Scoping Custom Role With microsoft.directory/auditLogs/allProperties/read Role Permission

Jamie Brandwood 131 Reputation points
2024-07-17T11:12:01.3233333+00:00

Hi Community,

Can you have a custom role with the microsoft.directory/auditLogs/allProperties/read role permission and use Admin Units to scope to devices only? Is this a scope'able permission?

Kind Regards,

Jamie

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
716 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,529 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 1.5L Reputation points MVP
    2024-07-17T11:27:57.9833333+00:00

  2. Marcin Policht 18,005 Reputation points MVP
    2024-07-17T11:38:19.11+00:00

    This permission is delegatable - as illustrated by https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference and the corresponding roles (such as Cloud Device Administrator) support Admin Unit-based delegation - so I'd expect this to work for custom roles as well.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments