Skip to content
TrustList
News

Microsoft Graph file APIs drop pre-authenticated URLs from April 2027

Editorial

By TrustList Editorial

SharePoint and OneDrive downloads, uploads, previews and thumbnails stop returning URLs with embedded auth; opt-in tenant controls for named app IDs come first.

About Microsoft Graph file APIs drop pre-authenticated URLs from April 2027

Microsoft Graph file APIs drop pre-authenticated URLs from April 2027

9 October 2026: From 1 April 2027, selected Microsoft Graph file APIs will stop returning URLs that carry authentication inside them. Microsoft is retiring these pre-authenticated, or tempauth, URLs in SharePoint Online and OneDrive, and any app that stores or redeems one will break.

Not yet independently verified. Read from a public archive of the Microsoft 365 Message Center, not from the admin center itself. The PowerShell cmdlet names for the tenant controls have not been published yet. We will update this when it can be confirmed, and remove this note.

Message Center post MC1492958, published on 9 October 2026, describes the change as a major one with admin and user impact. It covers the Worldwide, GCC, GCC High and DoD clouds. The rollout starts in early April 2027 and is expected to finish in late April.

The affected API families are broad: file download and content, createUploadSession, copy and long-running action monitors, preview, thumbnail, versions and format conversion. Today several of these answer with an HTTP 302 redirect to a link that works for anyone holding it for a short time. After the change they will return the content directly, or hand back a Graph URL that the caller must use with a normal Graph access token.

For apps already written against Graph with standard Entra ID tokens, Microsoft says nothing changes. The risk sits with integrations that take the redirect target, save it, pass it to a browser or a third-party service, or fetch it later without a token. Document viewers, e-signature and backup connectors, migration tools and AI assistants that fetch files for a model are the usual places to look. SharePoint URLs will also stop carrying temporary auth data, so anything that opens them directly needs a valid Entra ID token for the SharePoint Online resource.

Microsoft is adding tenant controls so that administrators can switch the new behaviour on early for specific application IDs. They arrive in a future SharePoint Online PowerShell release, are off by default and are set per app ID, not by Entra group. Direct SharePoint API calls that do not go through Graph are not covered by the control.

Microsoft's suggested order of work is to list the apps that obtain file, version, thumbnail, preview, upload-session or copy URLs through Graph, check whether each one inspects or redeems embedded-auth URLs, confirm it copes with direct content responses and sends the right token, then enable the setting for a small set of app IDs and watch for authentication failures before widening it. Vendors of third-party connectors should be asked now whether they are ready.

Company profile on TrustList: Microsoft

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy