Currently the Read-Only Admin role does not have visibility of all the application or deployment properties. This makes the role limiting for users that need access but do not want to risk making a change.
We also wish to implement Just In Time access using Entra Privileged Admin Groups, which means we can be in the Read Only role natively, and then PIM elevate to become members of the Package Admin role to make the required change
Please can the team look at whether the ReadOnly role can have visibility of all App and Deployment properties