Skip to content

Granting access via Entra ID Application Permissions does not provide least privilege guidelinesΒ #10532

@mundayn

Description

@mundayn

What type of issue is this?

Documentation issue / typo

What SharePoint development model, framework, SDK or API is this about?

πŸ’₯ SharePoint Framework

Target SharePoint environment

SharePoint Online

What browser(s) / client(s) have you tested

  • πŸ’₯ Internet Explorer
  • πŸ’₯ Microsoft Edge
  • πŸ’₯ Google Chrome
  • πŸ’₯ FireFox
  • πŸ’₯ Safari
  • mobile (iOS/iPadOS)
  • mobile (Android)
  • not applicable
  • other (enter in the "Additional environment details" area below)

Additional environment details

  • browser version
  • SPFx version
  • Node.js version
  • etc

Issue description

Page: https://learn.microsoft.com/en-us/sharepoint/dev/solution-guidance/security-apponly-azuread

Hi team,

This page does not provide any guidance for using Sites.Selected, only full tenant wide access, which is not following best security practices.

It would benefit the community to provide a zero trust, least privilege method of providing access using Sites.Selected.

Thank you,

Metadata

Metadata

Assignees

Labels

area:docsCategory: SharePoint developer/development documentation relatedsharepoint-developer-supportsharepoint-developer-support

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions