We are using the Microsoft Graph Search API (POST https://graph.microsoft.com/v1.0/search/query) to list recently modified documents in a SharePoint Online folder. A free-text exclusion (NOT Trial)* does not exclude matching files. Scoping the exclusion to a property (NOT filename:Trial)* works as expected.
Folder contents (relevant files)
- KPI_Forecasting.xlsx
- DPO_DSO.xlsx
- Trial_Balance__06_2026.xlsx
- Trial_Balance__07_2026.xlsx
- Trial_Balance__08_2026.xlsx
Query 1 – exclusion with free-text term (NOT working as expected)
{
"requests": [{
"entityTypes": ["driveItem"],
"query": {
"queryString": "path:\"https://client.sharepoint.com/sites/Q1Reporting/Shared Documents/CFO Dashboard/Input Files/\" AND isDocument:true AND LastModifiedTime:2026-09-22T18:15:00..2026-09-29T18:15:00 AND NOT Trial*"
},
"fields": ["lastModifiedBy", "name", "webUrl", "lastModifiedDateTime"],
"region": "ARE"
}]
}
Expected: KPI_Forecasting.xlsx and DPO_DSO.xlsx only
Actual: all 5 files returned, including the three Trial_Balance files.
Query 2 – exclusion scoped to the filename property (working as expected)
queryString: same as Query 1, ending in "AND NOT filename:Trial*" instead of "AND NOT Trial*"
Result: only KPI_Forecasting.xlsx and DPO_DSO.xlsx returned.
We would like to understand why the free-text NOT behaves differently, since the KQL syntax reference states that NOT applies to both free-text expressions and property restrictions.