Skip to content

Commit 673a787

Browse files
[Bulk update] Update RBAC boilerplate text in includes (#28677)
* Update RBAC boilerplate text in beta includes to new pattern - Replace 'In delegated scenarios with work or school accounts' with 'For delegated access using work or school accounts' - Replace 'or a custom role with a supported role permission' with 'or a custom role that grants the minimum permissions required for this operation' - Replace list intro sentence with new two-paragraph format using a blank blockquote separator and 'This operation supports the following built-in roles, which provide only the least privilege necessary:' - Add blockquote paragraph separator before inline italic role names Applies to 187 files in api-reference/beta/includes/rbac-for-apis/. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update RBAC boilerplate text in v1.0 includes (sync from beta) Sync 122 v1.0 RBAC include files from their updated beta counterparts. Updates delegated access intro text and role list intro to use the new [!IMPORTANT] callout pattern, matching the beta changes in 4fdbc82. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Nit undo paragraph * Update /authorAPIDocs, /reviewAPIDocs prompt as well --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 0939555 commit 673a787

310 files changed

Lines changed: 435 additions & 420 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

api-reference/beta/includes/rbac-for-apis/onpremauthenticationpolicy-entra-roles-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
88
> - Directory Reviewer
99
> - Global Administrator
1010
> - Global Reader

api-reference/beta/includes/rbac-for-apis/onpremauthenticationpolicy-entra-roles-write.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,5 +4,6 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
8-
> - Global Administrator
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation.
8+
>
9+
> *Global Administrator* is the only built-in role supported for this operation.

api-reference/beta/includes/rbac-for-apis/rbac-access-review-policy-apis-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
88
> - Global Reader
99
> - Security Reader
1010
> - Identity Governance Administrator

api-reference/beta/includes/rbac-for-apis/rbac-access-review-policy-apis-update.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,6 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
88
> - Identity Governance Administrator
99
> - Privileged Role Administrator

api-reference/beta/includes/rbac-for-apis/rbac-access-reviews-apis-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
88
> - To read access reviews of a group or app: the creator of the access review; *Global Reader*, *Security Reader*, *User Administrator*, *Identity Governance Administrator*, *Security Administrator*
99
>
1010
> - To read access reviews of a Microsoft Entra role: *Security Reader*, *Identity Governance Administrator*, *Privileged Role Administrator*, *Security Administrator*

api-reference/beta/includes/rbac-for-apis/rbac-access-reviews-apis-write.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,6 @@ ms.topic: include
44
---
55

66
> [!IMPORTANT]
7-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
7+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
88
> - To write access reviews of a group or app: *User Administrator*, *Identity Governance Administrator*
99
> - To write access reviews of a Microsoft Entra role: *Identity Governance Administrator*, *Privileged Role Administrator*

api-reference/beta/includes/rbac-for-apis/rbac-admin-units-apis-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
>
8-
> In delegated scenarios with work or school accounts, the signed-in user must be a member user or be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation.
8+
> For delegated access using work or school accounts, the signed-in user must be a member user or be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
99
> - Directory Readers - Read *basic* properties and members of administrative units
1010
> - Global Reader - Read *all* properties of administrative units, including members
1111
> - Privileged Role Administrator - Fully manage administrative units, including members, but excluding restricted administrative units. For more information, see [Restricted management administrative units in Microsoft Entra ID](/entra/identity/role-based-access-control/admin-units-restricted-management)

api-reference/beta/includes/rbac-for-apis/rbac-admin-units-apis-write.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,4 +5,4 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
>
8-
> In delegated scenarios with work or school accounts, the signed-in user must be a member user or be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. *Privileged Role Administrator* is the least privileged role supported for this operation.
8+
> For delegated access using work or school accounts, the signed-in user must be a member user or be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. s*Privileged Role Administrator* is the least privileged role supported for this operation.

api-reference/beta/includes/rbac-for-apis/rbac-adminconsentrequestpolicy-apis-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
>
8-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation:
8+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
99
>
1010
> - Global Reader
1111
> - Cloud Application Administrator

api-reference/beta/includes/rbac-for-apis/rbac-adminconsentrequestpolicy-apis-update.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.topic: include
55

66
> [!IMPORTANT]
77
>
8-
> In delegated scenarios with work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role with a supported role permission. The following least privileged roles are supported for this operation:
8+
> For delegated access using work or school accounts, the signed-in user must be assigned a supported [Microsoft Entra role](/entra/identity/role-based-access-control/permissions-reference?toc=%2Fgraph%2Ftoc.json) or a custom role that grants the permissions required for this operation. This operation supports the following built-in roles, which provide only the least privilege necessary:
99
>
1010
> - Cloud Application Administrator
1111
> - Application Administrator

0 commit comments

Comments
 (0)