pnp / pnp/cli-microsoft365

Minimal permissions for 'spo listitem related' commands

Open
#7,487 1 comment 0 reactions 1 assignee View on GitHub

@nanddeepn is already working on this.

Since Sep 2, 2026.

docs work in progress
Dominant language
TypeScript
Stars
1.5k
Forks
413
Avg merge
5d 6h
Merged PRs (30d)
21

Description

We're adding a new Permissions section to all commands. This section will document the minimal delegated and application permissions required to execute the command.

The goal is to:

  • Make it easier to run the CLI with custom app registrations and application permissions.
  • Ensure we only document the minimal set of permissions needed.
  • Keep documentation consistent by placing the Permissions section right before the Examples section.
  • If there are multiple resources, order them alphabetically
  • If there are commands that only support one type of auth (like delegated or app-only), we have an example for that as well. E.g. m365 planner tenant settings list - Permissions
Resources
Commands in scope

This issue covers the following commands:

  • m365 spo listitem batch add
  • m365 spo listitem batch remove
  • m365 spo listitem batch set
  • m365 spo listitem retentionlabel ensure
  • m365 spo listitem retentionlabel remove
  • m365 spo listitem roleassignment add
  • m365 spo listitem roleassignment remove
  • m365 spo listitem roleinheritance break
  • m365 spo listitem roleinheritance reset

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.