The process of building custom applications and tools that interact with Microsoft SharePoint, including SharePoint Online in Microsoft 365.
Hi @Melvin
Thank you for posting your question in the Microsoft Q&A forum.
The Q&A Assist answer is correct, and I’d like to add some further clarification:
The Sites.Selected permission in Microsoft Graph is a special delegated or application permission that restricts access to only specific SharePoint sites. By default, an app with Sites.Selectedhas no access to any site until an admin explicitly grants permissions for specific sites using SharePoint PowerShell.
Drives endpoints:
-The app can only access drives in sites it has been granted permission to.
-If the drive belongs to a site outside the allowed list, Graph returns 403 Forbidden.
-Drives from other sites are not visible, unlike Sites.Read.All, which grants access to all sites in the tenant.
Files endpoints:
Because files are always under a drive, and drives are always under a site:
-If the site is allowed, the app can access its files.
-If the site is not allowed, all file endpoints under it return 403 Forbidden.
Users endpoints
-Sites.Selected does not apply to users.
-User endpoints require separate permissions such as User.Read.All or User.ReadBasic.All.
-Granting Sites.Selected does not provide any user information, it only controls SharePoint site content.
Sites.Selected is purely site-scoped. Drives and files inherit the restriction because they belong to a site. Other Graph endpoints (users, groups, etc.) are unaffected and require their own permissions.
I hope this information is helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.