Mods
Azure

IAM Role: Azure/Managed Identity/metadata

PermissionGrant
microsoft.managedidentity/identities/readmetadata
microsoft.managedidentity/operations/readmetadata
microsoft.managedidentity/userassignedidentities/federatedidentitycredentials/readmetadata
microsoft.managedidentity/userassignedidentities/readmetadata