Files.ReadWrite.AppFolder on personal OneDrive: 200 for drive-root metadata

Igor Kolodin 0 Reputation points
2026-09-25T12:57:09.8066667+00:00

In a delegated Microsoft Graph flow for a personal Microsoft account, the token response reported exactly Files.ReadWrite.AppFolder and User.Read. Reading a synthetic file inside the app folder succeeded. A separate GET https://graph.microsoft.com/v1.0/me/drive/root?$select=id returned HTTP 200. Our client canceled the response body without parsing it; it did not list root children or access any file outside the app folder.

Is HTTP 200 for the root driveItem metadata expected with Files.ReadWrite.AppFolder? Does this scope still prevent listing, downloading, and modifying items outside the app folder for a personal OneDrive account? Which endpoint and expected result does Microsoft recommend for a safe negative authorization check using only synthetic data? The generic Get driveItem permission table does not list AppFolder, while the AppFolder guide says the service limits file access to that folder.

Microsoft Security | Microsoft Graph

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.