OneDrive Personal upload session: does If-Match remain a commit precondition?

2026-09-19T04:41:50.9933333+00:00

Context

We update an existing OneDrive Personal item through Microsoft Graph v1.0. We need optimistic concurrency: an upload session created for an exact item with a frozen eTag must never overwrite a write that changes that item before session completion.

In a bounded test:

  1. We created the upload session by item ID and supplied If-Match at session creation.
  2. The session accepted one fragment.
  3. A separate conditional write changed the same item's content and eTag.
  4. Sending the final fragment to the preauthenticated upload URL returned HTTP 404 with code itemNotFound.
  5. An exact-item read afterward showed that the concurrent bytes, eTag, and item identity were preserved.

We are not treating this single observation as a provider guarantee. We need the documented semantics before implementing the production write path.

Relevant documentation:

Questions

  1. On OneDrive Personal, does If-Match supplied to POST /drives/{driveId}/items/{itemId}/createUploadSession remain a commit precondition for the lifetime of that session after fragments have been accepted?
  2. If the exact destination item changes after session creation, is the session guaranteed to be invalidated or rejected before the final fragment can overwrite the newer bytes?
  3. Is HTTP 404 itemNotFound a supported and stable response for that stale-session race? If so, does it guarantee that no uploaded candidate bytes were committed?
  4. With deferCommit:true, is there a supported explicit commit request for OneDrive Personal that targets the existing item by immutable item ID and carries both @microsoft.graph.sourceUrl and If-Match, without addressing or rebinding by parent path/name?
  5. Which HTTP status and error-code combinations at the final fragment or explicit commit guarantee that the stale candidate was not committed?
  6. What recovery sequence is supported when the final response is lost or ambiguous, without a blind write retry?

Please distinguish the documented contract from current implementation behavior and state whether the answer applies specifically to OneDrive Personal. Normative Microsoft documentation links are preferred. If the behavior is not guaranteed, an explicit statement of that limitation would be useful.

Microsoft Security | Microsoft Graph
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.