Skip to content

Commit 0603ab9

Browse files
committed
Entra admin roles - invalidate refresh tokens
1 parent d592260 commit 0603ab9

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

api-reference/beta/api/user-invalidateallrefreshtokens.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,15 @@ Choose the permission or permissions marked as least privileged for this API. Us
2727
<!-- { "blockType": "permissions", "name": "user_invalidateallrefreshtokens" } -->
2828
[!INCLUDE [permissions-table](../includes/permissions/user-invalidateallrefreshtokens-permissions.md)]
2929

30+
> [!IMPORTANT]
31+
>
32+
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation:
33+
> - Directory Writers
34+
> - Helpdesk Administrator
35+
> - Authentication Administrator
36+
> - Privileged Authentication Administrator
37+
> - User Administrator
38+
3039
## HTTP request
3140
<!-- { "blockType": "ignored" } -->
3241
```http

0 commit comments

Comments
 (0)