Skip to content

Use Group.Create instead of Group.ReadWrite.All for group creation #4772

@marrobi

Description

@marrobi

AzureTRE currently grants Group.ReadWrite.All to its Application Admin just so it can create groups. Since November 2023, Microsoft Graph supports Group.Create, which is much more restrictive and matches the actual needs. Please update scripts and docs so only Group.Create is used unless broader group management is actually required.

Group.Create Graph permission docs

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions