logo
search
Permission & Access Issues

Fix Microsoft Graph SharePoint Upload HTTP 403 Error

Adam DavisAdam Davis Sep 28, 2026 869 views

Question details

A C# application receives an HTTP 403 Forbidden error when attempting to upload documents to SharePoint via the Microsoft Graph API, despite having Site.Selected permissions.

How to Fix Microsoft Graph SharePoint Upload HTTP 403 Error
Product
Microsoft Graph API
Device & OS
not provided
Scenario
Uploading documents or creating list items in SharePoint using a C# application with application authentication.
Observed behavior
The API request returns an HTTP 403 Forbidden error during document uploads, even though standard list creation requests succeed.
Before you start

Verify your Azure AD App Registration permissions, ensuring Sites.Selected is correctly granted and admin-consented, and decode your JWT access token to confirm the correct roles are present.

Solution 1Recommended

Verify Token Permissions and Site.Selected Assignments

Ensure your application token contains the necessary permissions and that the specific SharePoint site has been granted write access.

The Sites.Selected scope requires explicit permission assignment at the site level. Even if the Azure app has the scope, the specific SharePoint site must be told to allow your application to write data.

1
Decode Access Token

Use a token decoding tool to inspect your bearer token and check the 'roles' claim to confirm that the Sites.Selected permission is actively included.

2
Verify Site Permissions

Use the SharePoint Permissions API (POST /sites/{site-id}/permissions) to explicitly grant 'write' or 'fullcontrol' access to your specific application for the target site.

3
Check Endpoint URL

Confirm that your upload request URL targets the correct Site ID and Drive ID where the application has been granted the explicit permissions.

Verify Token Permissions and Site.Selected Assignments
Drive vs Site Permissions: List creation may succeed while file uploads fail if the application has permissions applied at the site level but lacks explicit write permissions to the specific Document Library (Drive).
Free Microsoft Office alternative

Simplify Your Document Workflow with WPS Office

Troubleshooting complex API integrations and SharePoint permissions can be time-consuming. If you need a reliable, lightweight suite for local or cloud document management without the enterprise overhead, try WPS Office as your daily driver.

  1. 1. Download WPS Office: Visit the official WPS website and click the free download button for your operating system.
  2. 2. Install the Suite: Run the lightweight installer and follow the simple on-screen instructions to set up the software.
  3. 3. Manage Documents Effortlessly: Open WPS Office to easily edit, save, and collaborate on your documents with full Microsoft format compatibility.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx) for seamless workflow integration.Free, lightweight, and fast to install on any device.Built-in PDF editing and document collaboration tools without complex API setups.Familiar user interface requiring no learning curve for Microsoft Office users.
QA img-9

Frequently Asked Questions

What does the Sites.Selected permission do in Microsoft Graph?

It allows an application to access only specific SharePoint sites rather than all sites in the tenant. However, you must also use a separate API call to grant the app explicit permissions, such as Write or Read, to those specific sites.

Why do list creations succeed but file uploads fail with a 403 error?

This often occurs if the app was granted permissions at the site or list level, but lacks explicit write permissions to the specific Document Library (Drive) where the upload is being attempted.

What details are required for a Microsoft Graph support ticket?

You should include the complete API request URL, the HTTP method used, token type, granted application permissions, Site and List identifiers, and the exact error response body including the request ID and timestamp.