Graph Permissions Explorer
The comprehensive reference for Microsoft Graph API permissions. Explore application and delegated permissions, discover API methods, and find the right scopes for your applications.
What You Can Do
Search Permissions
Quickly find permissions by name, description, or category. Use Ctrl+K for instant search.
Detailed Information
View complete permission details including descriptions, consent types, and IDs.
Code Examples
Get ready-to-use code snippets for C#, JavaScript, PowerShell, and Python.
API Methods
Discover which Graph API endpoints require each permission for v1.0 and beta.
Microsoft Graph permissions, explained
What is a Microsoft Graph permission?
A Microsoft Graph permission (also called a scope or app role) is a named authorization string such as User.Read or Mail.ReadWrite that an application requests in order to access a specific set of Microsoft 365 or Microsoft Entra ID data through the Microsoft Graph API. Each permission has a stable GUID that identifies it inside an app registration manifest.
What is the difference between application and delegated permissions in Microsoft Graph?
A delegated permission lets an application act on behalf of a signed-in user, so the effective access is the intersection of the permission and what that user is already allowed to do. An application permission (app role) lets the application act on its own with no signed-in user, so it applies tenant-wide and always requires administrator consent.
Which Microsoft Graph permissions require admin consent?
All application permissions require administrator consent. Delegated permissions require administrator consent when the consent type is Admin; delegated permissions with a User consent type can be granted by the user during sign-in. Each permission page on this site states the consent requirement explicitly.
How do I find the GUID of a Microsoft Graph permission?
Every permission page on this site publishes the real Microsoft Graph identifiers: the app role ID for the application permission and the OAuth2 permission scope ID for the delegated permission. All 987 permissions are also available as machine-readable JSON at https://permissions.cengizyilmaz.net/data/catalog/permissions.json.
What is a Microsoft first-party application ID?
A Microsoft first-party application ID is the client ID of an application published by Microsoft itself, such as Microsoft Graph PowerShell or Office 365 Exchange Online. Recognizing these IDs makes Entra ID sign-in logs and audit logs readable. This site catalogs 4023 of them with the source that each one came from.
Where does the data on this site come from?
Permission data is refreshed from Microsoft Graph service principals, Microsoft Learn permission and PowerShell documentation, Microsoft Graph OpenAPI metadata, and the Microsoft Entra documentation known GUID catalog. Community-contributed application entries are labeled separately and never merged into the official sources. Snapshot freshness is published at /build-info.json.