Skip to content

Configure Microsoft Graph Permissions

Identify the Microsoft Graph calls the product makes and whether it uses application or delegated permissions. Approve the minimum reviewed scopes needed for those calls. This site does not prescribe an unverified scope list.

An authorized administrator reviews the app registration’s API permissions and consent status. Record the permission names, mode, reason for each permission, and approver. Do not treat a permission displayed in an example as a product requirement.

For Selected permissions, consent alone does not provide access to a selected resource. An explicit resource assignment and an appropriate token are also needed. See Microsoft’s Selected permissions overview.

Document the confirmed product version, endpoints, approved scopes, and grants before handing the connection to a workflow user. The per-action permission matrix is pending implementation review.

Next: Sites.Selected and grant SharePoint site access.