如何通过Microsoft Graph API为SharePoint在线文件授予SharePoint组权限
The driveitem-invite endpoint isn't the right tool for assigning permissions to existing SharePoint groups—it's built for sending invitations to individual users (including external ones). Here's how to do it correctly:
1. Retrieve the SharePoint Group ID
First, get the unique ID of your "visitors of [site name]" group using this request:
GET /sites/{site-id}/groups?$filter=displayName eq 'visitors of [your-site-name]'
- Replace
{site-id}with your SharePoint site's ID. - Extract the
idvalue from the group object in the response.
2. Assign Permission to the File
Use the driveitem-permissions endpoint to directly add the group to the file's permissions:
POST /drives/{drive-id}/items/{item-id}/permissions Content-Type: application/json { "roles": ["read"], "grantedToIdentities": [ { "group": { "id": "{group-id}", "displayName": "visitors of [your-site-name]" } } ] }
{drive-id}: ID of your document library's drive.{item-id}: ID of the target file.{group-id}: The group ID from step 1.- Adjust
rolesas needed (e.g.,writefor edit access; visitors usually needread).
Required Permissions
Your application must have one of these permissions:
- Delegated:
Sites.Manage.AllorSites.FullControl.All - Application:
Sites.Manage.AllorSites.FullControl.All
内容的提问来源于stack exchange,提问作者Michael.Roger
相关产品推荐
相关产品推荐

