Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions. We are correcting the behavior of the Microsoft Graph delegated and app-only permission User.ReadBasic.All. This permission is intended to provide access only to a limited set of basic user profile properties. However, it currently also allows access to user app role assignments and license details. To address a security vulnerability, we are removing access to user app role assignments and license details from User.ReadBasic.All and aligning the permission with its intended scope. This is not a breaking change for applications that use User.ReadBasic.All only for its intended purpose of accessing basic user profile information. Applications that rely on this unintended access should be updated with the appropriate least-privileged permissions before rollout is complete. Rollout schedule General Availability (Worldwide): Beginning in mid-September 2026 and expected to complete by late September 2026 Impact on your organization Who is affected Organizations are affected if their applications use the Microsoft Graph delegated or app-only permission User.ReadBasic.All to read: User app role assignments User license details Developers, application owners, and administrators responsible for managing application permissions in Microsoft Entra ID should review this change. Platforms and services Microsoft Graph Microsoft Entra ID Applications using Microsoft Graph permissions What will happen Applications granted only User.ReadBasic.All will no longer be able to read user app role assignments or user license details. Applications that access only basic user properties, such as display name, email address, and department, will continue to function without changes. Affected applications may experience failures or permission-related errors after the change is applied. Users may experience application disruptions if an application has only User.ReadBasic.All but attempts to access user app role assignments or license details. Action required and recommendations Action is required if you have applications that use User.ReadBasic.All to access user app role assignments or license details. Recommended actions: Review applications granted User.ReadBasic.All in the Microsoft Entra admin center under Enterprise applications > Permissions or […]
The post Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Teams: Enhanced real-time alerting rule management in the Teams admin center
Microsoft Teams will enhance Real-Time Alerting rule management in the Teams admin center by enabling rule duplication, bulk user uploads, and...
Copilot Studio – Use MCP-compliant tools in agent workflows
We are announcing the ability to use MCP (model context protocol) – compliant tools in agent workflows in Microsoft Copilot Studio. This...
Microsoft Teams: Personal message reminders for chat and channels
Microsoft Teams will introduce personal message reminders for chat and channel messages in October 2026. Users can set, manage, and receive no...
M365 Copilot: Tell Copilot what you need directly from the Copilot button in Word, Excel, and PowerPoint
Microsoft 365 Copilot adds a new prompt input directly on the Copilot button in Word, Excel, and PowerPoint for faster, contextual content cre...
Microsoft Outlook for iPad: Minimize email drafts and return to them later
Outlook for iPad will allow users to compose emails in a separate window and minimize drafts to return later, enhancing multitasking. This fea...
Microsoft Purview eDiscovery: Select user-owned SharePoint Embedded containers as a data source
Microsoft Purview eDiscovery will support selecting user-owned SharePoint Embedded containers as data sources for cases, searches, and holds s...
Microsoft Purview: Removing pay-as-you-go requirements for Edge for Business DLP unmanaged app protections
Starting mid-October 2026, Microsoft Purview will remove the pay-as-you-go billing requirement for inline collection and DLP policies protecti...
Data Privacy: Microsoft Online Services Subprocessor Disclosure
This notice provides an update to the Microsoft Online Services Subprocessors List. Microsoft may engage non-Microsoft organizations to help p...
30-Day Reminder: Windows Server 2022 will reach end of mainstream support on October 13, 2026
On October 13, 2026, Windows Server 2022 will reach end of mainstream support. The October 2026 security update will be the last mainstream su...
Microsoft Copilot Cost Management: September Updates
September 2026 updates to Microsoft Copilot Cost Management introduce auto-application of new services to spending policies, user spending ale...