How to remove "RoleManagement.ReadWrite.Directory" permission
説明
How to remove "RoleManagement.ReadWrite.Directory" permission
対策
Manually
Grant the Migration - Basic consent.
Manually add the Migration - Basic Service Principle to the Exchange Admin Role and delete RoleManagement.ReadWrite.Directory permission on the Migration - Basic enterprise application.
Remove "RoleManagement.ReadWrite.Directory" from the Quest On Demand - Migration - Basic - Minimal
Exchange RBAC
Grant the Quest On Demand - Migration - Basic - Minimal consent
Open a SR with the OD Org ID and request the feature flag "migration.accounts.skipAssignExchangeAdminRole" be enabled.
Remove the RoleManagement.ReadWrite.Directory permissions from the Quest On Demand Migration - Basic – Minimal enterprise application
Get Application ID and Object ID for these two applications