An API that connects multiple Microsoft services, enabling data access and automation across platforms
What Entra permissions are needed to make a Graph API call to create a Sharepoint site?
Made new app with the following:
https://companyname.sharepoint.com/_layouts/15/AppRegNew.aspx
The app identifier has been successfully created.
Client Id: ***********
Client Secret: ***********
Title: test_sharepoint
App Domain: [www.companyname.com]
Redirect URI: https://www.companyname.com/form.php
Went to:
https://companyname.sharepoint.com/_layouts/15/appinv.aspx
Lookup app id.
Added permissions with:
"Create"
"Trust it"
In Entra we have added API permissions to our application we created:
Microsoft Graph:
Directory.ReadWrite.All
SharePoint:
AllSites.Write
AllSites.Read
From our PHP script we successfully request the token from:
https://login.microsoftonline.com/$tenant_id/oauth2/token
$data = array("client_id" => "$client_id@$tenant_id",
"client_secret" => "$client_secret",
//"resource" => "00000003-0000-0ff1-ce00-000000000000/companyname.sharepoint.com@$tenant_id",
"resource" => "https://graph.microsoft.com",
"grant_type" => "client_credentials",
"scope" => "https://graph.microsoft.com/.default"
);
Then we try to create the site with the graph API call:
https://graph.microsoft.com/v1.0/groups
$data = array(
"description"=> "test_description",
"displayName"=> "TEST My modern team site",
"groupTypes"=> [ "Unified" ],
"mailEnabled"=> true,
"mailNickname"=> "mymodernteamsite",
"securityEnabled"=> false
);
This error is returned:
{"error":{"code":"Authorization_RequestDenied","message":"Insufficient privileges to complete the operation.","innerError":{"date":"2025-09-21T23:31:18","request-id":"20cf016c-6731-452b-8f20-0fd3ecsdfgsdfg","client-request-id":"20cf016c-6731-452b-8f20-0fdasdfasdf9eb"}}
From what I have read, this means the permissions are wrong in Entra for Graph API. What permissions do we need? Or is there anything else that needs to be done?