Fix Microsoft Graph SharePoint Upload HTTP 403 Error
Question details
A C# application receives an HTTP 403 Forbidden error when attempting to upload documents to SharePoint via the Microsoft Graph API, despite having Site.Selected permissions.

- Product
- Microsoft Graph API
- Device & OS
- not provided
- Scenario
- Uploading documents or creating list items in SharePoint using a C# application with application authentication.
- Observed behavior
- The API request returns an HTTP 403 Forbidden error during document uploads, even though standard list creation requests succeed.
Verify your Azure AD App Registration permissions, ensuring Sites.Selected is correctly granted and admin-consented, and decode your JWT access token to confirm the correct roles are present.
Verify Token Permissions and Site.Selected Assignments
Ensure your application token contains the necessary permissions and that the specific SharePoint site has been granted write access.
The Sites.Selected scope requires explicit permission assignment at the site level. Even if the Azure app has the scope, the specific SharePoint site must be told to allow your application to write data.
Use a token decoding tool to inspect your bearer token and check the 'roles' claim to confirm that the Sites.Selected permission is actively included.
Use the SharePoint Permissions API (POST /sites/{site-id}/permissions) to explicitly grant 'write' or 'fullcontrol' access to your specific application for the target site.
Confirm that your upload request URL targets the correct Site ID and Drive ID where the application has been granted the explicit permissions.

Submit a Microsoft Graph Support Request
If your permissions are configured correctly and the HTTP 403 error persists, escalate the issue to Microsoft Developer Support.
Simplify Your Document Workflow with WPS Office
Troubleshooting complex API integrations and SharePoint permissions can be time-consuming. If you need a reliable, lightweight suite for local or cloud document management without the enterprise overhead, try WPS Office as your daily driver.
- 1. Download WPS Office: Visit the official WPS website and click the free download button for your operating system.
- 2. Install the Suite: Run the lightweight installer and follow the simple on-screen instructions to set up the software.
- 3. Manage Documents Effortlessly: Open WPS Office to easily edit, save, and collaborate on your documents with full Microsoft format compatibility.

Frequently Asked Questions
What does the Sites.Selected permission do in Microsoft Graph?
It allows an application to access only specific SharePoint sites rather than all sites in the tenant. However, you must also use a separate API call to grant the app explicit permissions, such as Write or Read, to those specific sites.
Why do list creations succeed but file uploads fail with a 403 error?
This often occurs if the app was granted permissions at the site or list level, but lacks explicit write permissions to the specific Document Library (Drive) where the upload is being attempted.
What details are required for a Microsoft Graph support ticket?
You should include the complete API request URL, the HTTP method used, token type, granted application permissions, Site and List identifiers, and the exact error response body including the request ID and timestamp.




