azure-msgraph-change-notification-client-state-input

The clientState shared secret is supplied when a Graph subscription is created and is echoed in notifications for validation. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:msgraph emits ContainsSecret

Where it sits

locationmicrosoft.graph.subscription.clientState
location kindsecret_value
data kindscredential webhook_secret
emits edgeContainsSecret
serviceMicrosoft Graph (app permissions) (azure:msgraph)

Collection recipe

access modewrite_only_input
operationPOST /subscriptions
response pathrequest.clientState
encodingjson
params{"tenant": "\u003ctenant-id\u003e"}

References

move · open · esc close