platform-identity-graph

Type: regulative

Decision

A landing zone identity must hold granular Microsoft Graph read permissions and no broad directory access.

Why

Without them, applications cannot resolve tenant identities, so user lookup and group-based authorization fail.

Violations

Anchor

no-platform-ops

Implements

Files

Links

← Back to knowledge graph