SHD / MC Checker

MC1492958 | Microsoft Graph: New tenant controls for retirement of non-standard file API tokens



MC1492958 | Microsoft Graph: New tenant controls for retirement of non-standard file API tokens

Classification planForChange
Last Updated 10/09/2026 20:43:28
Start Time 10/09/2026 20:43:19
End Time 05/30/2027 07:00:00
Action Required By Date 2027-04-01T07:00:00Z
Message Content

[What and why]

Microsoft is retiring pre-authenticated URLs, also known as tempauth URLs, from SharePoint Online and OneDrive. Beginning April 1, 2027, selected Microsoft Graph file APIs will no longer return URLs that contain embedded authentication information and will no longer issue HTTP 302 redirects to those URLs.

To help organizations prepare, new SharePoint Online tenant controls are coming soon in a future release of Microsoft SharePoint Online PowerShell. These controls will allow administrators to enable updated Microsoft Graph URL behavior for specific applications before the retirement date. This gives organizations time to validate application compatibility, improve security posture, and transition to standard Microsoft Entra ID authentication before the change takes effect.

[Rollout schedule]

  • Service change (Worldwide, GCC, GCC High, DoD): Beginning in early April 2027 and expected to complete in late April 2027

[Impact on your organization]

Who is affected

  • Administrators responsible for Microsoft Graph, SharePoint Online, OneDrive, application integrations, and tenant security
  • Owners of third-party applications, line-of-business applications, custom applications, and automation solutions that use affected Microsoft Graph file APIs
  • Organizations using applications that follow redirects or rely on URLs containing embedded authentication information

Platforms and services

  • Microsoft Graph
  • SharePoint Online
  • OneDrive
  • Microsoft Entra ID
  • Third-party and custom applications that consume Microsoft Graph file APIs

What will happen

Applications using affected Microsoft Graph APIs may currently receive:

  • SharePoint Online download, upload, monitor, preview, version, or similar URLs that contain temporary authentication information.
  • Media service URLs that contain temporary authentication information.
  • HTTP 302 redirects to URLs containing embedded authentication information.

After the change:

  • Applications configured to use supported Microsoft Graph URL alternatives will receive Microsoft Graph URLs and continue authenticating with Microsoft Graph access tokens.
  • APIs that currently return HTTP 302 redirects to temporary authentication URLs will instead return content directly.
  • SharePoint Online URLs returned by affected APIs will no longer contain embedded temporary authentication information.
  • Applications accessing SharePoint Online URLs directly will need a valid Microsoft Entra ID access token for the SharePoint Online resource.
  • Requests made directly to SharePoint APIs rather than through Microsoft Graph are not affected by the tenant control setting.
  • Applications that store, inspect, or redeem URLs containing embedded authentication tokens may stop functioning if not updated before April 1, 2027.
  • The change is not enabled by default through tenant controls. Administrators must choose which application IDs participate in testing and validation.

Affected API families include:

  • File download and content APIs
  • createUploadSession APIs
  • Copy APIs and long-running action monitors
  • Preview APIs
  • Thumbnail APIs
  • Version APIs
  • Format conversion APIs

[Action required and recommendations]

Administrators should begin validation before April 1, 2027.

Recommended actions:

  • Identify applications that obtain file, version, thumbnail, preview, upload-session, or copy-operation URLs through Microsoft Graph.
  • Review whether applications inspect, store, or redeem URLs containing embedded authentication information.
  • Verify that applications can process direct content responses instead of relying on HTTP 302 redirects.
  • Confirm applications can obtain and send the appropriate Microsoft Entra ID access token when calling Microsoft Graph or SharePoint Online endpoints.
  • Enable the new tenant setting for a limited set of application IDs and validate application behavior.
  • Monitor application errors, authentication failures, and sign-in activity during testing.
  • Expand the configuration to additional applications after successful validation.
  • Contact application vendors and internal application owners to confirm support plans and timelines for affected applications.
  • Communicate this upcoming change to development and application support teams.

No action is required if:

  • Your organization does not use the affected APIs.
  • Applications already use direct Microsoft Graph content endpoints and standard Microsoft Entra ID authentication.

Learn more

[Compliance considerations]

Question Answer
Does the change include an admin control, and can it be controlled through Entra ID group membership? Yes. New SharePoint Online tenant controls are being introduced to allow administrators to opt specific application IDs into the updated authentication behavior before the retirement date. Customers should review documentation to determine available scoping and configuration options. Regarding controlled by EntraID Group membership, I do not think that applies. These are SharePoint Online PowerShell cmdlets.
Machine Translation

[何となぜ]

MicrosoftはSharePoint OnlineおよびOneDriveから事前認証済みURL(tempauth URLとも呼ばれる)を廃止します。2027年4月1日以降、選ばれたMicrosoft GraphファイルAPIは、埋め込まれた認証情報を含むURLを返さなくなり、これらのURLへのHTTP 302リダイレクトも発行しなくなります。

組織が準備できるように、Microsoft SharePoint Online PowerShellの将来リリースで新しいテナントコントロールが間もなく導入されます。これらのコントロールにより、管理者は定年前に特定のアプリケーションに対して更新されたMicrosoft Graph URLの動作を有効にすることができます。これにより、組織はアプリケーションの互換性を検証し、セキュリティ体制を改善し、変更が適用される前に標準のMicrosoft Entra ID認証に移行する時間が確保されます。

[展開スケジュール]

  • サービス変更(世界、GCC、GCCハイ、国防総省):2027年4月初旬から始まり、2027年4月下旬に完了予定です

[組織への影響]

影響を受ける人物

  • Microsoft Graph、SharePoint Online、OneDrive、アプリケーション統合、テナントセキュリティを担当する管理者
  • 影響を受けたMicrosoft GraphファイルAPIを使用するサードパーティアプリケーション、ラインオブビジネスアプリケーション、カスタムアプリケーション、自動化ソリューションの所有者
  • その後に続くアプリケーションを使用する組織は、埋め込まれた認証情報を含むURLにリダイレクトまたは依存しています

ホームとサービス

  • マイクロソフトグラフ
  • SharePoint Online
  • OneDrive
  • Microsoft Entra ID
  • Microsoft GraphファイルAPIを利用するサードパーティおよびカスタムアプリケーション

何が起こるのか

影響を受けるMicrosoft Graph APIを使用するアプリケーションは現在以下を受け取ることができます:

  • SharePoint Onlineのダウンロード、アップロード、監視、プレビュー、バージョン、または一時的な認証情報を含む類似のURLです。
  • 一時的な認証情報を含むメディアサービスのURLです。
  • HTTP 302は埋め込まれた認証情報を含むURLにリダイレクトされます。

変更後:

  • サポートされたMicrosoft Graph URL代替を用いるように設定されたアプリケーションは、Microsoft Graph URLを受け取り、Microsoft Graphアクセストークンでの認証を継続します。
  • 現在HTTP 302リダイレクトを一時認証URLに返すAPIは、代わりにコンテンツを直接返します。
  • 影響を受けたAPIが返すSharePoint Online URLには、埋め込まれた一時認証情報は含まれません。
  • SharePoint Online URLに直接アクセスするアプリケーションは、SharePoint Onlineリソースの有効なMicrosoft Entra IDアクセストークンが必要です。
  • Microsoft Graphを経由せず、直接SharePoint APIに送られるリクエストはテナント制御設定の影響を受けません。
  • 埋め込み認証トークンを含むURLを保存、検査、または換金するアプリケーションは、2027年4月1日までに更新されなければ動作を停止する可能性があります。
  • この変更はテナントコントロールによってデフォルトで有効化されません。管理者はテストと検証に参加するアプリケーションIDを選択しなければなりません。

影響を受けるAPIファミリーには以下が含まれます:

  • ファイルダウンロードおよびコンテンツAPI
  • createUploadSession API
  • コピーAPIと長期実行のアクションモニター
  • プレビューAPI
  • サムネイルAPI
  • バージョンAPI
  • フォーマット変換API

[行動が必要と提言]

管理者は2027年4月1日までに検証を開始しるべきです。

推奨される行動:

  • Microsoft Graphを通じてファイル、バージョン、サムネイル、プレビュー、アップロードセッション、コピー操作のURLを取得するアプリケーションを特定します。
  • アプリケーションが埋め込まれた認証情報を含むURLを検査、保存、または交換するかどうかを確認しましょう。
  • アプリケーションがHTTP 302リダイレクトに頼らず、直接的なコンテンツ応答を処理できることを確認しましょう。
  • Microsoft GraphやSharePoint Onlineのエンドポイントを呼び出す際に、アプリケーションが適切なMicrosoft Entra IDアクセストークンを取得・送信できるか確認してください。
  • 限られたアプリケーションIDセットに対して新しいテナント設定を有効にし、アプリケーションの動作を検証します。
  • テスト中のアプリケーションエラー、認証失敗、サインイン活動を監視します。
  • 検証が成功した後、構成を他のアプリケーションにも拡張してください。
  • 対象アプリケーションのサポートプランやスケジュールを確認するために、アプリケーションベンダーや社内のアプリケーション所有者に連絡してください。
  • この変更を開発およびアプリケーションサポートチームに伝えてください。

以下の場合、何の対応も不要です:

  • あなたの組織は影響を受けたAPIを使用しません。
  • アプリケーションはすでに直接のMicrosoft Graphコンテンツエンドポイントと標準的なMicrosoft Entra ID認証を使用しています。

詳しくはこちら

[コンプライアンスの考慮事項]

質問 回答
変更には管理者権限が含まれていますか?また、Entra IDのグループメンバーシップを通じて管理できますか? はい。新しいSharePoint Onlineテナントコントロールが導入され、管理者が特定のアプリケーションIDを更新された認証動作に選出できるようにしています。顧客は利用可能なスコープや設定オプションを確認するためにドキュメントをご確認ください。EntraIDグループメンバーシップによる制御については、該当しないと思います。これらはSharePoint OnlineのPowerShellコマンドレットです。