User.ReadBasic.All listed as an Application permission, but no /users operation accepts it

Jonathan 0 Reputation points
2026-09-29T16:33:40.4233333+00:00

The permissions reference lists User.ReadBasic.All under both Application and Delegated categories, with a distinct app role id for each (97235f07-e226-4f63-ace3-39588e11d3a1 for Application) and AdminConsentRequired: Yes. This makes it appear as a real, consentable Application permission for reading users' basic profiles without a signed-in user.

However, the operation-level docs for the two most obvious use cases don't list it at all under Application:

  • List users — Application: User.Read.All, User.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All
  • Get a user — same list, no User.ReadBasic.All

This matches what we see in practice: with only User.ReadBasic.All (Application) granted and admin-consented, a client-credentials call to GET /users returns:

{
  "error": {
    "code": "Authorization_RequestDenied",
    "message": "Insufficient privileges to complete the operation."
  }
}

Adding User.Read.All (Application) instead resolves it immediately, with no other change.

Question: Is User.ReadBasic.All (Application) actually wired into any current Graph endpoint, or is it a declared app role with no operation currently honoring it? If the latter, it'd help to have that stated on the permissions-reference page itself, since right now it reads as fully functional for reading users without a signed-in user.

Microsoft Security | Microsoft Graph
0 comments No comments

1 answer

Sort by: Most helpful
  1. Vasil Michev 128K Reputation points MVP Volunteer Moderator
    2026-09-29T16:48:05.0733333+00:00

    That's not the behavior I'm seeing, a Graph API call to /users with User.ReadBasic.All application permissions returns the list of users just fine, with only the set of "supported" properties having non-null values. I'd suggest you double-check the query and decode the access token via tools such as jwt.ms to make sure the User.ReadBasic.All role is correctly reflected therein.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.