You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求删除权限返回HTTP 403错误——操作不允许问题求助

Fixing Microsoft Graph DELETE Permissions 403 (notAllowed) Error for SharePoint Folders

Hey there, sorry to hear you're stuck with this frustrating permission deletion issue—let's dive into what's likely going on and how to resolve it:

1. Understand Permission Scope Limitations

First, the discrepancy between permission scopes makes total sense:

  • Sites.FullControl.All grants full control over all SharePoint sites, including granular permission management for folders, which is why it works.
  • Files.ReadWrite.All is focused on file content operations (read/write/delete files) across OneDrive and SharePoint, but doesn't cover permission management for SharePoint site assets like folders.
  • Group.ReadWrite.All manages Microsoft 365 Group settings, not SharePoint-specific folder permissions.

If you don't want to use the broad Sites.FullControl.All, try the more granular Sites.Manage.All scope—it's designed specifically for managing site permissions, libraries, and content, which should cover your use case without overgranting.

2. Verify Permission Inheritance & Lock Status

SharePoint folders often inherit permissions from their parent library or site. If the permission you're trying to delete is inherited (check the inheritedFrom field in the permission object returned by GET /drives/{drive-id}/items/{item-id}/permissions), you'll need to delete it at the parent level instead of the folder.

Additionally, check if the site/library has any locks enabled:

  • A read-only site lock or retention policy can block permission modifications. Use this endpoint to check the site's status:
    GET https://graph.microsoft.com/v1.0/sites/{site-id}
    
    Look for the lockState field—if it's set to readOnly, you'll need to remove the lock first.

3. Check Tenant-Level Restrictions

Tenant admins may have enabled SharePoint settings that block permission changes:

  • Go to the SharePoint Admin Center > Permissions > Access Control and verify external sharing settings aren't restricting permission modifications.
  • In Azure AD, check your app's enterprise application settings to ensure there are no tenant-level restrictions on the permission scopes you're using.

4. Escalate to Microsoft Support Effectively

Since you mentioned support hasn't helped yet, provide them with:

  • The exact request-id (6f8821bc-bb2a-46ba-89c8-99238765e27f) and timestamp (2019-04-19T09:48:04) from the inner error.
  • A clear step-by-step reproduction guide (including which scopes you're using, the folder's permission setup).
  • Details on the number of affected tenants to emphasize the impact.

Temporary Workaround

If you need an immediate fix, switch to using Sites.FullControl.All (assuming it aligns with your security policies) to continue deleting permissions while waiting for Microsoft to address the underlying permission model issue.


内容的提问来源于stack exchange,提问作者Jorgen Solberg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:14:57