Are these Application permissions correct?

DS 0 Reputation points
2024-06-11T22:46:00.8+00:00

https://video2.skills-academy.com/en-us/graph/api/list-create?view=graph-rest-1.0&tabs=http#permissions

On the page above, the Application + Least privileged permissions is "Sites.Manage.All" and the Application + Higher privileged permissions is "Sites.ReadWrite.All". It looks from the description of these two permissions that "Sites.Manage.All" is higher than "Sites.ReadWrite.All". Are these two switched, or am I misinterpreting the table headings?

Permission type Least privileged permissions Higher privileged permissions
Delegated (work or school account) Sites.Manage.All Not available.
Delegated (personal Microsoft account) Not supported. Not supported.
Application Sites.Manage.All Sites.ReadWrite.All
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,200 questions
SharePoint
SharePoint
A group of Microsoft Products and technologies used for sharing and managing content, knowledge, and applications.
10,108 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Yanli Jiang - MSFT 23,186 Reputation points Microsoft Vendor
    2024-06-12T03:07:25.3766667+00:00

    Hi @DS ,

    Welcome to Q&A forum!

    I'm sorry for the confusion.

    For both Permissions, the article is just a brief scope of its use, and not to be used as a classification of level. In fact, Site.ReadWrite.All is higher than Site.Manage.All. And, the exact usage is still based on the usage scenarios provided in the API.

    Therefore, the headings in the table are correct and not switched.

    Have a nice day!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.