Inheritable Permissions
In brief
The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.
What Entra admins need to know
No administrator action is indicated; the documentation update does not clarify or change the supported inheritance patterns.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Review security implications. Ensure that inheritable permissions don't grant excessive access or expose sensitive resources beyond what's necessary. Regularly audit permission lists to maintain compliance and minimize risk.
Example scenarios
The following scenarios illustrate how different permission configurations serve different deployment needs.
@@ -124,8 +124,6 @@ When you configure required resource access and inheritable permissions for agen - **Review security implications.** Ensure that inheritable permissions don't grant excessive access or expose sensitive resources beyond what's necessary. Regularly audit permission lists to maintain compliance and minimize risk. -<!-- TODO: Confirm with engineering whether the enumerated scopes pattern (mentioned in manage-agent-identities-admin.md) is still a supported inheritance pattern or has been removed in favor of allAllowed/none only. -->- ## Example scenarios The following scenarios illustrate how different permission configurations serve different deployment needs. 