Skip to content

Content update - #75

Merged
Elliot Huffman (elliot-huffman) merged 6 commits into
publicfrom
main
Aug 14, 2026
Merged

Content update#75
Elliot Huffman (elliot-huffman) merged 6 commits into
publicfrom
main

Conversation

@jtdauria-shi

Copy link
Copy Markdown
Contributor
  • Onboarding documentation
  • Policy structure
  • Update Zensicle

jtdauria-shi and others added 6 commits July 28, 2026 16:27
Updated installation, prereqs, network inspection, & app permissions to enhance customer onboarding and converted multiple policy pages into a single page
…tallationUpdates

Updated customer onboarding + policy structure
Copilot AI lite review requested due to automatic review settings August 14, 2026 22:00
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedzensical@​0.0.51 ⏵ 0.0.539710010010080

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical-0.0.53/python/zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (zensical/templates/assets/javascripts/LICENSE)

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: pypi zensical under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (zensical/templates/assets/javascripts/LICENSE)

License: Font-Awesome-Free-License-6.x - The applicable license policy does not permit this license (5) (zensical/templates/.icons/fontawesome/LICENSE.txt)

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 65.0% likely risky

Notes: This fragment is primarily a configuration parser, but it contains security-relevant design choices that can become malicious impact if an attacker can control configuration inputs: it uses yaml.load with a potentially unsafe Loader and supports dynamic importing/calling of callables specified by dotted strings from config (_resolve + invocation in multiple extension hooks). It also imports modules listed in macros config (importlib.import_module) with side effects. If configs/themes/macros are trusted, risk may be acceptable; if untrusted, this is effectively a code-execution primitive. The snippet also appears truncated/buggy at the end (_convert_plugins returns an undefined variable), so additional context is needed for a complete assessment.

Confidence: 0.65

Severity: 0.70

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Potential security risk (AI signal): pypi zensical is 65.0% likely risky

Notes: This fragment is primarily a configuration parser, but it contains security-relevant design choices that can become malicious impact if an attacker can control configuration inputs: it uses yaml.load with a potentially unsafe Loader and supports dynamic importing/calling of callables specified by dotted strings from config (_resolve + invocation in multiple extension hooks). It also imports modules listed in macros config (importlib.import_module) with side effects. If configs/themes/macros are trusted, risk may be acceptable; if untrusted, this is effectively a code-execution primitive. The snippet also appears truncated/buggy at the end (_convert_plugins returns an undefined variable), so additional context is needed for a complete assessment.

Confidence: 0.65

Severity: 0.70

From: requirements.txtpypi/[email protected]

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates SHIELD documentation structure by reorganizing the nav, replacing the old “Required Graph API Permissions” doc with a new “Application Permissions” page, consolidating Conditional Access policy docs into a single “Entra Conditional Access” reference page, and bumping the zensical version used to build the site.

Changes:

  • Updated zensical.toml nav to reflect new prerequisite pages and a new “Policies” section under Deploy reference.
  • Replaced the removed “Required Graph API Permissions” page with a new “Application Permissions” page and updated an internal link.
  • Consolidated many Conditional Access policy pages into Entra-Conditional-Access.md and updated the docs tool version in requirements.txt.

Reviewed changes

Copilot reviewed 26 out of 27 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
zensical.toml Updates site navigation to new prerequisites and the new Deploy → Reference → Policies structure.
requirements.txt Bumps zensical from 0.0.51 to 0.0.53.
docs/SHIELD/Reference/Settings/Configure-Managed-Identity.md Updates the permissions doc link to point to the new page.
docs/SHIELD/Prerequisites/Required-Graph-API-Permissions.md Removes the old permissions page.
docs/SHIELD/Prerequisites/Network-Traffic-Inspection.md Adds a new prerequisite page describing network traffic inspection constraints.
docs/SHIELD/Prerequisites/Installation.md Rewrites installation/onboarding steps and networking requirements text.
docs/SHIELD/Prerequisites/index.md Expands prerequisites landing page with pricing/security/data-structure content and reorganized sections.
docs/SHIELD/Prerequisites/Application-Permissions.md Adds the replacement permissions page and permission tables.
docs/SHIELD/Deploy/Reference/Policies/Entra-Conditional-Access.md Adds consolidated Conditional Access policy documentation.
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/User-Risk.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Token-Binding.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Sign-In-Risk.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Session-Persistence.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/OS-Enforcement.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/MFA.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Location.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Legacy-Auth.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Join-Type.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Hardware-Enforcement.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Disable-CA-Resilience-Downgrade.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Compliance.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Block-Non-Priv.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Privileged/Conditional-Access/Authentication-Methods.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/MFA.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/MDCA.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/Location.md Removes legacy per-policy page (now consolidated).
docs/SHIELD/Deploy/Reference/Architecture/SHIELD/Enterprise/Conditional-Access/Compliance.md Removes legacy per-policy page (now consolidated).
Suppressed comments (2)

docs/SHIELD/Prerequisites/Application-Permissions.md:89

  • Same admonition formatting issue as above: the unindented blank line after !!! note may break rendering (and turn the following indented text into a code block).
!!! note

    `Policy.Read.All` is necessary due to a known issue with the current Graph API, in the future `Policy.ReadWrite.ConditionalAccess`/`Policy.Read.ConditionalAccess` will be all that is necessary.
    See this link for Microsoft's official statement: [Graph API Known Issues Portal](https://developer.microsoft.com/en-us/graph/known-issues/?search=13671)

docs/SHIELD/Prerequisites/Application-Permissions.md:80

  • Typo: “license lability” should be “license liability”.
    | [`SecurityIdentitiesAccount.Read.All`](https://learn.microsoft.com/en-us/graph/permissions-reference#securityidentitiesaccountreadall){:target="_blank"}                                                                                                                   | ✅                | Used in Discover to measure the Defender for Identity license lability.                                                                                                                                                                                                                                               |

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +17 to +19
!!! note

Permissions marked with '✅' are assigned by SHIELD to itself. Permissions marked as '❌' have to be assigned by an admin ahead of time.
The PowerShell app will graphically list all the managed identities, let you select one, then graphically list all the Graph API permissions you can assign it.
Assign the permissions listed here:
[Required Graph API Permissions](../../Prerequisites/Required-Graph-API-Permissions)
[Required Graph API Permissions](../../Prerequisites/Application-Permissions)
## Overview

This application is a self-hosted application that exists in the customer tenant on an Azure App Service, collecting and processing the requisite data only within the customer tenant before provided abstracted & fully anonymized data results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement.
SHIELD is a self-hosted application deployed in a customer’s Azure App Service tenant. SHIELD collects and processes all necessary data exclusively within the customer’s environment, then returns only abstracted and fully anonymized results back to SHI for reporting. All requirements can be set up by the delivery team or customer prior to engagement. This guide explains how to install the SHIELD - Desktop application and run your first scan. For more information about requirements, pricing, and more, see [Prerequisites](/SHIELD/Prerequisites).
- According to [Microsoft Documentation](http://aka.ms/pnc){:target="_blank"}, Traffic Inspection of any kind via a tool like Palo, Zscaler, or nginx (caching) violates Microsoft's Terms & Conditions (as well as each major cloud provider) as traffic that was decrypted and is heading to Microsoft is indistinguishable from man in the middle attacks.
- As a result, all traffic inspected is promptly dropped by Microsoft. As we rely on Azure Networking for SHIELD to run, this prevents SHIELD from functioning.
- Please validate that **ALL** Microsoft traffic is excluded from any form of Network Inspection: this is a requirement for SHIELD to function, as it is against Microsoft's terms and conditions.
For a smooth installation, network traffic inspection must be disabled on the device installing SHIELD. If inspection is enabled, Microsoft will drop the traffic, and SHIELD will not function properly. This includes tools like Palo, Zscaler, or nginx (caching). Traffic inspection must be excluded from network inspection according to Microsoft's terms and conditions. For more information, see [Microsoft Documentation](http://aka.ms/pnc){:target="_blank"}.
| [`IdentityRiskEvent.Read.All`](https://learn.microsoft.com/en-us/graph/permissions-reference#identityriskeventreadall){:target="_blank"} | ✅ | Used in Discover to evaluate the license liability for Entra ID Identity Protection. |
| [`IdentityRiskyUser.Read.All`](https://learn.microsoft.com/en-us/graph/permissions-reference#identityriskyuserreadall){:target="_blank"} | ✅ | Used in Discover to evaluate the license liability for Entra ID Identity Protection. |
| [`Policy.Read.All`](https://learn.microsoft.com/en-us/graph/permissions-reference#policyreadall){:target="_blank"} and [`Policy.ReadWrite.ConditionalAccess`](https://learn.microsoft.com/en-us/graph/permissions-reference#policyreadwriteconditionalaccess){:target="_blank"} | ✅ | Used to manage the conditional access policies for individual users during the lifecycle management and for when the initial deployment occurs to implement health checks, and identity partitioning. |
| [`SecurityIdentitiesAccount.Read.All`](https://learn.microsoft.com/en-us/graph/permissions-reference#securityidentitiesaccountreadall){:target="_blank"} | ✅ | Used in Discover to measure the Defender for Identity license lability. |
@elliot-huffman
Elliot Huffman (elliot-huffman) merged commit 2602bbe into public Aug 14, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants