microsoftgraph / microsoftgraph/msgraph-sdk-dotnet

Auto-grant Sites.Selected access to the SharePoint site created when provisioning a Microsoft 365 Group

Open
#3,176 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status:waiting-for-triage type:feature
Dominant language
C#
Stars
789
Forks
264
Avg merge
15h 17m
Merged PRs (30d)
3

Description

Is your feature request related to a problem? Please describe the problem.

When a site collection is created directly via POST /sites with the Sites.Create.All permission, the calling application is automatically granted Sites.Selected + FullControl on that new site collection — no extra step required (confirmed here: https://devblogs.microsoft.com/microsoft365dev/sharepoint-site-creation-in-microsoft-graph/).

This auto-grant does not extend to the SharePoint site provisioned automatically when a Microsoft 365 Group is created via POST /groups. An app that only holds Sites.Selected (not tenant-wide Sites.ReadWrite.All) can create the group, but has no access to the group's backing site afterwards — even though it triggered that site's creation. The only workaround is a manual follow-up call to POST /sites/{site-id}/permissions, adding an extra step, an extra failure point, and a possible race condition (the backing site is not always immediately addressable right after group creation).

Describe the solution you'd like.

Request: extend the existing Sites.Create.All → Sites.Selected auto-grant behavior to also cover sites provisioned indirectly as a side effect of Microsoft 365 Group creation, so an app with Sites.Selected that creates a group is automatically granted write access to that group's site too — consistent with how direct site creation already works.
This would let least-privilege apps (Sites.Selected only) provision groups and immediately manage their sites in one atomic step.

Additional context?

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the Microsoft Graph POST /sites and POST /groups behavior described in the issue, along with the linked announcement about direct site creation. Confirm whether the requested Sites.Selected auto-grant can be supported for group-created sites; done means the creating app receives equivalent access without a follow-up permissions call.

Written by the indexing model from the issue text.

Assessment

Domain
api, authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.