Endpoint access with Sites.Selected permission for Sharepoint

Melvin 80 Reputation points
2025-11-18T03:50:02.5066667+00:00

Hi,

I'm a little bit confused on how Sites.Selected affect the access scope of other endpoint not related to sites like:

Drives

  • Will access to drives be restricted to the drives of the permitted sites only or will this endpoint return data from drives outside of the permitted sites?
  • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}
  • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/root/children

Files

  • Will access to files be restricted to the files of the permitted sites only or will this endpoint return data from files outside of the permitted sites?
  • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/root:/{path_to_file}:/content
  • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/items/{file_id}/content

Users

  • Will users endpoints be affected by Sites.Selected permission or they have separate permission scopes?
  • https://graph.microsoft.com/v1.0/users

Thank you!

Microsoft 365 and Office | SharePoint | Development
0 comments No comments

Answer accepted by question author
Anonymous
2025-11-18T04:29:40.85+00:00

Hi @Melvin 

Thank you for posting your question in the Microsoft Q&A forum. 

The Q&A Assist answer is correct, and I’d like to add some further clarification: 

The Sites.Selected permission in Microsoft Graph is a special delegated or application permission that restricts access to only specific SharePoint sites. By default, an app with Sites.Selectedhas no access to any site until an admin explicitly grants permissions for specific sites using SharePoint PowerShell. 

Drives endpoints:

-The app can only access drives in sites it has been granted permission to. 

-If the drive belongs to a site outside the allowed list, Graph returns 403 Forbidden. 

-Drives from other sites are not visible, unlike Sites.Read.All, which grants access to all sites in the tenant. 

Files endpoints: 

Because files are always under a drive, and drives are always under a site: 

-If the site is allowed, the app can access its files. 

-If the site is not allowed, all file endpoints under it return 403 Forbidden. 

Users endpoints 

-Sites.Selected does not apply to users. 

-User endpoints require separate permissions such as User.Read.All or User.ReadBasic.All. 

-Granting Sites.Selected does not provide any user information, it only controls SharePoint site content. 

Sites.Selected is purely site-scoped. Drives and files inherit the restriction because they belong to a site. Other Graph endpoints (users, groups, etc.) are unaffected and require their own permissions. 

I hope this information is helpful. 


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2025-11-18T03:50:31.49+00:00

    The Sites.Selected permission in SharePoint and OneDrive is designed to restrict access to specific site collections. Here’s how it affects the access to other endpoints:

    Drives

    • Access to drives will be restricted to the drives of the permitted sites only. If your application has been granted Sites.Selected permission for a specific site collection, it will only be able to access drives associated with that site collection. Therefore, the endpoints like:
      • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}
      • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/root/children
        will return data only from the drives of the permitted sites.

    Files

    • Similarly, access to files will also be restricted to the files of the permitted sites. The endpoints:
      • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/root:/{path_to_file}:/content
      • https://graph.microsoft.com/v1.0/sites/{full_site_id}/drives/{drive_id}/items/{file_id}/content
        will only return data from files that are part of the drives of the permitted sites.

    Users

    • The Sites.Selected permission does not affect user endpoints. Access to user-related endpoints, such as https://graph.microsoft.com/v1.0/users, is governed by separate permission scopes. Therefore, the access to users is not restricted by the Sites.Selected permission.

    In summary, Sites.Selected permission limits access to drives and files to only those associated with the specified site collections, while user endpoints are managed independently with their own permissions.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.