MC1492958: Microsoft Graph Adds SharePoint Online Tenant Controls to Prepare for Retirement of Non‑Standard File API Tokens

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
62
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSharePoint AdminsSecurity TeamsDevelopersIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
Microsoft is introducing new SharePoint Online PowerShell tenant controls to help organisations prepare for the April 2027 retirement of pre-authenticated URLs in Microsoft Graph file APIs. Admins will need to identify and test affected applications that rely on embedded authentication URLs and enable the new tenant settings selectively. The impact is high for admins due to required validation, application review, and possible updates to authentication handling, while user impact remains moderate because the change is primarily backend. Urgency is moderate since the final change is over a year away but preparatory work should begin early.
78
🛡️ Admin Impact
35
👥 User Impact
55
⚡ Urgency
72
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

SharePoint Online and OneDrive will retire pre-authenticated file URLs in April 2027. New tenant controls in PowerShell will help admins test and prepare affected Graph API applications in advance.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Identify and test affected apps using the new tenant controls before April 2027 to ensure compatibility.
📅

ROLLOUT TIMELINE

Upcoming:
April 2027

📢 Official Microsoft Message Center Announcement


Microsoft Graph: New tenant controls for retirement of non-standard file API tokens
Message ID: MC1492958

[What and why]

Microsoft is retiring pre-authenticated URLs, also known as tempauth URLs, from SharePoint Online and OneDrive. Beginning April 1, 2027, selected Microsoft Graph file APIs will no longer return URLs that contain embedded authentication information and will no longer issue HTTP 302 redirects to those URLs.

To help organizations prepare, new SharePoint Online tenant controls are coming soon in a future release of Microsoft SharePoint Online PowerShell. These controls will allow administrators to enable updated Microsoft Graph URL behavior for specific applications before the retirement date. This gives organizations time to validate application compatibility, improve security posture, and transition to standard Microsoft Entra ID authentication before the change takes effect.

[Rollout schedule]

  • Service change (Worldwide, GCC, GCC High, DoD): Beginning in early April 2027 and expected to complete in late April 2027

[Impact on your organization]

Who is affected

  • Administrators responsible for Microsoft Graph, SharePoint Online, OneDrive, application integrations, and tenant security
  • Owners of third-party applications, line-of-business applications, custom applications, and automation solutions that use affected Microsoft Graph file APIs
  • Organizations using applications that follow redirects or rely on URLs containing embedded authentication information

Platforms and services

  • Microsoft Graph
  • SharePoint Online
  • OneDrive
  • Microsoft Entra ID
  • Third-party and custom applications that consume Microsoft Graph file APIs

What will happen

Applications using affected Microsoft Graph APIs may currently receive:

  • SharePoint Online download, upload, monitor, preview, version, or similar URLs that contain temporary authentication information.
  • Media service URLs that contain temporary authentication information.
  • HTTP 302 redirects to URLs containing embedded authentication information.

After the change:

  • Applications configured to use supported Microsoft Graph URL alternatives will receive Microsoft Graph URLs and continue authenticating with Microsoft Graph access tokens.
  • APIs that currently return HTTP 302 redirects to temporary authentication URLs will instead return content directly.
  • SharePoint Online URLs returned by affected APIs will no longer contain embedded temporary authentication information.
  • Applications accessing SharePoint Online URLs directly will need a valid Microsoft Entra ID access token for the SharePoint Online resource.
  • Requests made directly to SharePoint APIs rather than through Microsoft Graph are not affected by the tenant control setting.
  • Applications that store, inspect, or redeem URLs containing embedded authentication tokens may stop functioning if not updated before April 1, 2027.
  • The change is not enabled by default through tenant controls. Administrators must choose which application IDs participate in testing and validation.

Affected API families include:

  • File download and content APIs
  • createUploadSession APIs
  • Copy APIs and long-running action monitors
  • Preview APIs
  • Thumbnail APIs
  • Version APIs
  • Format conversion APIs

[Action required and recommendations]

Administrators should begin validation before April 1, 2027.

Recommended actions:

  • Identify applications that obtain file, version, thumbnail, preview, upload-session, or copy-operation URLs through Microsoft Graph.
  • Review whether applications inspect, store, or redeem URLs containing embedded authentication information.
  • Verify that applications can process direct content responses instead of relying on HTTP 302 redirects.
  • Confirm applications can obtain and send the appropriate Microsoft Entra ID access token when calling Microsoft Graph or SharePoint Online endpoints.
  • Enable the new tenant setting for a limited set of application IDs and validate application behavior.
  • Monitor application errors, authentication failures, and sign-in activity during testing.
  • Expand the configuration to additional applications after successful validation.
  • Contact application vendors and internal application owners to confirm support plans and timelines for affected applications.
  • Communicate this upcoming change to development and application support teams.

No action is required if:

  • Your organization does not use the affected APIs.
  • Applications already use direct Microsoft Graph content endpoints and standard Microsoft Entra ID authentication.

Learn more

[Compliance considerations]

QuestionAnswer
Does the change include an admin control, and can it be controlled through Entra ID group membership?Yes. New SharePoint Online tenant controls are being introduced to allow administrators to opt specific application IDs into the updated authentication behavior before the retirement date. Customers should review documentation to determine available scoping and configuration options. Regarding controlled by EntraID Group membership, I do not think that applies. These are SharePoint Online PowerShell cmdlets.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update