Hello Nathan Carr
Thank you for reaching out to Microsoft Support!!
The issue you're encountering arises because managed identities in Azure (both system-assigned and user-assigned) cannot directly be granted Microsoft Graph API permissions like Group.Read.All
through the Azure portal. This is a known limitation, as managed identities are not treated the same as service principals when it comes to assigning Graph API permissions.
You can submit this feature request using this support link, which will be monitored by Microsoft team and make the enhancements to Graph API.
Hope this helps.
If the answer is helpful, please click Accept Answer and kindly upvote it. If you have any further questions about this answer, please click Comment.