DSCResources/MSFT_AADMSGroupLifecyclePolicy/settings.json

{
    "resourceName": "AADMSGroupLifecyclePolicy",
    "description": "This resource configures an Azure Active Directory Group Lifecycle Policy (e.g. Expiration).",
    "permissions": [
        {
            "read": [
                {
                    "name":"Directory.Read.All"
                }
            ],
            "update": [
                {
                    "name": "Directory.ReadWrite.All"
                }
            ]
        }
    ]
}