Moved DeviceManagementRBAC.Read.All and Group.Read.All from
'required' to 'granted' section after adding them in Azure AD.
These permissions are now active and will resolve:
- Scope tag IDs to display names
- Group IDs to group names for assignments
Next step: Create new backup to verify scope tag name resolution works.