Is Microsoft Graph /search/query supported with delegated Sites.Selected, and will it stay that way?

Bambou 0 Reputation points
2026-10-03T12:08:38.1+00:00

Hello,

I am building an app that searches and reads SharePoint Online content on behalf of the signed-in user. I want the app to only access a set of approved sites, so it uses the delegated Sites.Selected permission only (no Sites.Read.All or Files.Read.All).

What I observe today with a delegated token whose only Graph scope is Sites.Selected:

  1. Site, drive, list and page endpoints (/sites/{id}, /sites/{id}/drives, /drives/{id}/items/{id}/content, /sites/{id}/lists/...) work on the granted sites and return 403 on the other sites, as expected.
  2. POST /v1.0/search/query (entityTypes driveItem, listItem and site) returns 200 with results.
  3. The search results are not restricted to the granted sites: they include items from any site the user can access. Reading those items still returns 403, so I filter the results in the app.

Sites.Selected is not listed in the permissions of the search/query documentation, and some threads from 2024 say that search does not work with Sites.Selected alone. So I am not sure whether point 2 is supported or may change.

My questions:

  1. Is calling /search/query with a delegated token that only contains Sites.Selected an officially supported scenario?
  2. If this behavior is changed or blocked in the future, would it be announced in advance (for example in the Microsoft 365 message center or the Graph changelog)?
  3. If it changes, is the plan to block search for Sites.Selected tokens, or to make search honor Sites.Selected (only return items from the granted sites)?
  4. Is there a supported way today to scope /search/query results to the sites granted through Sites.Selected?

Thanks for your help.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-10-03T12:09:03.92+00:00
    1. No. A delegated token that contains only Sites.Selected is not an officially supported permission model for POST /search/query. The documented permissions for Microsoft Search entity types relevant to SharePoint are:
      • site: Sites.Read.All or Sites.ReadWrite.All
      • list and listItem: Sites.Read.All or Sites.ReadWrite.All
      • drive and driveItem: Files.Read.All, Files.ReadWrite.All, Sites.Read.All, or Sites.ReadWrite.All
      Sites.Selected is not listed for Microsoft Search, and the site search API explicitly states that it doesn't support the Sites.Selected application permission. The accepted Microsoft Q&A guidance in the provided material also states that Graph Search does not enforce Sites.Selected and operates against the tenant-wide SharePoint search index.
    2. No advance-notice mechanism is documented in the provided material for this specific behavior. There is no supported statement here that changes would be announced through Message center or the Graph changelog.
    3. No documented product commitment or roadmap is provided here for either outcome. The supported facts are only:
      • today, Microsoft Search permissions do not document Sites.Selected
      • Graph Search is described in the provided Q&A as not enforcing Sites.Selected
      • there is currently no supported way stated here to make Microsoft Graph Search enforce Sites.Selected
    4. No. There is no supported way in the provided material to scope POST /search/query results to only the sites granted through Sites.Selected. Supported alternatives and constraints from the provided material:
      • Use site-scoped APIs such as /sites/{id}, /sites/{id}/drives, /sites/{id}/lists, and related content APIs. The provided Q&A states these respect Sites.Selected.
      • For Microsoft Search, delegated permissions can return SharePoint and OneDrive results based on the signed-in user's access, not the app's Sites.Selected grants.
      • includeHiddenContent works only with delegated permissions, but that setting is about hidden content and does not provide site scoping by Sites.Selected.

    Given the behavior described, treating search/query + delegated Sites.Selected as unsupported is the safe interpretation. The current 200 response should not be relied on as a supported contract for app-level site restriction.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.