Access Tenant-Level Configuration from an SPFx Web Part
Question details
A developer needs to read tenant-level configurations and administrator-only settings from within a SharePoint Framework (SPFx) web part.

- Product
- SharePoint Framework (SPFx)
- Device & OS
- not provided
- Scenario
- Developing an SPFx web part that requires access to tenant properties or administrative settings for environment-specific behaviors.
- Observed behavior
- The SPFx web part can easily read supported properties stored in the app catalog but lacks automatic permissions to read or write sensitive, administrator-only tenant settings.
Ensure you have the necessary SharePoint Administrator permissions and access to your Microsoft 365 tenant's App Catalog before configuring custom properties or setting up Azure backend APIs.
Use SharePoint REST API for App Catalog Tenant Properties
Use this method to access standard, non-sensitive tenant properties that are stored directly in the SharePoint app catalog.
SharePoint Framework natively supports reading global configurations stored as tenant properties in the App Catalog. This approach is highly efficient for publicly readable configuration strings but is limited to read-only operations for the web part.
Ensure that your required tenant properties are already defined and stored within your SharePoint App Catalog.
In your SPFx web part code, use the SPHttpClient class to construct a GET request to the REST endpoint: /_api/web/GetStorageEntity('YourPropertyName').
Retrieve the JSON response from the REST API call and parse the configuration value to apply it to your web part's logic.

Access Sensitive Settings via a Secured Backend Service
Use an Azure Function or Azure AD-protected API to securely handle sensitive configurations or advanced admin settings that require elevated privileges.
Switch to WPS Office for a Lightweight Document Solution
While managing complex SharePoint environments and SPFx web parts requires a Microsoft 365 ecosystem, you might be looking for a simpler, cost-effective office suite for your team's daily document tasks. WPS Office is a free, lightweight alternative that offers robust capabilities without enterprise overhead.
- 1. Download the installer: Visit the WPS Office website and click the free download button for your operating system.
- 2. Install the software: Run the downloaded installation file and follow the simple on-screen instructions to set up the suite.
- 3. Open your files: Launch WPS Office and instantly open any existing Microsoft Word, Excel, or PowerPoint documents with full formatting preserved.

Frequently Asked Questions
Can SPFx web parts write directly to tenant properties?
No, standard tenant properties stored in the SharePoint app catalog are read-only when accessed directly from an SPFx web part using SPHttpClient. For any write operations, you must use a secured backend API configured with the appropriate elevated permissions.
Why can't I access admin-only settings natively from my web part?
SPFx web parts execute entirely within the client's browser and operate under the context of the currently logged-in user. To prevent security vulnerabilities, web parts do not automatically inherit tenant-level administrative privileges, restricting access to admin-only configurations.
What is AadHttpClient used for in SPFx development?
The AadHttpClient is an SPFx utility class used to securely authenticate and communicate with APIs protected by Azure Active Directory. It is essential when your web part needs to call custom backends, like Azure Functions, that handle sensitive tenant configurations.




