Mods
Azure

IAM Role: Azure/Managed Identity/admin

PermissionGrant
microsoft.managedidentity/register/actionadmin
microsoft.managedidentity/userassignedidentities/assign/actionadmin
microsoft.managedidentity/userassignedidentities/deleteadmin
microsoft.managedidentity/userassignedidentities/federatedidentitycredentials/deleteadmin
microsoft.managedidentity/userassignedidentities/federatedidentitycredentials/writeadmin
microsoft.managedidentity/userassignedidentities/listassociatedresources/actionadmin
microsoft.managedidentity/userassignedidentities/revoketokens/actionadmin
microsoft.managedidentity/userassignedidentities/writeadmin
microsoft.managedidentity/identities/readmetadata
microsoft.managedidentity/operations/readmetadata
microsoft.managedidentity/userassignedidentities/federatedidentitycredentials/readmetadata
microsoft.managedidentity/userassignedidentities/readmetadata