Skip to content

Commit fed349d

Browse files
committed
Entra admin roles - conditional access APIs
1 parent f19c917 commit fed349d

25 files changed

+71
-6
lines changed

api-reference/beta/includes/rbac-for-apis/rbac-conditionalaccess-apis-read.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,5 +5,8 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
> In delegated scenarios with work or school accounts where the signed-in user is acting on another user, they must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
8+
> - Global Secure Access Administrator - read standard properties
9+
> - Security Reader - read standard properties
810
> - Security Administrator - read standard properties
9-
> - Conditional Access Administrator
11+
> - Global Reader
12+
> - Conditional Access Administrator

api-reference/beta/includes/rbac-for-apis/rbac-conditionalaccess-apis-write.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,5 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
> In delegated scenarios with work or school accounts where the signed-in user is acting on another user, they must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
8-
> - Global Secure Access Administrator - read standard properties
9-
> - Security Reader - read standard properties
10-
> - Security Administrator - read standard properties
11-
> - Global Reader
8+
> - Security Administrator
129
> - Conditional Access Administrator

api-reference/v1.0/api/authenticationcontextclassreference-delete.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "permissions", "name": "authenticationcontextclassreference_delete" } -->
2424
[!INCLUDE [permissions-table](../includes/permissions/authenticationcontextclassreference-delete-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-write](../includes/rbac-for-apis/rbac-conditionalaccess-apis-write.md)]
27+
2628
## HTTP request
2729

2830
<!-- { "blockType": "ignored" } -->

api-reference/v1.0/api/authenticationcontextclassreference-get.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "permissions", "name": "authenticationcontextclassreference_get" } -->
2424
[!INCLUDE [permissions-table](../includes/permissions/authenticationcontextclassreference-get-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-read](../includes/rbac-for-apis/rbac-conditionalaccess-apis-read.md)]
27+
2628
## HTTP request
2729

2830
<!-- { "blockType": "ignored" } -->

api-reference/v1.0/api/authenticationcontextclassreference-update.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "permissions", "name": "authenticationcontextclassreference_update" } -->
2424
[!INCLUDE [permissions-table](../includes/permissions/authenticationcontextclassreference-update-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-write](../includes/rbac-for-apis/rbac-conditionalaccess-apis-write.md)]
27+
2628
> [!NOTE]
2729
> This method has a [known permissions issue](https://developer.microsoft.com/en-us/graph/known-issues/?search=13671) and may require consent to multiple permissions.
2830

api-reference/v1.0/api/conditionalaccesspolicy-delete.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "ignored" } // Note: Removing this line will result in the permissions autogeneration tool overwriting the table. -->
2424
[!INCLUDE [permissions-table](../includes/permissions/conditionalaccesspolicy-delete-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-write](../includes/rbac-for-apis/rbac-conditionalaccess-apis-write.md)]
27+
2628
## HTTP request
2729

2830
<!-- { "blockType": "ignored" } -->

api-reference/v1.0/api/conditionalaccesspolicy-get.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "permissions", "name": "conditionalaccesspolicy_get" } -->
2424
[!INCLUDE [permissions-table](../includes/permissions/conditionalaccesspolicy-get-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-read](../includes/rbac-for-apis/rbac-conditionalaccess-apis-read.md)]
27+
2628
## HTTP request
2729

2830
<!-- { "blockType": "ignored" } -->

api-reference/v1.0/api/conditionalaccesspolicy-update.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "ignored" } // Note: Removing this line will result in the permissions autogeneration tool overwriting the table. -->
2424
[!INCLUDE [permissions-table](../includes/permissions/conditionalaccesspolicy-update-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-write](../includes/rbac-for-apis/rbac-conditionalaccess-apis-write.md)]
27+
2628
> [!NOTE]
2729
> This method has a [known permissions issue](https://developer.microsoft.com/en-us/graph/known-issues/?search=13671) and may require consent to multiple permissions.
2830

api-reference/v1.0/api/conditionalaccessroot-list-authenticationcontextclassreferences.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2525
<!-- { "blockType": "permissions", "name": "conditionalaccessroot_list_authenticationcontextclassreferences" } -->
2626
[!INCLUDE [permissions-table](../includes/permissions/conditionalaccessroot-list-authenticationcontextclassreferences-permissions.md)]
2727

28+
[!INCLUDE [rbac-conditionalaccess-apis-read](../includes/rbac-for-apis/rbac-conditionalaccess-apis-read.md)]
29+
2830
## HTTP request
2931

3032
<!-- { "blockType": "ignored" } -->

api-reference/v1.0/api/conditionalaccessroot-list-namedlocations.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ Choose the permission or permissions marked as least privileged for this API. Us
2323
<!-- { "blockType": "permissions", "name": "conditionalaccessroot_list_namedlocations" } -->
2424
[!INCLUDE [permissions-table](../includes/permissions/conditionalaccessroot-list-namedlocations-permissions.md)]
2525

26+
[!INCLUDE [rbac-conditionalaccess-apis-read](../includes/rbac-for-apis/rbac-conditionalaccess-apis-read.md)]
27+
2628
## HTTP request
2729

2830
<!-- { "blockType": "ignored" } -->

0 commit comments

Comments
 (0)