Graph API - Forbidden / Unauthorized operation despite the correct permissions

Leonard RADECKI 0 Reputation points


I would like to list "malwareStateForWindowsDevices" using an Application context according to API Documentation :
As specified, my application has the permission "DeviceManagementManagedDevices.Read.All" needed :

User's image

User's image

The type is "Application" and not "Delegated" as it should be. The permission is granted.

Just to be sure, my token is valid as expected when I request it (checking with :
User's image

However when I make my request I get (screenshot from Postman) :

User's image

It's not the case when I use other resources with the same permission. Indeed, I can list "detectedApps" : that needs the exact same "DeviceManagementManagedDevices.Read.All" permission.

EDIT : I add the permission "DeviceManagementConfiguration.Read.All" (checking with :
User's image

Still get the same response ("code": "Forbidden")

Thanks for your help,


Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
9,949 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vasil Michev 90,881 Reputation points MVP

    It looks like you need both DeviceManagementManagedDevices.Read.All and DeviceManagementConfiguration.Read.All for this query.