Commands to grant Azure application access to the Microsoft SharePoint site
Summarize
Summary of Commands to Grant Azure Application Access to the Microsoft SharePoint Site
This guide provides three distinct command-based methods to grant write access to a registered Azure application on a Microsoft SharePoint site at the site level, using the Microsoft Graph API. Each method—Curl, Azure CLI, and PowerShell—achieves the same outcome, allowing flexibility based on the tools already installed by your Azure administrators. These commands are intended for reference and must be customized with your specific tenant, application, and site details.
Show less
Key Details and Preparation
- Replace placeholders such as YOURTENANTID, YOURCLIENTID, YOURCLIENTSECRET, YOURTENANT, YOURSITENAME, and APPREGISTRATIONDISPLAYNAME with actual values from your Azure App Registration and SharePoint environment.
- Values like Tenant ID and Client ID are found in Azure App Registration under Overview, while the Client Secret is under Certificates & Secrets.
- The SharePoint site name corresponds to the subpath after
/sites/in your SharePoint URL, and the tenant name is the subdomain before.sharepoint.com.
Methods to Grant Access
Method 1: Curl
- Step 1: Obtain an OAuth access token for the Azure application.
- Step 2: Retrieve the SharePoint Site ID using the Microsoft Graph API and the access token.
- Step 3: Use the site ID and access token to grant write permissions to the Azure application on the SharePoint site.
This method requires manual extraction of tokens and IDs from JSON responses before proceeding to the next step.
Method 2: Azure CLI
- Execute a bash script where you input your tenant and application details.
- The script automates authentication, token retrieval, SharePoint Site ID fetching, and permission granting.
- Requires the Azure CLI installed and configured on your system.
Method 3: PowerShell
- Run a PowerShell script with your tenant, client, and site information.
- The script handles token acquisition, site ID retrieval, and permission assignment programmatically.
- Requires PowerShell installed on your system.
Practical Use and Considerations
- Choose the method that aligns with your existing toolset and administrative practices for seamless integration.
- Each approach securely grants write access privileges to the specified Azure application on your SharePoint site, enabling automated or application-driven interactions.
- Ensure that the registered Azure application’s permissions and roles are correctly configured in Azure AD to support this access.
- Commands and scripts must be executed by users with appropriate administrative privileges to avoid permission errors.
External References
While this guide includes all necessary command details, for additional context, you may refer to Microsoft Graph API documentation for site permissions and Microsoft Entra ID App Registration references. These are provided solely for installation and API understanding and are external to ServiceNow.
Use one of the following three methods to grant your registered Azure application write access to the Microsoft SharePoint site at the site level, using the Microsoft Graph API.
| Placeholder | Example value | Where to find it |
|---|---|---|
| YOUR_TENANT_ID | xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx | Azure App Registration > Overview > Directory (tenant) ID |
| YOUR_CLIENT_ID | yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy | Azure App Registration > Overview > Application (client) ID |
| YOUR_CLIENT_SECRET | abc123XYZ~mySecretValue | Azure App Registration > Certificates & secrets > Client secrets > Value |
| YOUR_TENANT / TENANT_NAME | contoso | The Microsoft 365 tenant name — the subdomain before .sharepoint.com |
| YOUR_SITE_NAME / SITE_NAME | MSIMSite | The Microsoft SharePoint site name — the relative path segment after /sites/ |
| APP_REGISTRATION_DISPLAY_NAME | Microsoft SharePoint Graph | The display name entered when registering the App |
| YOUR_TOKEN_FROM_STEP1 | eyJ0eXAiOiJKV1Qi... | Curl method only — the access_token value from the Step 1 response |
| YOUR_SITE_ID_FROM_STEP_2 | contoso.sharepoint.com,abc123,def456 | Curl method only — the id value from the Step 2 response |
Method 1 — Curl
Replace all placeholders with values from the table above before executing. Copy the access_token from Step 1 and the site id from Step 2 for use in Step 3.
# Step 1: Get OAuth Token for the Registered Azure Application
curl --location --request GET 'https://login.microsoftonline.com/YOUR_TENANT_ID/oauth2/v2.0/token' \
--header 'accept: application/json' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_id=YOUR_CLIENT_ID' \
--data-urlencode 'client_secret=YOUR_CLIENT_SECRET' \
--data-urlencode 'scope=https://graph.microsoft.com/.default'
# From the response JSON, copy the access_token value -- this becomes YOUR_TOKEN_FROM_STEP1
# Step 2: Retrieve SharePoint Site ID
curl --location 'https://graph.microsoft.com/v1.0/sites/YOUR_TENANT.sharepoint.com:/sites/YOUR_SITE_NAME' \
--header 'Authorization: Bearer YOUR_TOKEN_FROM_STEP1'
# From the response JSON, copy the id value -- this becomes YOUR_SITE_ID_FROM_STEP_2
# Step 3: Grant Azure Application Permissions to the SharePoint Site
curl --location 'https://graph.microsoft.com/v1.0/sites/YOUR_SITE_ID_FROM_STEP_2/permissions' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer YOUR_TOKEN_FROM_STEP1' \
--data '{"roles": ["write"], "grantedToIdentities": [{"application": {"id": "YOUR_CLIENT_ID", "displayName": "APP_REGISTRATION_DISPLAY_NAME"}}]}'
Method 2 — Azure CLI
Replace the placeholder variable values at the top of the script with your actual values, then execute the full script. Requires the Azure CLI. For installation, see Install Azure CLI.
#!/bin/bash
# Replace placeholder values with your actual values
TENANT_ID="YOUR_TENANT_ID"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"
TENANT_NAME="YOUR_TENANT" # e.g., contoso
SITE_NAME="YOUR_SITE_NAME"
APP_DISPLAY_NAME="APP_REGISTRATION_DISPLAY_NAME"
# Authenticate with Azure AD (without requiring a subscription)
az login --service-principal -u "$CLIENT_ID" -p "$CLIENT_SECRET" --tenant "$TENANT_ID" --allow-no-subscriptions
# Get access token for Microsoft Graph API
ACCESS_TOKEN=$(az account get-access-token --resource https://graph.microsoft.com --query accessToken --output tsv)
if [ -z "$ACCESS_TOKEN" ]; then echo "Failed to retrieve access token." >&2; exit 1; fi
# Fetch SharePoint Site ID
SITE_ID=$(az rest --method GET --uri "https://graph.microsoft.com/v1.0/sites/$TENANT_NAME.sharepoint.com:/sites/$SITE_NAME" --headers "Authorization=Bearer $ACCESS_TOKEN" --query "id" --output tsv)
if [ -z "$SITE_ID" ]; then echo "Failed to retrieve SharePoint Site ID." >&2; exit 1; fi
# Grant App Permissions to SharePoint Site
az rest --method POST --uri "https://graph.microsoft.com/v1.0/sites/$SITE_ID/permissions" \
--headers "Authorization=Bearer $ACCESS_TOKEN" "Content-Type=application/json" \
--body "{\"roles\": [\"write\"], \"grantedToIdentities\": [{\"application\": {\"id\": \"$CLIENT_ID\", \"displayName\": \"$APP_DISPLAY_NAME\"}}]}"
Method 3 — PowerShell
Replace the placeholder variable values at the top of the script with your actual values, then execute the full script. For installation, see Install PowerShell.
# Define Variables -- Replace placeholder values with actual values
$tenantId = "YOUR_TENANT_ID"
$clientId = "YOUR_CLIENT_ID"
$clientSecret = "YOUR_CLIENT_SECRET"
$tenantName = "YOUR_TENANT"
$siteName = "SITE_NAME"
$appDisplayName = "APP_REGISTRATION_DISPLAY_NAME"
try {
# Step 1: Get Access Token
$tokenResponse = Invoke-RestMethod -Method Post -Uri "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" -Body @{ grant_type = "client_credentials"; client_id = $clientId; client_secret = $clientSecret; scope = "https://graph.microsoft.com/.default" } -ContentType "application/x-www-form-urlencoded"
$accessToken = $tokenResponse.access_token
if (-not $accessToken) { throw "Failed to retrieve access token." }
# Step 2: Get SharePoint Site ID
$siteResponse = Invoke-RestMethod -Uri "https://graph.microsoft.com/v1.0/sites/$tenantName.sharepoint.com:/sites/$siteName" -Method Get -Headers @{ "Authorization" = "Bearer $accessToken" }
$siteId = $siteResponse.id
if (-not $siteId) { throw "Failed to retrieve SharePoint Site ID." }
# Step 3: Grant App Permissions
$body = @{ roles = @("write"); grantedToIdentities = @(@{ application = @{ id = $clientId; displayName = $appDisplayName } }); displayName = "$appDisplayName" } | ConvertTo-Json -Depth 10
Invoke-RestMethod -Uri "https://graph.microsoft.com/v1.0/sites/$siteId/permissions" -Method Post -Headers @{ "Authorization" = "Bearer $accessToken"; "Content-Type" = "application/json" } -Body $body
} catch { Write-Host "Error: $_" -ForegroundColor Red; exit 1 }
External references
These references are external to ServiceNow® and are provided for tooling installation and API reference only. The commands above are sourced from the Major Security Incident Management Workspace UI, not from these external links.