Microsoft Graph Permissions
Record the permission rationale
Section titled “Record the permission rationale”For each verified product operation, record its Graph endpoint, application or delegated permission mode, minimum required scope, resource grant, and reason. An API’s possible permissions are not automatically the product’s requirements.
Consent and grants
Section titled “Consent and grants”For Selected access, consent and resource assignment are distinct. Review both with the administrator. See Microsoft’s Selected permissions overview.
Pending product matrix
Section titled “Pending product matrix”The per-action scope list and setup identity privileges require implementation review. Keep setup authorization separate from the runtime application’s intended access.
Related: configure permissions and least privilege.