Microsoft Graph file APIs drop pre-authenticated URLs from April 2027
EditorialBy TrustList Editorial
SharePoint and OneDrive downloads, uploads, previews and thumbnails stop returning URLs with embedded auth; opt-in tenant controls for named app IDs come first.
About Microsoft Graph file APIs drop pre-authenticated URLs from April 2027
Microsoft Graph file APIs drop pre-authenticated URLs from April 2027
9 October 2026: From 1 April 2027, selected Microsoft Graph file APIs will stop returning URLs that carry authentication inside them. Microsoft is retiring these pre-authenticated, or tempauth, URLs in SharePoint Online and OneDrive, and any app that stores or redeems one will break.
Not yet independently verified. Read from a public archive of the Microsoft 365 Message Center, not from the admin center itself. The PowerShell cmdlet names for the tenant controls have not been published yet. We will update this when it can be confirmed, and remove this note.
Message Center post MC1492958, published on 9 October 2026, describes the change as a major one with admin and user impact. It covers the Worldwide, GCC, GCC High and DoD clouds. The rollout starts in early April 2027 and is expected to finish in late April.
The affected API families are broad: file download and content, createUploadSession, copy and long-running action monitors, preview, thumbnail, versions and format conversion. Today several of these answer with an HTTP 302 redirect to a link that works for anyone holding it for a short time. After the change they will return the content directly, or hand back a Graph URL that the caller must use with a normal Graph access token.
For apps already written against Graph with standard Entra ID tokens, Microsoft says nothing changes. The risk sits with integrations that take the redirect target, save it, pass it to a browser or a third-party service, or fetch it later without a token. Document viewers, e-signature and backup connectors, migration tools and AI assistants that fetch files for a model are the usual places to look. SharePoint URLs will also stop carrying temporary auth data, so anything that opens them directly needs a valid Entra ID token for the SharePoint Online resource.
Microsoft is adding tenant controls so that administrators can switch the new behaviour on early for specific application IDs. They arrive in a future SharePoint Online PowerShell release, are off by default and are set per app ID, not by Entra group. Direct SharePoint API calls that do not go through Graph are not covered by the control.
Microsoft's suggested order of work is to list the apps that obtain file, version, thumbnail, preview, upload-session or copy URLs through Graph, check whether each one inspects or redeems embedded-auth URLs, confirm it copes with direct content responses and sends the right token, then enable the setting for a small set of app IDs and watch for authentication failures before widening it. Vendors of third-party connectors should be asked now whether they are ready.
Company profile on TrustList: Microsoft
Related on TrustList:
- Exchange Server flaw lets a signed-in user read colleagues' mailboxes
- Entra ID stops processing MemberOf dynamic rules on 3 November
- Outlook will block .msix and .msixbundle attachments from November
Sources
Categories & features
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More SharePointThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.