From f527de261819bdf01a393b91e5bd63c8ab03ed47 Mon Sep 17 00:00:00 2001 From: David <1511024+marabooy@users.noreply.github.com> Date: Fri, 25 Sep 2026 03:57:33 +0300 Subject: [PATCH] Weekly Permissions sync 2026-09-25 --- permissions/new/permissions.json | 303 ++++++++++++++++++++++++++ permissions/new/provisioningInfo.json | 42 ++-- 2 files changed, 322 insertions(+), 23 deletions(-) diff --git a/permissions/new/permissions.json b/permissions/new/permissions.json index c15c4b5e..f33f9b4d 100644 --- a/permissions/new/permissions.json +++ b/permissions/new/permissions.json @@ -1392,6 +1392,18 @@ "paths": { "/servicePrincipals/microsoft.graph.agentIdentity": "" } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "POST" + ], + "paths": { + "/servicePrincipals/microsoft.graph.agentIdentity/{id}/microsoft.graph.identityGovernance.extend": "least=Application,DelegatedWork" + } } ], "ownerInfo": { @@ -1953,6 +1965,18 @@ "paths": { "/servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipal": "" } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "POST" + ], + "paths": { + "/servicePrincipals/microsoft.graph.agentIdentityBlueprintPrincipal/{id}/microsoft.graph.identityGovernance.extend": "least=Application,DelegatedWork" + } } ], "ownerInfo": { @@ -12673,6 +12697,7 @@ "/admin/configurationManagement/configurationSnapshots/{id}": "least=DelegatedWork,Application", "/admin/configurationManagement/configurationTemplates": "least=DelegatedWork,Application", "/admin/configurationManagement/configurationTemplates/{id}": "least=DelegatedWork,Application", + "/admin/configurationManagement/configurationTemplates/{id}/versions/{version}/referencedExternalMonitors/{tenantId}": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs/{id}": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs/{id}/results": "least=DelegatedWork,Application", @@ -12761,6 +12786,7 @@ "/admin/configurationManagement/configurationSnapshots/{id}": "", "/admin/configurationManagement/configurationTemplates": "", "/admin/configurationManagement/configurationTemplates/{id}": "", + "/admin/configurationManagement/configurationTemplates/{id}/versions/{version}/referencedExternalMonitors/{tenantId}": "", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs": "", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs/{id}": "", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs/{id}/results": "", @@ -12804,6 +12830,7 @@ "/admin/configurationManagement/configurationMonitors/{id}/validate": "least=DelegatedWork,Application", "/admin/configurationManagement/configurationSnapshots/createSnapshot": "least=DelegatedWork,Application", "/admin/configurationManagement/configurationTemplates": "least=DelegatedWork,Application", + "/admin/configurationManagement/configurationTemplates/{id}/versions/{version}/referencedExternalMonitors/{tenantId}/monitors/$ref": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationDriftFetchJobs": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationMonitorFetchJobs": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationMonitoringResultFetchJobs": "least=DelegatedWork,Application", @@ -12857,6 +12884,7 @@ "paths": { "/admin/configurationManagement/configurationMonitors/{id}": "least=DelegatedWork,Application", "/admin/configurationManagement/configurationTemplates/{id}": "least=DelegatedWork,Application", + "/admin/configurationManagement/configurationTemplates/{id}/versions/{version}/referencedExternalMonitors/{tenantId}/monitors/{monitorId}/$ref": "least=DelegatedWork,Application", "/admin/configurationManagement/externalTenants/configurationMonitors/{id}": "least=DelegatedWork,Application" } }, @@ -31157,6 +31185,7 @@ "/identityprotection/riskdetections/{id}": "least=DelegatedWork,Application", "/identityprotection/serviceprincipalriskdetections": "least=DelegatedWork,Application", "/identityprotection/serviceprincipalriskdetections/{id}": "least=DelegatedWork,Application", + "/identityProtection/settings/agentNotifications": "least=DelegatedWork,Application", "/riskdetections": "least=DelegatedWork,Application", "/riskdetections/{id}": "least=DelegatedWork,Application" } @@ -31169,6 +31198,14 @@ "IdentityRiskEvent.ReadWrite.All": { "authorizationType": "oAuth2", "schemes": { + "DelegatedWork": { + "adminDisplayName": "Read and write identity risk event information", + "adminDescription": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections.", + "userDisplayName": "Read and write identity risk event information", + "userDescription": "Allows the app to read and update identity risk event information for all users in your organization on your behalf. Update operations include confirming risk event detections.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + }, "Application": { "adminDisplayName": "Read and write all risk detection information", "adminDescription": "Allows the app to read and update identity risk detection information for your organization without a signed-in user. Update operations include confirming risk event detections. ", @@ -31177,6 +31214,30 @@ } }, "pathSets": [ + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "GET" + ], + "paths": { + "/identityProtection/settings/agentNotifications": "" + } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "PATCH" + ], + "paths": { + "/identityProtection/settings/agentNotifications": "least=DelegatedWork,Application" + } + }, { "schemeKeys": [ "Application" @@ -33248,6 +33309,248 @@ "pathSets": [], "ownerInfo": {} }, + "LifecyclePolicies-AgentId.Read.All": { + "authorizationType": "oAuth2", + "schemes": { + "DelegatedWork": { + "adminDisplayName": "Read identity lifecycle policies for agent identities", + "adminDescription": "Allows the app to read identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "userDisplayName": "Read identity lifecycle policies for agent identities", + "userDescription": "Allows the app to read identity lifecycle policies for agent identities that you have access to.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + }, + "Application": { + "adminDisplayName": "Read identity lifecycle policies for agent identities", + "adminDescription": "Allows the app to read identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + } + }, + "pathSets": [ + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "GET" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/impact(startDateTime={startDateTime},endDateTime={endDateTime})": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report/subjects": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicyPriorityConfigurations": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicyPriorityConfigurations/{subjectType}": "least=DelegatedWork,Application" + } + } + ], + "ownerInfo": { + "ownerSecurityGroup": "aadlcm" + } + }, + "LifecyclePolicies-AgentId.ReadWrite.All": { + "authorizationType": "oAuth2", + "schemes": { + "DelegatedWork": { + "adminDisplayName": "Read and write identity lifecycle policies for agent identities", + "adminDescription": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "userDisplayName": "Read and write identity lifecycle policies for agent identities", + "userDescription": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities that you have access to.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + }, + "Application": { + "adminDisplayName": "Read and write identity lifecycle policies for agent identities", + "adminDescription": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + } + }, + "pathSets": [ + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "GET" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies": "", + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/impact(startDateTime={startDateTime},endDateTime={endDateTime})": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report/subjects": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicyPriorityConfigurations": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicyPriorityConfigurations/{subjectType}": "" + } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "POST" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}/restore": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "least=DelegatedWork,Application" + } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "PATCH" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicyPriorityConfigurations/{subjectType}": "least=DelegatedWork,Application" + } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "DELETE" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "least=DelegatedWork,Application" + } + } + ], + "ownerInfo": { + "ownerSecurityGroup": "aadlcm" + } + }, + "LifecyclePolicies-Guests.Read.All": { + "authorizationType": "oAuth2", + "schemes": { + "DelegatedWork": { + "adminDisplayName": "Read identity lifecycle policies for external guests", + "adminDescription": "Allows the app to read identity lifecycle policies for external guests on behalf of the signed-in user.", + "userDisplayName": "Read identity lifecycle policies for external guests", + "userDescription": "Allows the app to read identity lifecycle policies for external guests on your behalf.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + }, + "Application": { + "adminDisplayName": "Read identity lifecycle policies for external guests", + "adminDescription": "Allows the app to read identity lifecycle policies for external guests in the organization, without a signed-in user.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + } + }, + "pathSets": [ + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "GET" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/attestationRequirements": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/attestationRequirements/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/impact(startDateTime={startDateTime},endDateTime={endDateTime})": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report/subjects": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules": "", + "/users/{id}/lifecycle": "least=DelegatedWork,Application" + } + } + ], + "ownerInfo": { + "ownerSecurityGroup": "aadlcm" + } + }, + "LifecyclePolicies-Guests.ReadWrite.All": { + "authorizationType": "oAuth2", + "schemes": { + "DelegatedWork": { + "adminDisplayName": "Read and write identity lifecycle policies for external guests", + "adminDescription": "Allows the app to create, update, and delete identity lifecycle policies for external guests on behalf of the signed-in user.", + "userDisplayName": "Read and write identity lifecycle policies for external guests", + "userDescription": "Allows the app to create, update, and delete identity lifecycle policies for external guests on your behalf.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + }, + "Application": { + "adminDisplayName": "Read and write identity lifecycle policies for external guests", + "adminDescription": "Allows the app to create, update, and delete identity lifecycle policies for external guests in the organization, without a signed-in user.", + "requiresAdminConsent": true, + "privilegeLevel": 3 + } + }, + "pathSets": [ + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "GET" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/attestationRequirements": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/attestationRequirements/{id}": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/impact(startDateTime={startDateTime},endDateTime={endDateTime})": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/report/subjects": "", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules": "", + "/users/{id}/lifecycle": "" + } + }, + { + "schemeKeys": [ + "DelegatedWork", + "Application" + ], + "methods": [ + "DELETE", + "PATCH", + "POST" + ], + "paths": { + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/deletedItems/lifecyclePolicies/{id}/restore": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/attestationRequirements/{id}": "least=DelegatedWork,Application", + "/identitygovernance/lifecycleworkflows/lifecyclePolicies/{id}/rules": "least=DelegatedWork,Application", + "/users/{id}/microsoft.graph.identityGovernance.attest": "least=DelegatedWork,Application" + } + } + ], + "ownerInfo": { + "ownerSecurityGroup": "aadlcm" + } + }, "LifecycleWorkflows-CustomExt.Read.All": { "authorizationType": "oAuth2", "schemes": { diff --git a/permissions/new/provisioningInfo.json b/permissions/new/provisioningInfo.json index 81f2e4e5..99cd2490 100644 --- a/permissions/new/provisioningInfo.json +++ b/permissions/new/provisioningInfo.json @@ -9534,76 +9534,72 @@ ], "LifecyclePolicies-AgentId.Read.All": [ { - "id": "3d09c9ee-9db9-4c84-85ec-f63a21b4ad2c", + "id": "65857db0-62ac-4279-aa73-c2b5dab186f5", "scheme": "DelegatedWork", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" }, { - "id": "75d9ca3df-7017-4feb-baa0-06a339b6c338", + "id": "6343d63f-034f-45b5-832d-9f9d7632e182", "scheme": "Application", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" } ], "LifecyclePolicies-AgentId.ReadWrite.All": [ { - "id": "f6fdb5f4-56bf-4daf-bb35-0b5ccdf56c4c", + "id": "f2292ca5-46fc-4195-9b4d-16491bf9bf7f", "scheme": "DelegatedWork", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" }, { - "id": "079f94bb-be92-4268-b63c-ce4fb09f4318", + "id": "00d1c504-8dc7-461b-8a0b-dc15c8f1bd5a", "scheme": "Application", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" } ], - "LifecyclePolicies-Guests.Read": [ + "LifecyclePolicies-Guests.Read.All": [ { - "id": "2483acba-993c-4263-aa45-9077957f81ec", + "id": "1bbb7916-b98a-449f-8ee4-c68bfcba5724", "scheme": "DelegatedWork", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" - } - ], - "LifecyclePolicies-Guests.Read.All": [ + }, { "id": "da2c2d45-124a-42d6-b85a-ac0d86b31a25", "scheme": "Application", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" } ], - "LifecyclePolicies-Guests.ReadWrite": [ + "LifecyclePolicies-Guests.ReadWrite.All": [ { - "id": "96155e7d-94f8-4996-84bc-bff285e5975b", + "id": "d9ec82ed-63db-4905-b1b3-859b74d2bbf5", "scheme": "DelegatedWork", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" - } - ], - "LifecyclePolicies-Guests.ReadWrite.All": [ + }, { "id": "0a0600bd-3cd8-47d8-a983-2c2c194f658f", "scheme": "Application", "environment": "public", - "isHidden": true, + "isHidden": false, "isEnabled": true, "resourceAppId": "ce79fdc4-cd1d-4ea5-8139-e74d7dbe0bb7" } @@ -10321,7 +10317,7 @@ "scheme": "DelegatedWork", "environment": "public", "isHidden": true, - "isEnabled": false, + "isEnabled": true, "resourceAppId": "e8c77dc2-69b3-43f4-bc51-3213c9d915b4" } ],