We are delighted to announce an update to our Azure Multitenant Applications, introducing enhanced permission modification capabilities. This release brings important improvements to the application’s functionality and security, ensuring a seamless experience for our valued customers.
Added Permissions:
Swisscom M365 Backup as a Service
AppId: ec2c8e17-afaa-4583-8a32-9b7530b7c118
Add ChannelMember.ReadWrite.All (D) (Microsoft Graph) permission, required to restore channel memberships in Microsoft Teams on behalf of the signed-in user.
Add ChannelMessage.Read.All (A) (Microsoft Graph) permission, required to back up channel messages in Microsoft Teams without a signed-in user.
Add Directory.Read.All (D) (Microsoft Graph) permission, required to read directory data for Exchange Online, Microsoft Teams, and SharePoint Online backup and restore operations on behalf of the signed-in user.
Add Directory.Read.All (A) (Microsoft Graph) permission, required to read directory data for unattended Exchange Online, Microsoft Teams, and SharePoint Online backup and restore operations.
Add Directory.ReadWrite.All (D) (Microsoft Graph) permission, required to restore directory data for Exchange Online, Microsoft Teams, and SharePoint Online on behalf of the signed-in user.
Add Directory.ReadWrite.All (A) (Microsoft Graph) permission, required to restore directory data during unattended Exchange Online, Microsoft Teams, and SharePoint Online operations.
Add Files.ReadWrite.All (A) (Microsoft Graph) permission, required to back up and restore files in Microsoft Teams and SharePoint Online site collections.
Add Group.Read.All (A) (Microsoft Graph) permission, required to back up Microsoft 365 group properties, memberships, and conversations.
Add Group.ReadWrite.All (D) (Microsoft Graph) permission, required to restore Microsoft 365 groups and memberships on behalf of the signed-in user.
Add Group.ReadWrite.All (A) (Microsoft Graph) permission, required to restore Microsoft 365 groups and memberships without a signed-in user.
Add MailboxFolder.ReadWrite (D) (Microsoft Graph) permission, required to back up and restore mailbox folders on behalf of the signed-in user.
Add MailboxFolder.ReadWrite.All (A) (Microsoft Graph) permission, required to back up and restore mailbox folders for all users without a signed-in user.
Add MailboxItem.ImportExport (D) (Microsoft Graph) permission, required to export and restore mailbox items on behalf of the signed-in user.
Add MailboxItem.ImportExport.All (A) (Microsoft Graph) permission, required to export and restore mailbox items for all users without a signed-in user.
Add MailboxItem.Read (D) (Microsoft Graph) permission, required to read mailbox items for backup on behalf of the signed-in user.
Add MailboxItem.Read.All (A) (Microsoft Graph) permission, required to read mailbox items for backup across all users without a signed-in user.
Add offline_access (D) (Microsoft Graph) permission, required to continue authorized backup and restore operations when the signed-in user is not actively using the application.
Add Sites.Read.All (D) (Microsoft Graph) permission, required to back up documents and list items in Microsoft Teams and SharePoint Online on behalf of the signed-in user.
Add Sites.Read.All (A) (Microsoft Graph) permission, required to back up documents and list items in Microsoft Teams and SharePoint Online without a signed-in user.
Add TeamSettings.ReadWrite.All (A) (Microsoft Graph) permission, required to back up and restore Microsoft Teams settings without a signed-in user.
Add User.Read.All (D) (Microsoft Graph) permission, required to read user profiles for Exchange Online, Microsoft Teams, and SharePoint Online backup and restore operations on behalf of the signed-in user.
Add User.Read.All (A) (Microsoft Graph) permission, required to read user profiles for unattended Exchange Online, Microsoft Teams, and SharePoint Online backup and restore operations.
Add EWS.AccessAsUser.All (D) (Office 365 Exchange Online) permission, required to access Exchange Online mailboxes through Exchange Web Services on behalf of the signed-in user.
Add Exchange.ManageAsApp (A) (Office 365 Exchange Online) permission, required to perform Exchange Online management operations using app-only authentication.
Add full_access_as_app (A) (Office 365 Exchange Online) permission, required to back up and restore all Exchange Online mailboxes through Exchange Web Services using app-only authentication.
Add AllSites.FullControl (D) (SharePoint) permission, required to back up and restore SharePoint Online site collections on behalf of the signed-in user.
Add Sites.FullControl.All (A) (SharePoint) permission, required to back up and restore all SharePoint Online site collections without a signed-in user.
Add User.Read.All (D) (SharePoint) permission, required to read SharePoint user profiles during backup and restore operations on behalf of the signed-in user.
Add User.Read.All (A) (SharePoint) permission, required to read SharePoint user profiles during unattended backup and restore operations.
Permission type: (A) Application, (D) Delegated.
Modified Roles:
Swisscom M365 DLP
AppId: 7f0a552f-7c0e-4afb-96da-1d1f189a6485
Update the ASA_M365_DLPaaSOperator-Role role group with the following role assignments:
Permanently active:
- Security Reader, required to provide read-only access to security information, alerts, and reports.
Eligible via Privileged Identity Management (PIM):
- Compliance Data Administrator, required to monitor compliance policies, manage compliance alerts, and work with compliance data.
- Content Explorer List viewer, required to view classified items and their locations in Microsoft Purview Content Explorer without access to their contents.
Learn more: Microsoft Entra built-in roles and Content Explorer permissions.
Added Roles:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add the ASA_M365_ApplicationAdmin-Role role group with the following role assignments:
Permanently active:
- Attribute Assignment Reader
- Attribute Definition Reader
- Directory Readers
- Message Center Reader
- Reports Reader
- Service Support Administrator
These roles provide the read-only directory, custom security attribute, service message, reporting, service health, and support capabilities required for regular application administration.
Eligible via Privileged Identity Management (PIM):
- Application Administrator
- Attribute Assignment Administrator
- Edge Administrator
- Office Apps Administrator
These roles provide elevated administration of applications, custom security attribute assignments, Microsoft Edge, and Microsoft 365 Apps only when activated through PIM.
Learn more: Microsoft Entra built-in roles.
Modified Permissions:
Swisscom M365 Phone System
AppId: 2bdd1880-78e3-413b-a4d6-5753955eaee5
In an effort to ensure a least priviledged approach, the Global Reader Role requirement has been removed for the Swisscom M365 Phone System App.
At the same time, Microsoft introduced the following new requirements for Entra ID Applications using the Microsoft Teams PowerShell Module:
Add RoleManagement.Read.Directory permission, required by Entra applications to authenticate against the Microsoft Teams PowerShell Module.
Add GroupMember.Read.All permission, required by Entra applications to authenticate against the Microsoft Teams PowerShell Module.
Learn more: Application-based authentication in Teams PowerShell Module.
These Applications are not involved in this release:
Swisscom M365 Foundation
AppId: 217d642e-c258-4597-a7f3-3573b3c8a813
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Swisscom M365 Backup as a Service
AppId: ec2c8e17-afaa-4583-8a32-9b7530b7c118
Swisscom M365 Endpoint Management
AppId: bf79789e-4016-4591-9079-0200fd0389df
Swisscom M365 Backup as a Service
AppId: ec2c8e17-afaa-4583-8a32-9b7530b7c118
Swisscom Threat Detection and Response
AppId: 3e8f866e-d64b-4197-956e-c5cf852e54cd
Swisscom MCC Microsoft
AppId: a59996f7-560b-4349-80a9-9f65c68a8386
Swisscom Enterprise Workspace
AppId: de007c00-80c4-4ba3-a281-b9d9635a5407
Swisscom Microsoft XDR as a Service
AppId: 61f68604-cf24-4530-b5c1-4530a43460d7
Swisscom M365 DLP
AppId: 7f0a552f-7c0e-4afb-96da-1d1f189a6485
Modified Permissions:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add M365 License Manager → Policy.ReadWrite.AllowSelfServicePurchase permission to the application. Allow/deny license selfservice purchase.
Add Microsoft Graph → RoleManagementPolicy.ReadWrite.AzureADGroup permission to the application. Read and write role management policies for Azure AD groups.
Add Microsoft Graph → PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup permission to the application. Read and write PIM schedules for Azure AD groups.
Add Microsoft Graph → CustomSecAttributeDefinition.ReadWrite.All permission to the application. Read and write custom security attribute definitions.
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Foundation | 217d642e-c258-4597-a7f3-3573b3c8a813 |
| Swisscom M365 Phone System | 2bdd1880-78e3-413b-a4d6-5753955eaee5 |
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom M365 Backup as a Service | ec2c8e17-afaa-4583-8a32-9b7530b7c118 |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Modified Permissions:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add ProjectWorkManagement → OrgSettings-Planner.ReadWrite.All permission to the application. This permission is required by the DSC version 1.25.402.1.
Add Insights Administrator role to the application. This role is required by DSC to handle Organisation settings.
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Foundation | 217d642e-c258-4597-a7f3-3573b3c8a813 |
| Swisscom M365 Phone System | 2bdd1880-78e3-413b-a4d6-5753955eaee5 |
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom M365 Backup as a Service | ec2c8e17-afaa-4583-8a32-9b7530b7c118 |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Modified Permissions:
Swisscom M365 Foundation
AppId: 217d642e-c258-4597-a7f3-3573b3c8a813
In an effort to ensure a least priviledged approach and usabilty of the Foundation for multiple services, following permissions have been removed from the Foundation application and by case added to other services that require them for operations:
Remove Agreement.ReadWrite.All
Remove Directory.Read.All
Remove Directory.ReadWrite.All
Remove Group.Read.All
Remove GroupMember.Read.All
Remove GroupMember.ReadWrite.All
Remove Member.Read.Hidden
Remove Organization.ReadWrite.All
Remove Policy.ReadWrite.ApplicationConfiguration
Remove Policy.ReadWrite.AuthenticationMethod
Remove Policy.ReadWrite.Authorization
Remove RoleManagement.Read.Directory
Remove User.Read.All
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add Organization.ReadWrite.All permission to the application. This role is required to cover functionalities previously handeled by the Foundation application and is only used by the Management Service.
Add Policy.ReadWrite.AuthenticationMethod permission to the application. This role is required to cover functionalities previously handeled by the Foundation application and is only used by the Management Service
Swisscom M365 Phone System
AppId: 2bdd1880-78e3-413b-a4d6-5753955eaee5
Add Group.ReadWrite.All permission, required by UCC Profile Onboarding (no longer performed with personal account).
Add Organization.Read.All permission, required by UCC Profile Onboarding (no longer performed with personal account).
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom M365 Backup as a Service | ec2c8e17-afaa-4583-8a32-9b7530b7c118 |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Modified Roles:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add Security Administrator role to the application. This role is required by the DSC to manage Role Groups in the Purview Portal.
Remove Security Operator role from the application. This role requirement is obsolete with adding the Security Administrator role.
Swisscom M365 Backup as a Service
AppId: ec2c8e17-afaa-4583-8a32-9b7530b7c118
Add ChannelMember.ReadWrite.All permissionm. This role is required by the backup application.
Add Files.ReadWrite.All permission. This role is required by the backup application.
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Foundation | 217d642e-c258-4597-a7f3-3573b3c8a813 |
| Swisscom M365 Phone System | 2bdd1880-78e3-413b-a4d6-5753955eaee5 |
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Modified Permissions:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add SharePointTenantSettings.ReadWrite.All permission to the application. This permission is required by the DSC version 1.24.619.1.
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Foundation | 217d642e-c258-4597-a7f3-3573b3c8a813 |
| Swisscom M365 Phone System | 2bdd1880-78e3-413b-a4d6-5753955eaee5 |
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom M365 Backup as a Service | ec2c8e17-afaa-4583-8a32-9b7530b7c118 |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Modified Permissions:
Swisscom M365 Management
AppId: 61231e0c-8598-42cb-a068-73f45159d616
Add Reports.Read.All permission to the application. With this permission we are able to read the Sharepoint Limit and react accordingly.
These Applications are not involved in this release:
| Application Name | AppId |
|---|---|
| Swisscom M365 Foundation | 217d642e-c258-4597-a7f3-3573b3c8a813 |
| Swisscom M365 Phone System | 2bdd1880-78e3-413b-a4d6-5753955eaee5 |
| Swisscom M365 Endpoint Management | bf79789e-4016-4591-9079-0200fd0389df |
| Swisscom M365 Backup as a Service | ec2c8e17-afaa-4583-8a32-9b7530b7c118 |
| Swisscom Threat Detection and Response | 3e8f866e-d64b-4197-956e-c5cf852e54cd |
| Swisscom MCC Microsoft | a59996f7-560b-4349-80a9-9f65c68a8386 |
| Swisscom Enterprise Workspace | de007c00-80c4-4ba3-a281-b9d9635a5407 |
| Swisscom Microsoft XDR as a Service | 61f68604-cf24-4530-b5c1-4530a43460d7 |
| Swisscom M365 DLP | 7f0a552f-7c0e-4afb-96da-1d1f189a6485 |
Additional Information:
For further details on the updated permission modification features and other enhancements, please refer to our comprehensive documentation available at docs.swisscom.ch.
We value your feedback. If you have any questions, encounter any issues, or would like to provide suggestions for future updates, please don’t hesitate to contact our support team.
Thank you for your continued support and trust in our Azure Multitenant Applications. We remain committed to delivering an exceptional experience and meeting your evolving needs.