Skip to content

Microsoft Graph Permissions

For each verified product operation, record its Graph endpoint, application or delegated permission mode, minimum required scope, resource grant, and reason. An API’s possible permissions are not automatically the product’s requirements.

For Selected access, consent and resource assignment are distinct. Review both with the administrator. See Microsoft’s Selected permissions overview.

The per-action scope list and setup identity privileges require implementation review. Keep setup authorization separate from the runtime application’s intended access.

Related: configure permissions and least privilege.