<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App Service Access Management for SharePoint CRUD - MS Graph API in Product Forum</title>
    <link>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/124360#M54311</link>
    <description>&lt;P&gt;We use delegated auth, the service accounts themselves are then limited to only allow login from certain networks which as far as I'm aware is not possible with application auth.&lt;/P&gt;&lt;P&gt;For our infrastructure teams and other internal departments access is then granted to the service accounts via the standard SharePoint IDAM controls (via invitations or groups from an existing site owner). This also means that if for some reason we need to disable access, we can do so very quickly without impacting any other automations. We generally use a different service account for each process / project (depending on scope).&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jan 2026 12:48:47 GMT</pubDate>
    <dc:creator>jordan.harvey.norfolkcc</dc:creator>
    <dc:date>2026-01-13T12:48:47Z</dc:date>
    <item>
      <title>App Service Access Management for SharePoint CRUD - MS Graph API</title>
      <link>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/62506#M15605</link>
      <description>&lt;P data-sourcepos="7:1-7:106"&gt;&lt;SPAN&gt;I'm using the Microsoft Graph API to manage files (create,&lt;/SPAN&gt;&lt;SPAN&gt; read,&lt;/SPAN&gt;&lt;SPAN&gt; update,&lt;/SPAN&gt;&lt;SPAN&gt; delete) within a SharePoint drive.&lt;/SPAN&gt;&lt;SPAN&gt; What's the best way to control access for my App Service?&lt;/SPAN&gt;&lt;SPAN&gt; Here's what I'm considering:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-sourcepos="9:1-9:65"&gt;
&lt;LI data-sourcepos="9:1-9:65"&gt;&lt;STRONG&gt;Delegated Permissions vs. Application Permissions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Which is more suitable for my scenario?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL data-sourcepos="9:1-9:65"&gt;
&lt;LI data-sourcepos="10:1-10:120"&gt;&lt;STRONG&gt;Delegated Permissions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;If this is the way to go,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;how do I properly assign the required identity to the App Service?&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Can I use a system user?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-sourcepos="12:1-12:103"&gt;&lt;STRONG&gt;Additional Notes:&lt;/STRONG&gt;&lt;SPAN&gt; I'm relatively new to Azure administration,&lt;/SPAN&gt;&lt;SPAN&gt; so any guidance is much appreciated!&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Kantasit&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 20 Feb 2024 09:29:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/62506#M15605</guid>
      <dc:creator>kantasit</dc:creator>
      <dc:date>2024-02-20T09:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: App Service Access Management for SharePoint CRUD - MS Graph API</title>
      <link>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/123854#M54184</link>
      <description>&lt;P&gt;for Sharepoint go with Application permission , sharepoint infrastructure team can create the app id, tenant id and client secret . Which you can use to get the access token to call other endpoints&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 20:15:56 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/123854#M54184</guid>
      <dc:creator>naveed_raza</dc:creator>
      <dc:date>2025-12-08T20:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: App Service Access Management for SharePoint CRUD - MS Graph API</title>
      <link>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/124360#M54311</link>
      <description>&lt;P&gt;We use delegated auth, the service accounts themselves are then limited to only allow login from certain networks which as far as I'm aware is not possible with application auth.&lt;/P&gt;&lt;P&gt;For our infrastructure teams and other internal departments access is then granted to the service accounts via the standard SharePoint IDAM controls (via invitations or groups from an existing site owner). This also means that if for some reason we need to disable access, we can do so very quickly without impacting any other automations. We generally use a different service account for each process / project (depending on scope).&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 12:48:47 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/App-Service-Access-Management-for-SharePoint-CRUD-MS-Graph-API/m-p/124360#M54311</guid>
      <dc:creator>jordan.harvey.norfolkcc</dc:creator>
      <dc:date>2026-01-13T12:48:47Z</dc:date>
    </item>
  </channel>
</rss>

