What permissions do tenant members have when querying guests' open extensions?












1














We are trying to figure out what permissions are applicable to tenant members in regards to tenant guests' open extensions in Microsoft Graph.



The official documentation says permissions User.ReadBasic.All is available to any user by default and allows to read open extensions of all users. However, it is not clear if this is applicable to guest users as well or not.



Let's say we have a tenant tA, a tenant member uA and an external user uB (either member of another tenant, or a personal account). User uB has an open extension with some data. User uA adds uB as a guest to tenant A (for example, invites to a team in MS Teams). Shall user uA be able to read the open extension of uB?



I have tried this with Microsoft Graph Explorer. My test shows that




  • If user uB is a business user, i.e. a member of an organizational tenant B, then user uA cannot read the extension data. uA can find the user, read profile, but expanding extensions returns nothing.

  • If user uB is a personal account, e.g. some_user@outlook.com, then uA can read extension data.


It looks like for business accounts, user object extensions are visible only to the tenant that created the user, but not to inviting tenants. For personal accounts, however, looks like there are no restrictions, as if MS Graph user objects were created in the inviting tenant.



What are the specifications for accessing data of a guest user? Are they published anywhere?










share|improve this question
























  • I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
    – Marc LaFleur
    Nov 15 at 2:15


















1














We are trying to figure out what permissions are applicable to tenant members in regards to tenant guests' open extensions in Microsoft Graph.



The official documentation says permissions User.ReadBasic.All is available to any user by default and allows to read open extensions of all users. However, it is not clear if this is applicable to guest users as well or not.



Let's say we have a tenant tA, a tenant member uA and an external user uB (either member of another tenant, or a personal account). User uB has an open extension with some data. User uA adds uB as a guest to tenant A (for example, invites to a team in MS Teams). Shall user uA be able to read the open extension of uB?



I have tried this with Microsoft Graph Explorer. My test shows that




  • If user uB is a business user, i.e. a member of an organizational tenant B, then user uA cannot read the extension data. uA can find the user, read profile, but expanding extensions returns nothing.

  • If user uB is a personal account, e.g. some_user@outlook.com, then uA can read extension data.


It looks like for business accounts, user object extensions are visible only to the tenant that created the user, but not to inviting tenants. For personal accounts, however, looks like there are no restrictions, as if MS Graph user objects were created in the inviting tenant.



What are the specifications for accessing data of a guest user? Are they published anywhere?










share|improve this question
























  • I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
    – Marc LaFleur
    Nov 15 at 2:15
















1












1








1







We are trying to figure out what permissions are applicable to tenant members in regards to tenant guests' open extensions in Microsoft Graph.



The official documentation says permissions User.ReadBasic.All is available to any user by default and allows to read open extensions of all users. However, it is not clear if this is applicable to guest users as well or not.



Let's say we have a tenant tA, a tenant member uA and an external user uB (either member of another tenant, or a personal account). User uB has an open extension with some data. User uA adds uB as a guest to tenant A (for example, invites to a team in MS Teams). Shall user uA be able to read the open extension of uB?



I have tried this with Microsoft Graph Explorer. My test shows that




  • If user uB is a business user, i.e. a member of an organizational tenant B, then user uA cannot read the extension data. uA can find the user, read profile, but expanding extensions returns nothing.

  • If user uB is a personal account, e.g. some_user@outlook.com, then uA can read extension data.


It looks like for business accounts, user object extensions are visible only to the tenant that created the user, but not to inviting tenants. For personal accounts, however, looks like there are no restrictions, as if MS Graph user objects were created in the inviting tenant.



What are the specifications for accessing data of a guest user? Are they published anywhere?










share|improve this question















We are trying to figure out what permissions are applicable to tenant members in regards to tenant guests' open extensions in Microsoft Graph.



The official documentation says permissions User.ReadBasic.All is available to any user by default and allows to read open extensions of all users. However, it is not clear if this is applicable to guest users as well or not.



Let's say we have a tenant tA, a tenant member uA and an external user uB (either member of another tenant, or a personal account). User uB has an open extension with some data. User uA adds uB as a guest to tenant A (for example, invites to a team in MS Teams). Shall user uA be able to read the open extension of uB?



I have tried this with Microsoft Graph Explorer. My test shows that




  • If user uB is a business user, i.e. a member of an organizational tenant B, then user uA cannot read the extension data. uA can find the user, read profile, but expanding extensions returns nothing.

  • If user uB is a personal account, e.g. some_user@outlook.com, then uA can read extension data.


It looks like for business accounts, user object extensions are visible only to the tenant that created the user, but not to inviting tenants. For personal accounts, however, looks like there are no restrictions, as if MS Graph user objects were created in the inviting tenant.



What are the specifications for accessing data of a guest user? Are they published anywhere?







azure-active-directory microsoft-graph






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Nov 15 at 2:02









Marc LaFleur

18.6k31833




18.6k31833










asked Nov 13 at 16:53









Pavel Gatilov

6,80411934




6,80411934












  • I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
    – Marc LaFleur
    Nov 15 at 2:15




















  • I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
    – Marc LaFleur
    Nov 15 at 2:15


















I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
– Marc LaFleur
Nov 15 at 2:15






I retagged in hopes one of the AAD folks will catch this but, FTR, it sounds like a bug to me. Your description of how the AAD account behaves is my understanding of the intended behavior: User.ReadBasic.All doesn't return extensions, User.Read.All (or User.Read for reading the current user's extensions) does. Regardless, the behavior obviously should at least be the same for both AAD and MSA guests. You may want to open a support ticket with AAD directly and have them take a look.
– Marc LaFleur
Nov 15 at 2:15



















active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53285925%2fwhat-permissions-do-tenant-members-have-when-querying-guests-open-extensions%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown






























active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.





Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


Please pay close attention to the following guidance:


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53285925%2fwhat-permissions-do-tenant-members-have-when-querying-guests-open-extensions%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Guess what letter conforming each word

Port of Spain

Run scheduled task as local user group (not BUILTIN)