The permissions reference lists User.ReadBasic.All under both Application and Delegated categories, with a distinct app role id for each (97235f07-e226-4f63-ace3-39588e11d3a1 for Application) and AdminConsentRequired: Yes. This makes it appear as a real, consentable Application permission for reading users' basic profiles without a signed-in user.
However, the operation-level docs for the two most obvious use cases don't list it at all under Application:
- List users — Application: User.Read.All, User.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All
- Get a user — same list, no User.ReadBasic.All
This matches what we see in practice: with only User.ReadBasic.All (Application) granted and admin-consented, a client-credentials call to GET /users returns:
{
"error": {
"code": "Authorization_RequestDenied",
"message": "Insufficient privileges to complete the operation."
}
}
Adding User.Read.All (Application) instead resolves it immediately, with no other change.
Question: Is User.ReadBasic.All (Application) actually wired into any current Graph endpoint, or is it a declared app role with no operation currently honoring it? If the latter, it'd help to have that stated on the permissions-reference page itself, since right now it reads as fully functional for reading users without a signed-in user.