logo
search
Permission & Access Issues

How to Embed a Filtered Read-Only SharePoint List on an External Website

Emma BrownEmma Brown Sep 30, 2026 868 views

Question details

The user needs to securely display partner-specific SharePoint announcements on an external website while strictly preventing visitors from bypassing filters to view unauthorized data.

How to Embed a Filtered Read-Only SharePoint List on an External Website
Product
SharePoint
Device & OS
not provided
Scenario
Displaying partner-specific announcements from a SharePoint list onto a public or external partner website.
Observed behavior
Standard client-side embedding solutions allow users to potentially modify URL filters and access unauthorized partner data, necessitating a secure server-side access control approach.
Before you start

Ensure you have the necessary administrative permissions in SharePoint and the Microsoft Azure Portal to register applications and configure server-side authentication APIs.

Solution 1Recommended

Implement Server-Side Filtering via Microsoft Graph API

The most reliable and secure method to present filtered SharePoint data externally is by using a middleware server to handle API requests, ensuring users cannot manipulate filters.

Relying on frontend iframes or client-side web parts is not secure for sensitive partner data, as technically savvy users can modify URL parameters. A server-side architecture ensures that filtering happens before the data ever reaches the user's browser.

1
Register an Azure AD Application

Log in to the Microsoft Entra admin center (Azure Portal), navigate to 'App registrations', and click 'New registration' to create an app for backend API authentication.

2
Grant Read-Only Permissions

Under 'API permissions' in your registered app, add the Microsoft Graph permission 'Sites.Read.All' to ensure the external application can only view, but never edit, the SharePoint lists.

3
Configure Backend Server Filtering

In your backend server code (e.g., Node.js or C#), construct a Microsoft Graph API GET request to the specific SharePoint list and append OData query parameters like '$filter=PartnerName eq 'SpecificPartner''.

4
Expose a Custom API Endpoint

Create a secure REST API endpoint on your middleware server that executes the Graph API call and returns only the filtered JSON results.

5
Render Data on the External Website

Write JavaScript on your external website's frontend to fetch the data from your custom middleware endpoint and display it in a static, read-only HTML table or list.

Implement Server-Side Filtering via Microsoft Graph API
Security Notice: Never pass Azure AD client secrets or tokens directly to the external website's frontend code. All authentication must occur securely on your backend server.
Free Microsoft Office alternative

Looking for a lightweight and secure document solution?

While configuring Microsoft SharePoint for external data sharing requires complex server-side setups, managing your daily documents shouldn't be difficult. WPS Office provides a free, lightweight, and highly compatible alternative for all your document creation and management needs. Enjoy a familiar interface and seamless migration without the heavy enterprise subscription costs.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
  2. 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen prompts to set up the software.
  3. 3. Open Existing Documents: Launch WPS Office and directly open your existing Microsoft Office files to edit and save with full format compatibility.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation with fast loading and processing times.Familiar user interface ensuring a seamless migration experience.Built-in robust PDF editing, conversion, and secure document sharing features.
microsoft office alternative - wps office

Frequently Asked Questions

Can I use a standard iframe to securely embed a filtered SharePoint list?

No. Standard iframes and basic web part embedding rely on client-side rendering. Visitors can easily modify URL parameters or inspect the page source to bypass filters, potentially exposing unauthorized partner data.

Do external website visitors need a Microsoft 365 license to view the data via an API?

No. If you use a custom backend server with the Microsoft Graph API to fetch and display the data, visitors do not need individual Microsoft 365 licenses. The backend application authenticates to Microsoft on their behalf using an app registration.

How do I ensure the embedded announcements remain read-only?

When configuring your Azure AD application for the backend service, strictly grant 'Sites.Read.All' permissions. Avoid granting any 'Write' or 'Manage' permissions to ensure the data cannot be altered by the external application under any circumstances.