Application Permissions
Required Permissions
The below permissions are necessary for the operation of this web app.
User Permissions
Install SHIELD
Permission Name | What it is used for |
|---|---|
Global Administrator | To use the SHIELD installer link and install SHIELD into the Azure tenant. For more information, see How to Install SHIELDOverview and Installation Requirements. |
ℹ️ Note
Permissions marked with '✅' are assigned by SHIELD to itself. Permissions marked as '❌' have to be assigned by an admin ahead of time.
Entra ID Role Assignments
Permission Name | Self Auto Granted | What it is used for |
|---|---|---|
✅ | Used to delete privileged users as they have a privileged role lockout. The Graph API requires a sensitive permission assigned to the principal doing the API call. |
Microsoft Graph API
Permission Name | Self Auto Granted | What it is used for |
|---|---|---|
❌ | Used by the settings and update engine to update the permissions of the Azure App Service's Managed Identity to support new functionality in future updates or on initial startup. All permissions assigned will align with this page. If they do not and you are on the latest version, stop the app and contact us. | |
❌ | Used to create and maintain the app registration used to authenticate users to the API. Additionally used by the settings and update engine on permission assignment to convert app id and template IDs to tenant localized object IDs. | |
✅ | Used in Discover to read the access reviews that are configured in the tenant. | |
✅ | Used in Discover to be able to read directory objects such as users, group, devices, service principals, and their configurations. | |
✅ | Used in Discover to read the entitlement lifecycle management system's configurations such as access packages. | |
✅ | Used in Discover to evaluate the license liability for Entra ID Identity Protection. | |
✅ | Used in Discover to evaluate the license liability for Entra ID Identity Protection. | |
✅ | Used to read conditional access policy configurations. Conditional access policy reading is not included in Directory.Read.All | |
✅ | Used for reading PIM-based long term role assignments. Also needs RoleManagement.Read.All as a supporting permission otherwise permission errors occur. | |
✅ | Used for reading eligible PIM role assignments. Also needs RoleManagement.Read.All as a supporting permission otherwise permission errors occur. | |
✅ | Used for reading all PIM roles. | |
✅ | Used to read approver configurations in PIM. | |
✅ | Used in Discover to measure the Defender for Identity license lability. |
ℹ️ Note
Policy.Read.All is necessary due to a known issue with the current Graph API, in the future Policy.ReadWrite.ConditionalAccess/Policy.Read.ConditionalAccess will be all that is necessary. See this link for Microsoft's official statement: Graph API Known Issues Portal
SHI - Data Gateway
Permission Name | Self Auto Granted | What it is used for |
|---|---|---|
LicenseReport.ReadWrite | ✅ | Used to store the license report after a run of Discover has completed. |
Telemetry.Shield.ReadWrite | ✅ | Used by SHIELD to store its monthly telemetry report and keep it isolated from other tenants. |
UpdateShield.Check | ✅ | Used by SHIELD to check for updates. |
Grant-MIGraphPermission Usage
The Grant MI Graph Permission PowerShell script is an easy way to bulk apply permissions to managed identities using either the command line or a graphical picker. You can find the script here at the PowerShell gallery. You will need global admin rights or a role/rights that include the following MS GraphAPI permissions to apply the proper permissions to the Managed Identity:
- Directory.Read.All
- AppRoleAssignment.ReadWrite.All
- Application.ReadWrite.All
CLI usage for complete permissions assignment to a MI:
PowerShell
Where the parameter ObjectID's value is your Managed Identities' Object ID (GUID). 885c119e-caa1-4148-bc58-20e28ff4f3ce is not a real value, please replace it.
For more information about script usage, please run:
PowerShell