entra1-5 Exercise 1: The Smallest Role That Does the Job ========================================================= Source: Microsoft Learn, "Least privileged roles by task", and "Default user permissions". Role lists change; re-check before asking a client for anything. (a) Read the sign-in logs for a failing app Smallest role: Reports Reader (Microsoft's least privileged role for reading audit and sign-in logs). Application Administrator and Cloud Application Administrator can also, but are bigger. You or them: Ask for Reports Reader for a limited time, or have the client's administrator share their screen. Never ask for more than you need. (b) See when a client secret expires Smallest role: The page on enterprise applications lists "read all configuration" as available to the default user role, and Microsoft's default-permissions table lets members and guests read properties of registered and enterprise applications. Whether the credential expiry dates on the registration are visible to a default guest is not something these pages state, so confirm it in the client's tenant. Fallback: Global Reader (read-only and broader), or the client's administrator reads the Certificates & secrets page to you. You or them: You can look if the tenant lets you; if not, ask them. (c) Create a new client secret Smallest role: The application's owner, or Application Administrator / Cloud Application Administrator. You or them: Whoever's tenant holds the registration. Arrangement A (your own multitenant app): you, in your own tenant. Arrangements B and C: the client's administrator. You should not ask for write access to a client's tenant for this; ask them to do it and send you the value securely. (d) Make a new SAML signing certificate active Smallest role: Per Microsoft's certificate tutorial: Privileged Role Administrator, Cloud Application Administrator or Application Administrator. Microsoft's task table also lists the enterprise application owner for updating single sign-on properties (owners added by Graph or PowerShell have some limits on SAML settings). You or them: The client's administrator, on the day, with your team ready to install the matching certificate on your side. (e) Read the provisioning logs Smallest role: Reports Reader (the enterprise application owner, Application Administrator and Cloud Application Administrator can also). You or them: As for (a): a limited-time Reports Reader, or a screen share. (f) Grant admin consent for a Microsoft Graph application permission Smallest role: On Microsoft's table, Privileged Role Administrator, with a note that in practice this typically requires Global Administrator. You or them: Always the client's administrator. Never request this level of role for a support case. THE PRINCIPLE ------------- Ask for the least that lets you see the evidence, for the shortest time, or ask the administrator to share their screen. Roles that change things (credentials, certificates, consent) belong to the tenant's owner. WHY THIS WORKS AS AN ANSWER --------------------------- It uses the documented roles instead of guessing, notes honestly where the documentation is silent (b), and separates "who can" from "who should", which is the judgement a vendor engineer has to make in a client's tenant.