enterprise-application-connectors · prepared

Microsoft Graph connector boundary

Official-source delegated, application, read, write, consent, and least-privilege boundaries for Microsoft 365 data through Microsoft Graph.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.microsoft-graph
sha256:6fa9061c1d6178542318c9ef0dd949783056b94022f92a12322566bb5348fe24

Open canonical machine JSON →

Evidence-backed facts

  1. Microsoft Graph permission names distinguish operations such as Read or ReadBasic and constraints such as All, Selected, Shared, or OwnedBy. informative
  2. ReadWrite permissions can authorize create, update, and delete operations and must not be substituted for a narrower read permission when writes are unnecessary. informative
  3. Delegated permissions act on behalf of a signed-in user, while application permissions act without one and generally require administrator consent. informative
  4. The connector must request the least privileged endpoint-specific permission and still respect the signed-in user, tenant, resource, and RBAC boundaries. informative