Evidence-backed facts
- Microsoft Graph permission names distinguish operations such as Read or ReadBasic and constraints such as All, Selected, Shared, or OwnedBy. informative
- ReadWrite permissions can authorize create, update, and delete operations and must not be substituted for a narrower read permission when writes are unnecessary. informative
- Delegated permissions act on behalf of a signed-in user, while application permissions act without one and generally require administrator consent. informative
- The connector must request the least privileged endpoint-specific permission and still respect the signed-in user, tenant, resource, and RBAC boundaries. informative