Skip to content

Commit 33a7b00

Browse files
authored
Merge pull request #25645 from microsoftgraph/rbac-EntraHealth
Entra admin roles - Microsoft Entra Health
2 parents d4d580e + 2ddcb1a commit 33a7b00

8 files changed

+40
-50
lines changed

api-reference/beta/api/serviceactivity-getmetricsforconditionalaccesscompliantdevicessigninsuccess.md

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,7 @@ Choose the permission or permissions marked as least privileged for this API. Us
2020
<!-- { "blockType": "permissions", "name": "serviceactivity_getmetricsforconditionalaccesscompliantdevicessigninsuccess" } -->
2121
[!INCLUDE [permissions-table](../includes/permissions/serviceactivity-getmetricsforconditionalaccesscompliantdevicessigninsuccess-permissions.md)]
2222

23-
In addition to the delegated permissions, the signed-in user who is accessing the data needs to belong to at least one of the following [Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json), which allow them to read sign-in reports:
24-
25-
+ Global Reader
26-
+ Reports Reader
27-
+ Security Administrator
28-
+ Security Operator
29-
+ Security Reader
23+
[!INCLUDE [rbac-entra-health-service-activity-apis](../includes/rbac-for-apis/rbac-entra-health-service-activity-apis.md)]
3024

3125
## HTTP request
3226

api-reference/beta/api/serviceactivity-getmetricsforconditionalaccessmanageddevicessigninsuccess.md

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,7 @@ Choose the permission or permissions marked as least privileged for this API. Us
2020
<!-- { "blockType": "permissions", "name": "serviceactivity_getmetricsforconditionalaccessmanageddevicessigninsuccess" } -->
2121
[!INCLUDE [permissions-table](../includes/permissions/serviceactivity-getmetricsforconditionalaccessmanageddevicessigninsuccess-permissions.md)]
2222

23-
In addition to the delegated permissions, the signed-in user who is accessing the data needs to belong to at least one of the following [Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json), which allow them to read sign-in reports:
24-
25-
+ Global Reader
26-
+ Reports Reader
27-
+ Security Administrator
28-
+ Security Operator
29-
+ Security Reader
23+
[!INCLUDE [rbac-entra-health-service-activity-apis](../includes/rbac-for-apis/rbac-entra-health-service-activity-apis.md)]
3024

3125
## HTTP request
3226

api-reference/beta/api/serviceactivity-getmetricsformfasigninfailure.md

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,7 @@ Choose the permission or permissions marked as least privileged for this API. Us
2020
<!-- { "blockType": "permissions", "name": "serviceactivity_getmetricsformfasigninfailure" } -->
2121
[!INCLUDE [permissions-table](../includes/permissions/serviceactivity-getmetricsformfasigninfailure-permissions.md)]
2222

23-
In addition to the delegated permissions, the signed-in user who is accessing the data needs to belong to at least one of the following [Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json), which allow them to read sign-in reports:
24-
25-
+ Global Reader
26-
+ Reports Reader
27-
+ Security Administrator
28-
+ Security Operator
29-
+ Security Reader
23+
[!INCLUDE [rbac-entra-health-service-activity-apis](../includes/rbac-for-apis/rbac-entra-health-service-activity-apis.md)]
3024

3125
## HTTP request
3226

api-reference/beta/api/serviceactivity-getmetricsformfasigninsuccess.md

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,7 @@ Choose the permission or permissions marked as least privileged for this API. Us
2020
<!-- { "blockType": "permissions", "name": "serviceactivity_getmetricsformfasigninsuccess" } -->
2121
[!INCLUDE [permissions-table](../includes/permissions/serviceactivity-getmetricsformfasigninsuccess-permissions.md)]
2222

23-
In addition to the delegated permissions, the signed-in user who is accessing the data needs to belong to at least one of the following [Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json), which allow them to read sign-in reports:
24-
25-
+ Global Reader
26-
+ Reports Reader
27-
+ Security Administrator
28-
+ Security Operator
29-
+ Security Reader
23+
[!INCLUDE [rbac-entra-health-service-activity-apis](../includes/rbac-for-apis/rbac-entra-health-service-activity-apis.md)]
3024

3125
## HTTP request
3226

api-reference/beta/api/serviceactivity-getmetricsforsamlsigninsuccess.md

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,7 @@ Choose the permission or permissions marked as least privileged for this API. Us
2020
<!-- { "blockType": "permissions", "name": "serviceactivity_getmetricsforsamlsigninsuccess" } -->
2121
[!INCLUDE [permissions-table](../includes/permissions/serviceactivity-getmetricsforsamlsigninsuccess-permissions.md)]
2222

23-
In addition to the delegated permissions, the signed-in user who is accessing the data needs to belong to at least one of the following [Microsoft Entra roles](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json), which allow them to read sign-in reports:
24-
25-
+ Global Reader
26-
+ Reports Reader
27-
+ Security Administrator
28-
+ Security Operator
29-
+ Security Reader
23+
[!INCLUDE [rbac-entra-health-service-activity-apis](../includes/rbac-for-apis/rbac-entra-health-service-activity-apis.md)]
3024

3125
## HTTP request
3226

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
---
2+
author: Zacharypeng
3+
ms.topic: include
4+
---
5+
6+
> [!IMPORTANT]
7+
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation:
8+
>
9+
> - Global Reader
10+
> - Reports Reader
11+
> - Security Reader
12+
> - Security Administrator
13+
> - Security Operator

api-reference/beta/toc/reports/toc.yml

Lines changed: 16 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -148,6 +148,22 @@ items:
148148
href: ../../resources/azureadauthentication.md
149149
- name: Get SLA attainment
150150
href: ../../api/azureadauthentication-get.md
151+
- name: Service activity
152+
items:
153+
- name: Service activity
154+
items:
155+
- name: Service activity
156+
href: ../../resources/serviceactivity.md
157+
- name: Get MFA sign-in success metrics
158+
href: ../../api/serviceactivity-getmetricsformfasigninsuccess.md
159+
- name: Get MFA sign-in failure metrics
160+
href: ../../api/serviceactivity-getmetricsformfasigninfailure.md
161+
- name: Get managed devices Conditional Access sign-in metrics
162+
href: ../../api/serviceactivity-getmetricsforconditionalaccessmanageddevicessigninsuccess.md
163+
- name: Get compliant devices Conditional Access sign-in metrics
164+
href: ../../api/serviceactivity-getmetricsforconditionalaccesscompliantdevicessigninsuccess.md
165+
- name: Get SAML sign-in metrics
166+
href: ../../api/serviceactivity-getmetricsforsamlsigninsuccess.md
151167
- name: Health monitoring
152168
items:
153169
- name: Overview
@@ -220,20 +236,6 @@ items:
220236
href: ../../resources/userregistrationmethodsummary.md
221237
- name: List
222238
href: ../../api/authenticationmethodsroot-usersregisteredbymethod.md
223-
- name: Service activity
224-
items:
225-
- name: Service activity
226-
href: ../../resources/serviceactivity.md
227-
- name: Get MFA sign-in success metrics
228-
href: ../../api/serviceactivity-getmetricsformfasigninsuccess.md
229-
- name: Get MFA sign-in failure metrics
230-
href: ../../api/serviceactivity-getmetricsformfasigninfailure.md
231-
- name: Get managed devices Conditional Access sign-in metrics
232-
href: ../../api/serviceactivity-getmetricsforconditionalaccessmanageddevicessigninsuccess.md
233-
- name: Get compliant devices Conditional Access sign-in metrics
234-
href: ../../api/serviceactivity-getmetricsforconditionalaccesscompliantdevicessigninsuccess.md
235-
- name: Get SAML sign-in metrics
236-
href: ../../api/serviceactivity-getmetricsforsamlsigninsuccess.md
237239
- name: Service principal sign in activity
238240
items:
239241
- name: Service principal sign in activity

api-reference/beta/toc/toc.mapping.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2250,7 +2250,6 @@
22502250
"shouldSort": true,
22512251
"resources": [
22522252
"appCredentialSignInActivity",
2253-
"serviceActivity",
22542253
"servicePrincipalSignInActivity"
22552254
],
22562255
"childNodes": [
@@ -2290,6 +2289,12 @@
22902289
"azureADAuthentication"
22912290
]
22922291
},
2292+
{
2293+
"name": "Service activity",
2294+
"resources": [
2295+
"serviceActivity"
2296+
]
2297+
},
22932298
{
22942299
"name": "Health monitoring",
22952300
"overview": "../../resources/healthmonitoring-overview.md",

0 commit comments

Comments
 (0)