An API that connects multiple Microsoft services, enabling data access and automation across platforms
Files.ReadWrite.AppFolder on personal OneDrive: 200 for drive-root metadata
In a delegated Microsoft Graph flow for a personal Microsoft account, the token response reported exactly Files.ReadWrite.AppFolder and User.Read. Reading a synthetic file inside the app folder succeeded. A separate GET https://graph.microsoft.com/v1.0/me/drive/root?$select=id returned HTTP 200. Our client canceled the response body without parsing it; it did not list root children or access any file outside the app folder.
Is HTTP 200 for the root driveItem metadata expected with Files.ReadWrite.AppFolder? Does this scope still prevent listing, downloading, and modifying items outside the app folder for a personal OneDrive account? Which endpoint and expected result does Microsoft recommend for a safe negative authorization check using only synthetic data? The generic Get driveItem permission table does not list AppFolder, while the AppFolder guide says the service limits file access to that folder.