Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.
In short
eDiscovery.Read.All is available as both an application permission and a delegated permission in the Microsoft Graph API, grouped under the eDiscovery category. Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user. It grants read-only access to resources. Application permissions always require admin consent.
Permission data: October 3, 2026 at 3:19 AM UTC
Delegated Access
App-Only Access
Permission Details
Application Permission
Read all eDiscovery objects
Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.
Delegated Permission
Admin consent required
Read all eDiscovery objects
Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects on behalf of the signed-in user.
User sees: Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects on your behalf.
Properties
Microsoft Graph betamapped-docs
Properties is shown from beta metadata because a stable v1.0 schema is not available for this resource mapping.
Property
Type
Description
closedBy
identitySet
The user who closed the case.
closedDateTime
DateTimeOffsetNullable
The date and time when the case was closed. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z
createdBy
identitySet
The user who created the case.
createdDateTime
DateTimeOffsetNullable
The date and time when the entity was created. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z
description
StringNullable
The case description.
displayName
StringNullable
The case name.
externalId
StringNullable
The external case number for customer reference.
id
String
The ID for the eDiscovery case. Read-only.
lastModifiedBy
identitySet
The last user who modified the entity.
lastModifiedDateTime
DateTimeOffsetNullable
The latest date and time when the case was modified. The Timestamp type represents date and time information using ISO 8601 format and is always in UTC time. For example, midnight UTC on Jan 1, 2014 is 2014-01-01T00:00:00Z
status
ediscovery.caseStatus
The case status. Possible values are unknown, active, pendingDelete, closing, closed, and closedWithError. For details, see the following table.
custodians
ediscovery.custodian collection
Returns a list of case custodian objects for this case. Nullable.
legalHolds
ediscovery.legalHold collection
Returns a list of case legalHold objects for this case. Nullable.
noncustodialDataSources
ediscovery.noncustodialDataSource collection
Returns a list of case noncustodialDataSource objects for this case. Nullable.
operations
ediscovery.caseOperation collection
Returns a list of case operation objects for this case. Nullable.
Showing 15 of 19 properties.
JSON Representation
Microsoft Graph betamapped-docs
JSON representation is shown from beta metadata because a stable v1.0 schema is not available for this resource mapping.
// Code snippets are only available for the latest version. Current version is 5.x
// Dependencies
using Microsoft.Graph.Models.Security;
var requestBody = new EdiscoveryCaseMember
{
RecipientType = RecipientType.User,
SmtpAddress = "[email protected]",
};
// To initialize your graphClient, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=csharp
var result = await graphClient.Security.Cases.EdiscoveryCases["{ediscoveryCase-id}"].CaseMembers.PostAsync(requestBody);
# Code snippets are only available for the latest version. Current version is 1.x
from msgraph import GraphServiceClient
from msgraph.generated.models.security.ediscovery_case_member import EdiscoveryCaseMember
from msgraph.generated.models.recipient_type import RecipientType
# To initialize your graph_client, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=python
request_body = EdiscoveryCaseMember(
recipient_type = RecipientType.User,
smtp_address = "[email protected]",
)
result = await graph_client.security.cases.ediscovery_cases.by_ediscovery_case_id('ediscoveryCase-id').case_members.post(request_body)
What is the eDiscovery.Read.All Microsoft Graph permission?
eDiscovery.Read.All is available as both an application permission and a delegated permission in the Microsoft Graph API, grouped under the eDiscovery category. Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user. It grants read-only access to resources. Application permissions always require admin consent. It is mapped to the Microsoft Graph ediscovery-case resource type. 247 documented Microsoft Graph REST methods require it. 190 Microsoft Graph PowerShell commands are documented for it.
Is eDiscovery.Read.All an application or a delegated permission?
eDiscovery.Read.All is available as both an application permission (app-only access, no signed-in user) and a delegated permission (access on behalf of a signed-in user).
What is the permission ID (GUID) for eDiscovery.Read.All?
For eDiscovery.Read.All, the application (app role) ID is 50180013-6191-4d1e-a373-e590ff4e66af, and the delegated (OAuth2 scope) ID is 99201db3-7652-4d5a-809a-bdb94f85fe3c. These are the real Microsoft Graph identifiers and can be used directly in an app registration manifest.