EntitlementManagement.ReadWrite.All
Allows the app to read and write access packages and related entitlement management resources without a signed-in user.
In short
EntitlementManagement.ReadWrite.All is available as both an application permission and a delegated permission in the Microsoft Graph API, grouped under the EntitlementManagement category. Allows the app to read and write access packages and related entitlement management resources without a signed-in user. It grants read and write access to resources. Application permissions always require admin consent.
Permission Details
Read and write all entitlement management resources
Allows the app to read and write access packages and related entitlement management resources without a signed-in user.
9acd699f-1e81-4958-b001-93b1d2506e19
Read and write entitlement management resources
Allows the app to request access to and management of access packages and related entitlement management resources on behalf of the signed-in user.
ae7a573d-81d7-432b-ad44-4ed5c9d89038
Properties
Properties is shown from stable Microsoft Graph v1.0 metadata.
| Property | Type | Description |
|---|---|---|
id |
String |
This value indicates the resource is a singleton. Read-only. Inherited from entity. |
accessPackageAssignmentApprovals |
approval collection |
Approval stages for decisions associated with access package assignment requests. |
accessPackages |
accessPackage collection |
Access packages define the collection of resource roles and the policies for which subjects can request or be assigned access to those resources. |
accessPackageSuggestions |
accessPackageSuggestion collection |
Suggested access packages for end users based on various criteria such as related people insights and assignment history. |
assignmentPolicies |
accessPackageAssignmentPolicy collection |
Access package assignment policies govern which subjects can request or be assigned an access package via an access package assignment. |
assignmentRequests |
accessPackageAssignmentRequest collection |
Access package assignment requests created by or on behalf of a subject. |
assignments |
accessPackageAssignment collection |
The assignment of an access package to a subject for a period of time. |
availableAccessPackages |
availableAccessPackage collection |
Access packages available for end users to browse and request. |
catalogs |
accessPackageCatalog collection |
A container for access packages. |
connectedOrganizations |
connectedOrganization collection |
References to a directory or domain of another organization whose users can request access. |
controlConfigurations |
controlConfiguration collection |
Configuration settings that control the lifecycle and access policies of entitlement management within a tenant. |
externalOriginResourceConnectors |
externalOriginResourceConnector collection |
Represents the connectors used to communicate with external resource systems. |
resourceEnvironments |
accessPackageResourceEnvironment collection |
A reference to the geolocation environments in which a resource is located. |
resourceRequests |
accessPackageResourceRequest collection |
Represents a request to add or remove a resource to or from a catalog respectively. |
resourceRoleScopes |
accessPackageResourceRoleScope collection |
Showing 15 of 18 properties.
JSON Representation
JSON representation is shown from stable Microsoft Graph v1.0 metadata.
{
"@odata.type": "#microsoft.graph.entitlementManagement",
"id": "String (identifier)"
}
Relationships
Relationships is shown from stable Microsoft Graph v1.0 metadata.
| Relationship | Type | Description |
|---|---|---|
accessPackageAssignmentApprovals |
approval collection |
Approval stages for decisions associated with access package assignment requests. |
accessPackages |
accessPackage collection |
Access packages define the collection of resource roles and the policies for which subjects can request or be assigned access to those resources. |
accessPackageSuggestions |
accessPackageSuggestion collection |
Suggested access packages for end users based on various criteria such as related people insights and assignment history. |
availableAccessPackages |
availableAccessPackage collection |
Access packages available for end users to browse and request. |
assignmentPolicies |
accessPackageAssignmentPolicy collection |
Access package assignment policies govern which subjects can request or be assigned an access package via an access package assignment. |
assignmentRequests |
accessPackageAssignmentRequest collection |
Access package assignment requests created by or on behalf of a subject. |
assignments |
accessPackageAssignment collection |
The assignment of an access package to a subject for a period of time. |
catalogs |
accessPackageCatalog collection |
A container for access packages. |
connectedOrganizations |
connectedOrganization collection |
References to a directory or domain of another organization whose users can request access. |
controlConfigurations |
controlConfiguration collection |
Configuration settings that control the lifecycle and access policies of entitlement management within a tenant. |
resourceEnvironments |
accessPackageResourceEnvironment collection |
A reference to the geolocation environments in which a resource is located. |
resourceRequests |
accessPackageResourceRequest collection |
Represents a request to add or remove a resource to or from a catalog respectively. |
resources |
accessPackageResource collection |
The resources associated with the catalogs. |
settings |
entitlementManagementSettings |
The settings that control the behavior of Microsoft Entra entitlement management. |
externalOriginResourceConnectors |
externalOriginResourceConnector collection |
Represents the connectors used to communicate with external resource systems. |
resourceRoleScopes |
accessPackageResourceRoleScope collection |
Related resourceRoleScopes data exposed by this resource. |
subjects |
accessPackageSubject collection |
Related subjects data exposed by this resource. |
accessPackageAssignmentPolicies |
accessPackageAssignmentPolicy collection |
Represents the policy that governs which subjects can request or be assigned an access package via an access package assignment. |
accessPackageAssignmentRequests |
accessPackageAssignmentRequest collection |
Represents access package assignment requests created by or on behalf of a user. DO NOT USE. TO BE RETIRED SOON. Use the assignmentRequests relationship instead. |
accessPackageAssignmentResourceRoles |
accessPackageAssignmentResourceRole collection |
Represents the resource-specific role which a subject has been assigned through an access package assignment. |
accessPackageAssignments |
accessPackageAssignment collection |
The assignment of an access package to a subject for a period of time. |
Graph Methods
Microsoft Graph v1.0 endpoints are mapped directly from refreshed Microsoft Learn permissions tables.
Microsoft Graph beta endpoints are mapped directly from refreshed Microsoft Learn permissions tables.
Microsoft Graph PowerShell v1.0 commands are mapped directly from refreshed Microsoft Learn PowerShell snippets.
Microsoft Graph PowerShell beta commands are mapped directly from refreshed Microsoft Learn PowerShell snippets.
Code Examples
// Code snippets are only available for the latest version. Current version is 5.x
// To initialize your graphClient, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=csharp
await graphClient.IdentityGovernance.EntitlementManagement.Assignments["{accessPackageAssignment-id}"].Reprocess.PostAsync();
const options = {
authProvider,
};
const client = Client.init(options);
await client.api('/identityGovernance/entitlementManagement/assignments/d82eb508-acc4-43cc-bcf1-7c1c4a2c073b/reprocess')
.post();
Import-Module Microsoft.Graph.Identity.Governance
Update-MgEntitlementManagementAssignment -AccessPackageAssignmentId $accessPackageAssignmentId
# Code snippets are only available for the latest version. Current version is 1.x
from msgraph import GraphServiceClient
# To initialize your graph_client, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=python
await graph_client.identity_governance.entitlement_management.assignments.by_access_package_assignment_id('accessPackageAssignment-id').reprocess.post()
App Registration
Navigate to Azure Portal
Go to App registrations in Microsoft Entra admin center
Add API Permission
Select your app → API permissions → Add a permission → Microsoft Graph
Select Permission Type
Choose Application permissions or delegated permissions and search for EntitlementManagement.ReadWrite.All
Grant Admin Consent
Application permissions always require admin consent.
Frequently asked questions
What is the EntitlementManagement.ReadWrite.All Microsoft Graph permission?
EntitlementManagement.ReadWrite.All is available as both an application permission and a delegated permission in the Microsoft Graph API, grouped under the EntitlementManagement category. Allows the app to read and write access packages and related entitlement management resources without a signed-in user. It grants read and write access to resources. Application permissions always require admin consent. It is mapped to the Microsoft Graph entitlementmanagement resource type. 230 documented Microsoft Graph REST methods require it. 174 Microsoft Graph PowerShell commands are documented for it.
Is EntitlementManagement.ReadWrite.All an application or a delegated permission?
EntitlementManagement.ReadWrite.All is available as both an application permission (app-only access, no signed-in user) and a delegated permission (access on behalf of a signed-in user).
Does EntitlementManagement.ReadWrite.All require admin consent?
Application permissions always require admin consent.
What is the permission ID (GUID) for EntitlementManagement.ReadWrite.All?
For EntitlementManagement.ReadWrite.All, the application (app role) ID is 9acd699f-1e81-4958-b001-93b1d2506e19, and the delegated (OAuth2 scope) ID is ae7a573d-81d7-432b-ad44-4ed5c9d89038. These are the real Microsoft Graph identifiers and can be used directly in an app registration manifest.