Skip to content

Weekly Permissions sync 2026-08-11 - #1594

Open
David (marabooy) wants to merge 1 commit into
masterfrom
permissions-update/2026-08-11
Open

Weekly Permissions sync 2026-08-11#1594
David (marabooy) wants to merge 1 commit into
masterfrom
permissions-update/2026-08-11

Conversation

@marabooy

Copy link
Copy Markdown
Contributor

Weekly Permissions sync 2026-08-11

@marabooy
David (marabooy) requested a review from a team as a code owner August 11, 2026 20:40
Copilot AI lite review requested due to automatic review settings August 11, 2026 20:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Weekly permissions sync updating the permissions/new catalogs used by DevX/Graph Explorer for permission deployment metadata and API-path-to-scope mappings.

Changes:

  • Updated provisioningInfo.json deployment metadata (Zone visibility flags, Fairfax environment tagging) and added deployment entries for CopilotCostManagement.Read.All.
  • Added lifecycle workflows subject-processing-results summary route mapping.
  • Added new permission definitions for Zone.Read.All and Zone.ReadWrite.All, including their path sets.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
permissions/new/provisioningInfo.json Updates permission deployment metadata (visibility/environment) and adds a new permission deployment entry.
permissions/new/permissions.json Extends path mappings and introduces Zone permission definitions and HTTP method coverage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +64588 to +64592
"adminDescription": "Allows the app to read, create, update, and delete Zones and manage their environments in Microsoft Defender for Cloud for the signed-in user.",
"userDisplayName": "Read and manage all Zones in Microsoft Defender for Cloud",
"userDescription": "Allows the app to read, create, update, and delete Zones and manage their environments in Microsoft Defender for Cloud on behalf of the signed-in user..",
"requiresAdminConsent": true,
"privilegeLevel": 3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants