Remove rows from role settings: Roles with what they grant and who holds them.
Roles with what they grant and who holds them.
is_system marks the two roles the product maintains rather than the tenant: the administrator, which holds every permission and reaches every site, and the read-only role the product’s support team signs in with. Every other role is the tenant’s own to rename, change or delete.
is_external marks the ones that make their holder somebody another company employs — the second half of what identity.is_external() reads, and the reason granting one is not the same kind of act as granting any of the others.
held_only_by_service_accounts is true when the role has holders and every one of them is a service account, which is what a picker choosing whom to share with or ask for a signature leaves out.
Headers
Preference
return=representation, return=minimal, return=none Query Parameters
Response
No Content

