platform-identity-graph
Type: decision
Decision
Landing zone identities receive granular Microsoft Graph read permissions — never broad directory access.
Why
Without them, applications cannot resolve tenant identities — user lookup and group-based authorization fail.
Violations
- Landing zone identity granted write permissions to Microsoft Graph
- Landing zone identity granted Directory.Read.All instead of granular read permissions.
Links
- landing-zone-identity — The single shared identity is what makes one permission grant sufficient to cover every workload in the landing zone.
← Back to knowledge graph