Microsoft Corporation
Automatic reduction of permissions for client applications

Last updated:

Abstract:

A least-privilege permission or permissions is automatically assigned to a client application in order to ensure that the client application is able to perform the bare minimum actions on a resource. The client application accesses the protected resource using a web API. The determination of the least-privilege permission(s) is based on actions previously performed on the resource by the client application. The identity provider monitors the actions performed on a resource by the client application and determines the bare minimum permission needed for the client application.

Status:
Grant
Type:

Utility

Filling date:

17 Sep 2019

Issue date:

18 Jan 2022