Skip to content

Commit a1a4000

Browse files
authored
Adds minimal permission for entra user commands. Closes #6955
1 parent bc4a13b commit a1a4000

6 files changed

Lines changed: 109 additions & 0 deletions

File tree

docs/docs/cmd/entra/user/user-groupmembership-list.mdx

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,25 @@ m365 entra user groupmembership list [options]
3030

3131
<Global />
3232

33+
## Permissions
34+
35+
<Tabs>
36+
<TabItem value="Delegated">
37+
38+
| Resource | Permissions |
39+
|-----------------|------------------------------------------|
40+
| Microsoft Graph | User.ReadBasic.All, GroupMember.Read.All |
41+
42+
</TabItem>
43+
<TabItem value="Application">
44+
45+
| Resource | Permissions |
46+
|-----------------|------------------------------------------|
47+
| Microsoft Graph | User.ReadBasic.All, GroupMember.Read.All |
48+
49+
</TabItem>
50+
</Tabs>
51+
3352
## Examples
3453

3554
Retrieves groups that the user is a member of

docs/docs/cmd/entra/user/user-guest-add.mdx

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,25 @@ m365 entra user guest add [options]
3939

4040
<Global />
4141

42+
## Permissions
43+
44+
<Tabs>
45+
<TabItem value="Delegated">
46+
47+
| Resource | Permissions |
48+
|-----------------|-----------------|
49+
| Microsoft Graph | User.Invite.All |
50+
51+
</TabItem>
52+
<TabItem value="Application">
53+
54+
| Resource | Permissions |
55+
|-----------------|-----------------|
56+
| Microsoft Graph | User.Invite.All |
57+
58+
</TabItem>
59+
</Tabs>
60+
4261
## Examples
4362

4463
Invite a user via email and set the display name.

docs/docs/cmd/entra/user/user-password-validate.mdx

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,18 @@ This command is based on an API that is currently in preview and is subject to c
2929

3030
:::
3131

32+
## Permissions
33+
34+
<Tabs>
35+
<TabItem value="Delegated">
36+
37+
| Resource | Permissions |
38+
|-----------------|----------------|
39+
| Microsoft Graph | User.ReadWrite |
40+
41+
</TabItem>
42+
</Tabs>
43+
3244
## Examples
3345

3446
Validate password _cli365P@ssW0rd_ against the organization's password validation policy.

docs/docs/cmd/entra/user/user-registrationdetails-list.mdx

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,6 +77,25 @@ When multiple values are specified for `--registeredMethods` option, the command
7777

7878
:::
7979

80+
## Permissions
81+
82+
<Tabs>
83+
<TabItem value="Delegated">
84+
85+
| Resource | Permissions |
86+
|-----------------|-------------------|
87+
| Microsoft Graph | AuditLog.Read.All |
88+
89+
</TabItem>
90+
<TabItem value="Application">
91+
92+
| Resource | Permissions |
93+
|-----------------|-------------------|
94+
| Microsoft Graph | AuditLog.Read.All |
95+
96+
</TabItem>
97+
</Tabs>
98+
8099
## Examples
81100

82101
Retrieve registration details for all users.

docs/docs/cmd/entra/user/user-session-revoke.mdx

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
11
import Global from '../../_global.mdx';
2+
import Tabs from '@theme/Tabs';
3+
import TabItem from '@theme/TabItem';
24

35
# entra user session revoke
46

@@ -40,6 +42,25 @@ This API doesn't revoke sign-in sessions for external users, because external us
4042

4143
:::
4244

45+
## Permissions
46+
47+
<Tabs>
48+
<TabItem value="Delegated">
49+
50+
| Resource | Permissions |
51+
|-----------------|-------------------------|
52+
| Microsoft Graph | User.RevokeSessions.All |
53+
54+
</TabItem>
55+
<TabItem value="Application">
56+
57+
| Resource | Permissions |
58+
|-----------------|-------------------------|
59+
| Microsoft Graph | User.RevokeSessions.All |
60+
61+
</TabItem>
62+
</Tabs>
63+
4364
## Examples
4465

4566
Revoke sign-in sessions of a user specified by id

docs/docs/cmd/entra/user/user-signin-list.mdx

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,25 @@ m365 entra user signin list [options]
3030

3131
<Global />
3232

33+
## Permissions
34+
35+
<Tabs>
36+
<TabItem value="Delegated">
37+
38+
| Resource | Permissions |
39+
|-----------------|-------------------|
40+
| Microsoft Graph | AuditLog.Read.All |
41+
42+
</TabItem>
43+
<TabItem value="Application">
44+
45+
| Resource | Permissions |
46+
|-----------------|-------------------|
47+
| Microsoft Graph | AuditLog.Read.All |
48+
49+
</TabItem>
50+
</Tabs>
51+
3352
## Examples
3453

3554
Get all user's sign-ins in your tenant.

0 commit comments

Comments
 (0)