Skip to content

Latest commit

 

History

History
15 lines (11 loc) · 1.08 KB

rbac-pim-groups-apis-read-eligibilityschedules.md

File metadata and controls

15 lines (11 loc) · 1.08 KB
author ms.topic ms.date ms.author
ilyalushnikov
include
04/07/2023
ilyalushnikov

In delegated scenarios with work or school accounts, the signed-in user must be an owner or member of the group or be assigned a supported Microsoft Entra role or a custom role with a supported role permission. The following least privileged roles are supported for this operation.

  • For role-assignable groups: Global Reader or Privileged Role Administrator
  • For non-role-assignable groups: Global Reader, Directory Writer, Groups Administrator, Identity Governance Administrator, or User Administrator

The role assignments for the calling user should be scoped at the directory level.

Other roles with permissions to manage groups (such as Exchange Administrators for non-role-assignable Microsoft 365 groups) and administrators with assignments scoped at administrative unit level can manage groups through groups API and override changes made in Microsoft Entra PIM through PIM for groups APIs.