Plan for Change: Updates to required permissions for Microsoft Graph Beta API deviceManagement

Starting July 31, 2025, Microsoft Graph Beta API deviceManagement will require either DeviceManagementScripts.Read.All or DeviceManagementScripts.ReadWrite.All permissions. Update any apps, scripts, or tools to include these permissions and remove the old ones. Detailed instructions are available in the provided links.

Starting July 31, 2025, or soon after, the following Graph APIs will require either DeviceManagementScripts.Read.All or DeviceManagementScripts.ReadWrite.All permissions to continue working:

How this will affect your organization:

Previously, these Graph APIs required granting either DeviceManagementConfiguration.ReadWrite.All or DeviceManagementConfiguration.Read.All permissions. If you have any enterprise applications, scripts or other tools that have been granted these permissions they will need to be updated in order to continue calling the listed Graph APIs.  

What you need to do to prepare:

Ensure any apps, scripts, or tooling that reference the listed Graph APIs include either DeviceManagementScripts.Read.All or DeviceManagementScripts.ReadWrite.All permissions and remove the old permissions: DeviceManagementConfiguration.ReadWrite.All or DeviceManagementConfiguration.Read.All.

For detailed instructions for updating permissions for applications, refer to: Update an app’s requested permissions in Microsoft Entra ID

Message ID: MC1066336


Comments are closed.


I've been working with Microsoft Technologies over the last ten years, mainly focused on creating collaboration and productivity solutions that drive the adoption of Microsoft Modern Workplace.

%d bloggers like this: