Scoping Custom Role With microsoft.directory/auditLogs/allProperties/read Role Permission

Jamie Brandwood 131 Reputation points
2024-07-17T11:12:01.3233333+00:00

Hi Community,

Can you have a custom role with the microsoft.directory/auditLogs/allProperties/read role permission and use Admin Units to scope to devices only? Is this a scope'able permission?

Kind Regards,

Jamie

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
805 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,611 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 147.8K Reputation points MVP
    2024-07-17T11:27:57.9833333+00:00

  2. Marcin Policht 23,395 Reputation points MVP
    2024-07-17T11:38:19.11+00:00

    This permission is delegatable - as illustrated by https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference and the corresponding roles (such as Cloud Device Administrator) support Admin Unit-based delegation - so I'd expect this to work for custom roles as well.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.