API giving access to Entra and Microsoft 365 data. Authorisation uses application or delegated permissions rather than Azure RBAC.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AB-900SC-300
Each book explains Microsoft Graph in context, with comparison tables and the common traps.
Terms in this definition
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.
- Delegated permissions
Entra permission type under which an app works on behalf of whoever is signed in, reaching only the data that user can access.
- Azure RBAC
Azure's model for granting access: built-in or custom roles are assigned at a scope to users, groups or managed identities. Calling Foundry keylessly with Entra ID requires a data-plane role, for example Foundry User (formerly Azure AI User) or Cognitive Services OpenAI User.
Related terms
- AI Administrator
Microsoft Entra role for managing Microsoft 365 Copilot and other AI settings; holders may also consent on behalf of the whole tenant, Microsoft Graph application permissions excepted.
- Application Administrator
Microsoft Entra role able to manage every enterprise application and app registration, application proxy included. It may grant admin consent, apart from Microsoft Graph app roles.
- CAE
Instead of letting an access token run until it expires, Microsoft Entra continuous access evaluation allows Microsoft Graph, Teams, SharePoint Online, Exchange Online and similar services to end a session almost straight away. Triggers include a disabled account, a password reset, revoked tokens, high user risk or a move to a different network location.
- Calendars.ReadWrite
Microsoft Graph permission for creating, reading, updating and deleting events; as an application permission it spans every calendar in the organisation and needs admin consent, while delegated it reaches only the signed-in user's own calendars.
- Copilot connectors
Bring content from outside systems into Microsoft 365 so that Copilot, agents and Microsoft Search can work with it. Items are either indexed in Microsoft Graph with their access lists or fetched on demand, and in both cases the source's permissions still apply.
- EnableMIPLabels
Set this Entra group setting to True with Microsoft Graph PowerShell to allow sensitivity labels on Teams, SharePoint sites and Microsoft 365 groups; afterwards run Execute-AzureAdLabelSync to bring the labels across.
- GraphAPIAuditEvents
Lets you query, in advanced hunting, calls made through Microsoft Entra ID to Microsoft Graph that target the tenant's resources.
- Intune Administrator
A highly privileged Microsoft Entra role with complete read and write control over Intune, along with the ability to look after users, groups and devices. In PowerShell and Microsoft Graph its name is Intune Service Administrator; for everyday tasks Microsoft suggests giving people a least-privilege Intune role instead.