Scope
Specifies the OAuth scope used to request permissions when accessing Microsoft SharePoint data.
Possible Values
AllSites.Manage, AllSites.Read, AllSites.Write, .defaultData Type
string
Default Value
".default"
Remarks
This connection property determines the set of permissions requested during the OAuth flow when authenticating to Microsoft SharePoint. If this property is not specified, the provider automatically uses .default as the scope.
Valid options for this property are:
- .default: Requests application permissions without a user context. All the application permissions that have been granted for that web API are included in the retrieved OAuthAccessToken.
- AllSites.Read: Enables reading from custom lists.
- AllSites.Write: Enables reading from and writing to custom lists.
- AllSites.Manage: Enables reading, writing, and creating custom lists.
This property is useful for controlling the level of access the provider requests during the OAuth flow and ensuring that the token returned has the appropriate permissions for the desired operations.
Additional Information
Choosing a more permissive scope, such as AllSites.Manage, can simplify operations by enabling full access to lists and creation capabilities, but may raise security considerations. Restricting the scope to read or write can reduce potential exposure, but may require reauthentication or scope changes for certain operations. Using .default allows the provider to rely on pre-approved application permissions, which can streamline authentication, but requires proper Azure application configuration.