AUdit Logs are restricted to the users Admin units.
You could test that out and add devices to the units:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi Community,
Can you have a custom role with the microsoft.directory/auditLogs/allProperties/read role permission and use Admin Units to scope to devices only? Is this a scope'able permission?
Kind Regards,
Jamie
AUdit Logs are restricted to the users Admin units.
You could test that out and add devices to the units:
This permission is delegatable - as illustrated by https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference and the corresponding roles (such as Cloud Device Administrator) support Admin Unit-based delegation - so I'd expect this to work for custom roles as well.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin