Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions permissions/new/permissions.json
Original file line number Diff line number Diff line change
Expand Up @@ -60645,6 +60645,9 @@
"paths": {
"/admin/windows/updates/deploymentaudiences": "least=DelegatedWork,Application",
"/admin/windows/updates/deployments": "least=DelegatedWork,Application",
"/admin/windows/updates/policies": "least=DelegatedWork,Application",
"/admin/windows/updates/policies/{id}/approvals": "least=DelegatedWork,Application",
"/admin/windows/updates/policies/{id}/rings": "least=DelegatedWork,Application",
"/admin/windows/updates/resourceconnections": "least=DelegatedWork,Application",
"/admin/windows/updates/updatableassets": "least=DelegatedWork,Application",
"/admin/windows/updates/updatepolicies": "least=DelegatedWork,Application",
Expand Down Expand Up @@ -60678,6 +60681,9 @@
],
"paths": {
"/admin/windows/updates/deployments/{id}": "least=DelegatedWork,Application",
"/admin/windows/updates/policies/{id}": "least=DelegatedWork,Application",
"/admin/windows/updates/policies/{id}/approvals/{id}": "least=DelegatedWork,Application",
"/admin/windows/updates/policies/{id}/rings/{id}": "least=DelegatedWork,Application",
"/admin/windows/updates/updatepolicies/{id}": "least=DelegatedWork,Application",
"/admin/windows/updates/updatepolicies/{id}/compliancechanges/{id}": "least=DelegatedWork,Application"
}
Expand Down
249 changes: 179 additions & 70 deletions permissions/new/provisioningInfo.json
Original file line number Diff line number Diff line change
Expand Up @@ -311,7 +311,7 @@
"isEnabled": true,
"resourceAppId": "9c31bd49-9f18-4580-84a0-e6e6dbd13640"
}
],
],
"AgentCollection.Read.Quarantined": [
{
"id": "43acfda3-daf3-4aa4-955d-b051d0024e82",
Expand All @@ -331,7 +331,7 @@
"isEnabled": true,
"resourceAppId": "9c31bd49-9f18-4580-84a0-e6e6dbd13640"
}
],
],
"AgentIdentityBlueprint.CreateAsManager": [
{
"id": "ecf9c9c0-b7d6-48c0-8ad6-7b00493a2efb",
Expand Down Expand Up @@ -956,6 +956,24 @@
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"MS-ServicePrincipal.Create": [
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
Comment on lines +959 to +976
Copy link

Copilot AI Jan 12, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The new permission entries for "MS-ServicePrincipal.Create" have empty "id" and "environment" fields. These fields should contain valid values. Empty strings for the "id" field are problematic as this field typically serves as a unique identifier for the permission, and empty "environment" values may cause issues when the permission is applied in specific environments.

Copilot uses AI. Check for mistakes.
"Application.Read.All": [
{
"id": "c79f8feb-a9db-4090-85f9-90d820caa0eb",
Expand Down Expand Up @@ -4352,25 +4370,26 @@
"resourceAppId": "00000000-0000-0000-0000-000000000000"
}
],
"Device-ResourceAccount.Read.All": [
{
"id": "c1f9b7d2-2f3a-4a1e-9c6b-000000000001",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000000-0000-0000-0000-000000000000"
"Device-ResourceAccount.Read.All": [
{
"id": "c1f9b7d2-2f3a-4a1e-9c6b-000000000001",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000000-0000-0000-0000-000000000000"
}
],
"User-DevicesForResourceAccount.Read.All": [
{ "id": "e8c1a9b2-3f4d-4a9e-9d2b-6a7c8e9f0b12",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000000-0000-0000-0000-000000000000"
}
],
{
"id": "e8c1a9b2-3f4d-4a9e-9d2b-6a7c8e9f0b12",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000000-0000-0000-0000-000000000000"
}
],
"Device-UsageRight.Read.All": [
{
"id": "cee9882c-10b9-464d-be42-92b6590fc3c0",
Expand Down Expand Up @@ -8457,6 +8476,96 @@
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"ManagedIdentity.Read.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"ManagedIdentity.Update.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"ManagedIdentity.Delete.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"ManagedIdentity.HardDelete.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"ManagedIdentity.Restore.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
},
{
"id": "",
"scheme": "Application",
"environment": "",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
Comment on lines +8479 to +8568
Copy link

Copilot AI Jan 12, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All five new ManagedIdentity permission entries (Read.All, Update.All, Delete.All, HardDelete.All, and Restore.All) have empty "id" and "environment" fields. These fields should contain valid values. Empty strings for the "id" field are problematic as this field typically serves as a unique identifier for the permission, and empty "environment" values may cause issues when the permission is applied in specific environments.

Copilot uses AI. Check for mistakes.
"ManagedTenants.Read.All": [
{
"id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3",
Expand Down Expand Up @@ -15736,7 +15845,7 @@
"resourceAppId": ""
}
],
"TokenRevocations.Read.All":[
"TokenRevocations.Read.All": [
{
"id": "10506a2e-a91b-4aba-886f-ba9f7938f05b",
"scheme": "Application",
Expand All @@ -15754,7 +15863,7 @@
"resourceAppId": "00000002-0000-0000-c000-000000000000"
}
],
"TokenRevocations.ReadWrite.All":[
"TokenRevocations.ReadWrite.All": [
{
"id": "e91cbba3-7784-4313-8460-b91c2137514d",
"scheme": "Application",
Expand Down Expand Up @@ -17026,20 +17135,20 @@
],
"UserAuthMethod-ResourceKey.Read.All": [
{
"id": "",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
"id": "",
"scheme": "DelegatedWork",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
},
{
"id": "",
"scheme": "Application",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
"id": "",
"scheme": "Application",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
}
],
"UserAuthMethod-ResourceKey.ReadWrite.All": [
Expand All @@ -17052,12 +17161,12 @@
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
},
{
"id": "",
"scheme": "Application",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
"id": "",
"scheme": "Application",
"environment": "public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "ea890292-c8c8-4433-b5ea-b09d0668e1a6"
}
],
"UserAuthMethod-SoftwareOATH.Read": [
Expand Down Expand Up @@ -24623,40 +24732,40 @@
}
],
"LockboxSettings.Read.All": [
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
"LockboxSettings.ReadWrite.All": [
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
"LockboxRequest.Read.All": [
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
],
"LockboxRequest.ReadWrite.All": [
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
]
{
"scheme": "DelegatedWork",
"environment": "PPE;public",
"isHidden": true,
"isEnabled": true,
"resourceAppId": "00000003-0000-0000-c000-000000000000"
}
]
}
}