| MC1470871 | Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details |
|---|
| Classification | preventOrFixIssue |
|---|---|
| Last Updated | 09/11/2026 23:08:45 |
| Start Time | 09/11/2026 23:08:21 |
| End Time | 10/30/2026 07:00:00 |
| Message Content |
[What and why] We are correcting the behavior of the Microsoft Graph delegated and app-only permission User.ReadBasic.All. This permission is intended to provide access only to a limited set of basic user profile properties. However, it currently also allows access to user app role assignments and license details. To address a security vulnerability, we are removing access to user app role assignments and license details from User.ReadBasic.All and aligning the permission with its intended scope. This is not a breaking change for applications that use User.ReadBasic.All only for its intended purpose of accessing basic user profile information. Applications that rely on this unintended access should be updated with the appropriate least-privileged permissions before rollout is complete. [Rollout schedule]
[Impact on your organization] Who is affected Organizations are affected if their applications use the Microsoft Graph delegated or app-only permission User.ReadBasic.All to read:
Developers, application owners, and administrators responsible for managing application permissions in Microsoft Entra ID should review this change. Platforms and services
What will happen
[Action required and recommendations] Action is required if you have applications that use User.ReadBasic.All to access user app role assignments or license details. Recommended actions:
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. |
| Machine Translation |
[何となぜ] Microsoft Graphの委任権限およびアプリのみ権限である User.ReadBasic.Allの挙動を修正しています。この権限は、基本的なユーザープロファイルプロパティの限られたセットのみへのアクセスを提供することを目的としています。しかし現在は、ユーザーアプリの役割割り当てやライセンス詳細へのアクセスも許可しています。 セキュリティの脆弱性に対処するため、 User.ReadBasic.All からユーザーアプリの役割割り当てやライセンス詳細へのアクセスを削除し、権限を意図の範囲に整合させます。これは、 User.ReadBasic.All を使用するアプリケーションにとっては、基本的なユーザープロファイル情報へのアクセスという目的でのみ問題となる変更ではありません。 この意図しないアクセスに依存するアプリケーションは、ロールアウト完了前に適切な最小権限権限で更新されるべきです。 [展開スケジュール]
[組織への影響] 影響を受ける人物 組織は、アプリケーションがMicrosoft Graphの委任権限またはアプリのみ権限である User.ReadBasic.All を使って以下を読む場合に影響を受けます。
Microsoft Entra IDのアプリケーション権限管理を担当する開発者、アプリケーションオーナー、管理者はこの変更を検討すべきです。 ホームとサービス
何が起こるのか
[行動が必要と提言] User.ReadBasic.Allを使用しているアプリケーションでユーザーアプリの役割割り当てやライセンス詳細にアクセスする場合は、アクションが必要です。 推奨される行動:
[コンプライアンスの考慮事項] コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。 |