能否通过API为单个OneDrive文件夹分配权限,复刻Dropbox Enterprise视图功能
Absolutely—you can absolutely set up granular, per-user permissions for individual OneDrive folders (so each user only sees their assigned folder) using the Microsoft Graph API (the modern, preferred interface for OneDrive/SharePoint, replacing the older OneDrive API). Here’s how to pull it off:
1. Start with the Right API Tool
Skip the legacy OneDrive API and use Microsoft Graph: it’s built for enterprise-scale permission management and works seamlessly with OneDrive for Business (which you’ll want for enterprise use cases like this). All permission operations revolve around the permissions resource in Graph.
2. Assign Folder-Specific Permissions to Users
For each target folder, use the invite endpoint to grant access only to the intended user:
- API Endpoint:
POST /drives/{drive-id}/items/{folder-id}/invite - Sample Request Body:
{ "recipients": [{"email": "user1@yourcompany.com"}], "message": "You’ve been granted access to your dedicated folder", "requireSignIn": true, "sendInvitation": true, "roles": ["read"] }- Set
rolesto"read"for view-only access (matching Dropbox’s "views" behavior), or use"write"/"readwrite"if you need to grant edit access later. - Critical: Each user is only invited to their specific folder—they won’t get access to parent folders or other unrelated folders by default.
- Set
3. Break Permission Inheritance (Critical for Isolation)
OneDrive folders inherit permissions from their parent by default. To make sure your target folder’s permissions are fully isolated:
- Call
POST /drives/{drive-id}/items/{folder-id}/permissions/breakInheritance - Use the parameter
copyExistingPermissions: falseto wipe inherited permissions, so you start with a clean slate for the folder’s access rules.
This ensures no unintended access from parent folder permissions leaks through.
4. Manage Existing Permissions
- Check who has access: Use
GET /drives/{drive-id}/items/{folder-id}/permissionsto list all users/entities with access to the folder. - Update/remove access: Use
PATCHto modify a user’s role, orDELETEon a specific permission resource to revoke access entirely.
5. Enterprise-Scale Tips
- Batch operations: If you’re setting up permissions for dozens/hundreds of users/folders, use Graph’s batch request feature to reduce API call overhead.
- App permissions: Make sure your application has the right Graph permissions—
Files.ReadWrite.AllorSites.ReadWrite.All(depending on whether you’re using OneDrive for Business or SharePoint) will let you manage permissions at scale. - Groups (optional): For teams of users who need access to the same folder, you can use Azure AD groups instead of individual users—but for one-to-one user-folder mapping, direct user invites are the way to go.
With these steps, each user will only see their assigned folder when accessing OneDrive (either via the web UI or your custom app), mirroring the core functionality of Dropbox Enterprise’s "views" feature.
内容的提问来源于stack exchange,提问作者Jonathan Carter

