A cloud-based identity and access management service for securing user authentication and resource access
- No. A delegated token that contains only
Sites.Selectedis not an officially supported permission model forPOST /search/query. The documented permissions for Microsoft Search entity types relevant to SharePoint are:-
site:Sites.Read.AllorSites.ReadWrite.All -
listandlistItem:Sites.Read.AllorSites.ReadWrite.All -
driveanddriveItem:Files.Read.All,Files.ReadWrite.All,Sites.Read.All, orSites.ReadWrite.All
Sites.Selectedis not listed for Microsoft Search, and the site search API explicitly states that it doesn't support theSites.Selectedapplication permission. The accepted Microsoft Q&A guidance in the provided material also states that Graph Search does not enforceSites.Selectedand operates against the tenant-wide SharePoint search index. -
- No advance-notice mechanism is documented in the provided material for this specific behavior. There is no supported statement here that changes would be announced through Message center or the Graph changelog.
- No documented product commitment or roadmap is provided here for either outcome. The supported facts are only:
- today, Microsoft Search permissions do not document
Sites.Selected - Graph Search is described in the provided Q&A as not enforcing
Sites.Selected - there is currently no supported way stated here to make Microsoft Graph Search enforce
Sites.Selected
- today, Microsoft Search permissions do not document
- No. There is no supported way in the provided material to scope
POST /search/queryresults to only the sites granted throughSites.Selected. Supported alternatives and constraints from the provided material:- Use site-scoped APIs such as
/sites/{id},/sites/{id}/drives,/sites/{id}/lists, and related content APIs. The provided Q&A states these respectSites.Selected. - For Microsoft Search, delegated permissions can return SharePoint and OneDrive results based on the signed-in user's access, not the app's
Sites.Selectedgrants. -
includeHiddenContentworks only with delegated permissions, but that setting is about hidden content and does not provide site scoping bySites.Selected.
- Use site-scoped APIs such as
Given the behavior described, treating search/query + delegated Sites.Selected as unsupported is the safe interpretation. The current 200 response should not be relied on as a supported contract for app-level site restriction.
References:
- Use the Microsoft Search API to query data
- Search for sites
- Overview of Selected permissions in OneDrive and SharePoint
- Graph Search API returns all sites despite "Sites.Selected" App-Only permission - Microsoft Q&A
- Endpoint access with Sites.Selected permission for Sharepoint - Microsoft Q&A
- Use the Microsoft Search API to search OneDrive and SharePoint content