📘 What This Project Demonstrates How Microsoft Graph API permissions (e.g., user.read.all) define scope and control
That custom roles allow precision but require awareness of limitations
The power of built-in roles—and how they may overgrant for minimal tasks
How to interpret role behavior from the Admin Center UI