Graph API delegation issue

Giridharan Sriram 1 Reputation point

We are having issue in the Graph API delegation.

In aplication level- Graph API access used whch has ability to read all site collection document at tenant level
But here the user who does not have access to the site collection will be able to read or retrieve the confidential documents when they use GRAPH API

Delegation Level- When we try with, documents are getting downloaded from the site collection even who does have access to the library.

Is there any alternative way to overcome this?

Microsoft Graph Files API
Microsoft Graph Files API
A Microsoft API to create an app that connects with files across OneDrive, OneDrive for Business, and SharePoint document libraries.
325 questions
Microsoft Graph Site Lists API
Microsoft Graph Site Lists API
A Microsoft API that "supports access to SharePoint sites, lists, and drives; read-only support for site resources; read-write support for lists, listItems, and driveItems; and address resources by SharePoint ID, URL, or relative path.
295 questions
No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Michael 17,886 Reputation points

    Hi @Giridharan Sriram ,

    For application permission, the effective permissions of your app will be the full level of privileges implied by the permission. As long as the app has permission, the user would have permission no matter if he has the permission or not.

    For delegated permissions, the effective permissions of your app will be the intersection of the delegated permissions the app has been granted (via consent) and the privileges of the currently signed-in user. So it needs both the user and app has permission to the file. If one of them doesn't have permission, the user would not have access.

    For graph api delegated and application permissions, the details are in this article:


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.