@ee1 for the Azure AD connection the Read Directory I believe is needed when reading group information, extended attributes, data not belonging to the user signing. When enabled, the directory data would require administrator consent unless the user logging in is an administrator or the Azure AD administrator gives consent for every user in the directory.