Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

5
  • If you donot want the 3rd app to read full profile from your aad, you should not grant them the permission to your aad. A custom api for them should be the best choice for your concern of security risk. Commented Aug 4, 2018 at 5:48
  • I don't need to restrict the return from the user.readBasic.all, I want this permission to be available as an app permission. Currently all I can use is Directory.Read.all which is too open. Commented Aug 5, 2018 at 22:26
  • Because what you want is not int the current api, so I think you can submit a request in the UserVoice:officespdev.uservoice.com/forums/… Commented Aug 6, 2018 at 1:23
  • If you still want to set the "Read all users' basic profiles" in the azure portal "not delegated", we cannot do it now. The "Read all users' basic profiles" is not default app permission. Commented Aug 6, 2018 at 1:47
  • Thanks. I've submitted a request. Commented Aug 7, 2018 at 11:03