055+
"schemes": {
23056+
"DelegatedWork": {
23057+
"adminDisplayName": "Read Preview jobs and snapshots",
23058+
"adminDescription": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on behalf of the signed-in user.",
23059+
"userDisplayName": "Read Preview jobs and snapshots",
23060+
"userDescription": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on your behalf.",
23061+
"requiresAdminConsent": true,
23062+
"privilegeLevel": 4
23063+
},
23064+
"Application": {
23065+
"adminDisplayName": "Read Preview jobs and snapshots",
23066+
"adminDescription": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on behalf of the signed-in user.",
23067+
"userDisplayName": "Read Preview jobs and snapshots",
23068+
"userDescription": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on your behalf.",
23069+
"requiresAdminConsent": true,
23070+
"privilegeLevel": 4
23071+
}
23072+
},
23073+
"pathSets": [
23074+
{
23075+
"schemeKeys": [
23076+
"DelegatedWork",
23077+
"Application"
23078+
],
23079+
"methods": [
23080+
"GET"
23081+
],
23082+
"paths": {
23083+
"/directory/recovery/snapshots": "least=Application,DelegatedWork",
23084+
"/directory/recovery/snapshots/{id}": "least=Application,DelegatedWork",
23085+
"/directory/recovery/snapshots/{id}/recoveryJobs/{id}/getFailedChanges": "least=Application,DelegatedWork",
23086+
"/directory/recovery/snapshots/{id}/recoveryPreviewJobs/{id}/getChanges": "least=Application,DelegatedWork"
23087+
}
23088+
}
23089+
],
23090+
"ownerInfo": {
23091+
"ownerSecurityGroup": "xtenantex"
23092+
}
23093+
},
23094+
"EntraBackup.ReadWrite.Preview": {
23095+
"authorizationType": "oAuth2",
23096+
"schemes": {
23097+
"DelegatedWork": {
23098+
"adminDisplayName": "Create a preview job, read preview job and snapshots",
23099+
"adminDescription": "Allows the app to list the all the snapshots, create a preview job and enumerate the changes of a specific preview job, on behalf of the signed-in user.",
23100+
"userDisplayName": "Create a preview job, read preview job and snapshots",
23101+
"userDescription": "Allows the app to list the all the snapshots, create a preview job and enumerate the changes of a specific preview job, on your behalf.",
23102+
"requiresAdminConsent": true,
23103+
"privilegeLevel": 4
23104+
}
23105+
},
23106+
"pathSets": [
23107+
{
23108+
"schemeKeys": [
23109+
"DelegatedWork"
23110+
],
23111+
"methods": [
23112+
"POST"
23113+
],
23114+
"paths": {
23115+
"/directory/recovery/snapshots/{id}/recoveryPreviewJobs": "least=DelegatedWork"
23116+
}
23117+
}
23118+
],
23119+
"ownerInfo": {
23120+
"ownerSecurityGroup": "xtenantex"
23121+
}
23122+
},
23123+
"EntraBackup.ReadWrite.Recovery": {
23124+
"authorizationType": "oAuth2",
23125+
"schemes": {
23126+
"DelegatedWork": {
23127+
"adminDisplayName": "Create preview and recovery job, read recovery job and snapshots",
23128+
"adminDescription": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.",
23129+
"userDisplayName": "Create preview and recovery job, read recovery job and snapshots",
23130+
"userDescription": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on your behalf.",
23131+
"requiresAdminConsent": true,
23132+
"privilegeLevel": 4
23133+
}
23134+
},
23135+
"pathSets": [
23136+
{
23137+
"schemeKeys": [
23138+
"DelegatedWork"
23139+
],
23140+
"methods": [
23141+
"POST"
23142+
],
23143+
"paths": {
23144+
"/directory/recovery/snapshots/{id}/recoveryJobs": "least=DelegatedWork"
23145+
}
23146+
}
23147+
],
23148+
"ownerInfo": {
23149+
"ownerSecurityGroup": "xtenantex"
23150+
}
23151+
},
2310223152
"EventListener.Read.All": {
2310323153
"authorizationType": "oAuth2",
2310423154
"schemes": {
@@ -42074,7 +42124,11 @@
4207442124
"GET"
4207542125
],
4207642126
"paths": {
42077-
"/auditlogs/provisioning": "least=DelegatedWork"
42127+
"/auditlogs/provisioning": "least=DelegatedWork",
42128+
"/reports/correlations": "least=DelegatedWork",
42129+
"/reports/correlations/{id}": "least=DelegatedWork",
42130+
"/reports/correlations/{id}/identities": "least=DelegatedWork",
42131+
"/reports/correlations/{id}/identities/{id}": "least=DelegatedWork"
4207842132
}
4207942133
}
4208042134
],

0 commit comments

Comments
 (0)