Skip to content

Commit 7efd040

Browse files
authored
Merge pull request #28292 from microsoftgraph/permissions-reference/2026-02-23
2026-02-23: Automated permissions reference update
2 parents 1f120e8 + 1ab94e0 commit 7efd040

3 files changed

Lines changed: 70 additions & 5 deletions

File tree

changelog/Manual.NonWorkloadChanges.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,47 @@
11
{
22
"changelog": [
3+
{
4+
"ChangeList": [
5+
{
6+
"Id": "74c50b70-259d-4c6e-80fb-2c15dde1e827",
7+
"ApiChange": "Permission",
8+
"ChangedApiName": "FileStorageContainerType.Manage.All",
9+
"ChangeType": "Change",
10+
"Description": "Updated the `FileStorageContainerType.Manage.All` delegated permission to no longer require admin consent.",
11+
"Target": "FileStorageContainerType.Manage.All"
12+
},
13+
{
14+
"Id": "74c50b70-259d-4c6e-80fb-2c15dde1e827",
15+
"ApiChange": "Permission",
16+
"ChangedApiName": "FileStorageContainerTypeReg.Manage.All",
17+
"ChangeType": "Change",
18+
"Description": "Updated the `FileStorageContainerTypeReg.Manage.All` delegated permission to no longer require admin consent.",
19+
"Target": "FileStorageContainerTypeReg.Manage.All"
20+
},
21+
{
22+
"Id": "74c50b70-259d-4c6e-80fb-2c15dde1e827",
23+
"ApiChange": "Permission",
24+
"ChangedApiName": "ThreatSubmission.Read",
25+
"ChangeType": "Change",
26+
"Description": "Updated the `ThreatSubmission.Read` delegated permission to now require admin consent.",
27+
"Target": "ThreatSubmission.Read"
28+
},
29+
{
30+
"Id": "74c50b70-259d-4c6e-80fb-2c15dde1e827",
31+
"ApiChange": "Permission",
32+
"ChangedApiName": "ThreatSubmission.ReadWrite",
33+
"ChangeType": "Change",
34+
"Description": "Updated the `ThreatSubmission.ReadWrite` delegated permission to now require admin consent.",
35+
"Target": "ThreatSubmission.ReadWrite"
36+
}
37+
],
38+
"Id": "74c50b70-259d-4c6e-80fb-2c15dde1e827",
39+
"Cloud": "prd",
40+
"Version": "v1.0",
41+
"CreatedDateTime": "2026-02-23T10:54:33.0608937Z",
42+
"WorkloadArea": "Permissions",
43+
"SubArea": ""
44+
},
345
{
446
"ChangeList": [
547
{

concepts/permissions-reference.md

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.localizationpriority: high
77
ms.topic: reference
88
ms.subservice: entra-applications
99
ms.custom: graphiamtop20, scenarios:getting-started
10-
ms.date: 02/16/2026
10+
ms.date: 02/23/2026
1111
#Customer intent: As a developer, I want to learn more about the permissions available in Microsoft Graph, so that I understand the impact of granting specific permissions to my app.
1212
---
1313

@@ -3538,7 +3538,7 @@ GET https://graph.microsoft.com/v1.0/servicePrincipals(appId='00000003-0000-0000
35383538
| Identifier | - | 8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b |
35393539
| DisplayText | - | Manage file storage container types on behalf of the signed in user |
35403540
| Description | - | Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin. |
3541-
| AdminConsentRequired | - | Yes |
3541+
| AdminConsentRequired | - | No |
35423542

35433543
---
35443544

@@ -3549,7 +3549,7 @@ GET https://graph.microsoft.com/v1.0/servicePrincipals(appId='00000003-0000-0000
35493549
| Identifier | - | c319a7df-930e-44c0-a43b-7e5e9c7f4f24 |
35503550
| DisplayText | - | Manage file storage container type registrations on behalf of the signed in user |
35513551
| Description | - | Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin. |
3552-
| AdminConsentRequired | - | Yes |
3552+
| AdminConsentRequired | - | No |
35533553

35543554
---
35553555

@@ -8549,6 +8549,17 @@ GET https://graph.microsoft.com/v1.0/servicePrincipals(appId='00000003-0000-0000
85498549

85508550
---
85518551

8552+
### TeamworkTargetedMessage.Read.All
8553+
8554+
| Category | Application | Delegated |
8555+
|--|--|--|
8556+
| Identifier | b0cfd829-be18-4b31-bb0e-ec1df8197ba3 | - |
8557+
| DisplayText | Read all targeted messages of group chat or channel | - |
8558+
| Description | Allows the app to read all group chat or channel targeted messages in Microsoft Teams. | - |
8559+
| AdminConsentRequired | Yes | - |
8560+
8561+
---
8562+
85528563
### TeamworkUserInteraction.Read.All
85538564

85548565
| Category | Application | Delegated |
@@ -8655,7 +8666,7 @@ GET https://graph.microsoft.com/v1.0/servicePrincipals(appId='00000003-0000-0000
86558666
| Identifier | - | fd5353c6-26dd-449f-a565-c4e16b9fce78 |
86568667
| DisplayText | - | Read threat submissions |
86578668
| Description | - | Allows the app to read the threat submissions and threat submission policies owned by the signed-in user. |
8658-
| AdminConsentRequired | - | No |
8669+
| AdminConsentRequired | - | Yes |
86598670

86608671
---
86618672

@@ -8677,7 +8688,7 @@ GET https://graph.microsoft.com/v1.0/servicePrincipals(appId='00000003-0000-0000
86778688
| Identifier | - | 68a3156e-46c9-443c-b85c-921397f082b5 |
86788689
| DisplayText | - | Read and write threat submissions |
86798690
| Description | - | Allows the app to read the threat submissions and threat submission policies owned by the signed-in user. Also allows the app to create new threat submissions on behalf of the signed-in user. |
8680-
| AdminConsentRequired | - | No |
8691+
| AdminConsentRequired | - | Yes |
86818692

86828693
---
86838694

concepts/whats-new-overview.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,12 @@ For details about previous updates to Microsoft Graph, see [Microsoft Graph what
2020
2121
## February 2026: New and generally available
2222

23+
### Files
24+
25+
Updated the admin consent requirement for the following delegated permissions related to SharePoint Embedded file storage container management:
26+
- The `FileStorageContainerType.Manage.All` delegated permission no longer requires admin consent.
27+
- The `FileStorageContainerTypeReg.Manage.All` delegated permission no longer requires admin consent.
28+
2329
### Groups
2430

2531
- Added the **resourceBehaviorOptions** and **resourceProvisioningOptions** properties to the [group](/graph/api/resources/group) resource. These properties enable you to specify group behaviors and associated resources for a Microsoft 365 group.
@@ -40,6 +46,12 @@ Use the message trace API to track the flow of email messages through your Excha
4046

4147
Added the `restrictWebGrounding` member to the [dlpAction](/graph/api/resources/enums-security#dlpaction-values) enumeration to support restricting web grounding actions in data loss prevention policies in Microsoft Purview.
4248

49+
### Security | Threat protection
50+
51+
Updated the admin consent requirement for the following delegated permissions related to threat submissions:
52+
- The `ThreatSubmission.Read` delegated permission now requires admin consent.
53+
- The `ThreatSubmission.ReadWrite` delegated permission now requires admin consent.
54+
4355
### Teamwork and communications | Administration
4456

4557
- [Get the policy ID](/graph/api/teamsadministration-teamspolicyassignment-getpolicyid) for a given policy name and policy type within Teams administration.

0 commit comments

Comments
 (0)