Loading...

Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details

Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details

User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions. We are correcting the behavior of the Microsoft Graph delegated and app-only permission User.ReadBasic.All. This permission is intended to provide access only to a limited set of basic user profile properties. However, it currently also allows access to user app role assignments and license details. To address a security vulnerability, we are removing access to user app role assignments and license details from User.ReadBasic.All and aligning the permission with its intended scope. This is not a breaking change for applications that use User.ReadBasic.All only for its intended purpose of accessing basic user profile information. Applications that rely on this unintended access should be updated with the appropriate least-privileged permissions before rollout is complete. Rollout schedule General Availability (Worldwide): Beginning in mid-September 2026 and expected to complete by late September 2026 Impact on your organization Who is affected Organizations are affected if their applications use the Microsoft Graph delegated or app-only permission User.ReadBasic.All to read: User app role assignments User license details Developers, application owners, and administrators responsible for managing application permissions in Microsoft Entra ID should review this change. Platforms and services Microsoft Graph Microsoft Entra ID Applications using Microsoft Graph permissions What will happen Applications granted only User.ReadBasic.All will no longer be able to read user app role assignments or user license details. Applications that access only basic user properties, such as display name, email address, and department, will continue to function without changes. Affected applications may experience failures or permission-related errors after the change is applied. Users may experience application disruptions if an application has only User.ReadBasic.All but attempts to access user app role assignments or license details. Action required and recommendations Action is required if you have applications that use User.ReadBasic.All to access user app role assignments or license details. Recommended actions: Review applications granted User.ReadBasic.All in the Microsoft Entra admin center under Enterprise applications > Permissions or […]

The post Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Dynamics 365 Field Service: Automate optimizations with Scheduling Operations Agent

This release expands the optimization capabilities of the Scheduling Operations Agent to include the ability to create recurring optimizations...

18 hours ago

Microsoft Teams: Call quality feedback surveys for Teams Rooms on Android

Microsoft Teams will introduce call quality feedback surveys for Teams Rooms on Android starting November 2026. Users can rate audio, video, a...

19 hours ago

Microsoft Edge: Retiring legacy sign-in implementation on Windows

Microsoft Edge on Windows will retire its legacy direct-WAM sign-in in version 157, fully adopting the OneAuth library to standardize authenti...

19 hours ago

Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

Microsoft Defender Vulnerability Management is privately previewing expanded vulnerability coverage for selected Node.js, Python, and Java pac...

19 hours ago

Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

Microsoft Defender for Office 365 extends Teams URL protection to detect malicious URLs in QR codes post-delivery, warning users and enabling ...

19 hours ago

Microsoft Teams: Analytics for desk utilization in Teams Pro Management portal

Microsoft Teams Pro Management portal will add desk utilization analytics, showing usage, reservations, occupancy, and peak patterns. Requires...

19 hours ago

‘Record A Skill’ Capability in PowerPoint Copilot

PowerPoint Copilot will introduce a “Record a Skill” feature in October 2026, allowing users to record and reuse workflows for com...

19 hours ago

Microsoft 365: Targeted Release retirement

Microsoft 365 Targeted Release will retire in January 2027, replaced by Frontier, Standard, and Deferred release options. Administrators must ...

19 hours ago

Interim guidance for Manitoba time zone changes

A time zone change affects Windows devices in Manitoba, with Windows releasing a fix in October 2026. Manitoba is permanently moving to UTC-5 ...

19 hours ago

Microsoft Purview DLP: Improved setup and Intune multi-admin approval support for unmanaged apps in Edge for Business

Starting November 2026, Microsoft Purview DLP will improve setup and support Intune multi-admin approval for unmanaged apps in Edge for Busine...

19 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.