Permissions
For HTTP 403 or permission denied
Section titled “For HTTP 403 or permission denied”Microsoft Graph uses 403 Forbidden when access is not allowed. Confirm the error details and the operation attempted before changing permissions. See Microsoft’s error reference.
Check the approved permission plan
Section titled “Check the approved permission plan”Have IT compare the actual application’s permission mode and consent with the confirmed requirements for the action. If Sites.Selected applies, also check the grant for the specific site and the role assigned there.
Avoid unreviewed escalation
Section titled “Avoid unreviewed escalation”Do not resolve an unexplained 403 by adding tenant-wide permissions. The action’s endpoints, scopes, and grant requirements must first be confirmed against the implementation.
Related: configure Graph permissions, Sites.Selected, and SharePoint access.