An Azure service that provides hosted, universal storage for Azure app configurations.
Hi Glenn,
The issue is likely the way the Sites.Selected permission is being granted.
Adding this XML through the SharePoint App Permissions page:
<AppPermissionRequests>
<AppPermissionRequest Scope="http://sharepoint/content/sitecollection/web" Right="Write" />
</AppPermissionRequests>
does not replace the Sites.Selected resource assignment for an Entra ID application.
For an Azure App Registration, grant Sites.Selected and then explicitly assign the app Write access to the target SharePoint site using Microsoft Graph:
POST https://graph.microsoft.com/v1.0/sites/{siteId}/permissions
{
"roles": ["write"],
"grantedToIdentities": [
{
"application": {
"id": "<client-id>",
"displayName": "<app-name>"
}
}
]
}
Microsoft documents that Sites.Selected requires both admin consent and an explicit permission assignment on the target site. The write role provides the required write access.
For SharePoint REST APIs, Microsoft also documents that Sites.Selected can be used after the site-level permission has been configured through the Graph permissions endpoint.
So I would first remove the dependency on the AppPermissionRequests XML and configure the Entra application using the Sites.Selected + site-level write assignment model.
There is no separate "Comments" application permission documented for SharePoint list-item comments.