| MC1011142 | Microsoft OneNote: App-only authentication for OneNote Microsoft Graph APIs will retire |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 02/20/2025 01:11:22 |
| Start Time | 02/20/2025 01:11:03 |
| End Time | 05/30/2025 07:00:00 |
| Action Required By Date | 2025-03-30T07:00:00Z |
| Message Content |
Note: If your organization uses Microsoft OneNote, please read. As part of the Microsoft Secure Future Initiative and to address the growing number of cyber threats, we will change the authentication flow for Microsoft Graph OneNote APIs. What is the update? Effective March 31, 2025, we will retire support for authentication tokens with application permissions (app-only tokens) for MSGraph OneNote APIs. We will continue to support authentication tokens that have delegated permissions. While app-only tokens are easy to use, they may be more easily exploited compared to more sophisticated authorization methods. Requests to the Notes API endpoints using tokens with application permissions will return 401 unauthorized errors starting March 31, 2025. How do I know if this update impacts my service?
What action is required on my part? Before March 31, 2025, third-party applications using app-only tokens will need to migrate to using delegated authentication tokens. This update is necessary to enhance the security of your data. To introduce a more secure form of authorization, please take these steps:
Learn more
We appreciate your cooperation in making these necessary changes to ensure the security of your data. |