logo
search
Others

Access Tenant-Level Configuration from an SPFx Web Part

Amos GikundaAmos Gikunda Sep 29, 2026 869 views

Question details

A developer needs to read tenant-level configurations and administrator-only settings from within a SharePoint Framework (SPFx) web part.

How to Access Tenant-Level Configuration from an SPFx Web Part
Product
SharePoint Framework (SPFx)
Device & OS
not provided
Scenario
Developing an SPFx web part that requires access to tenant properties or administrative settings for environment-specific behaviors.
Observed behavior
The SPFx web part can easily read supported properties stored in the app catalog but lacks automatic permissions to read or write sensitive, administrator-only tenant settings.
Before you start

Ensure you have the necessary SharePoint Administrator permissions and access to your Microsoft 365 tenant's App Catalog before configuring custom properties or setting up Azure backend APIs.

Solution 1Recommended

Use SharePoint REST API for App Catalog Tenant Properties

Use this method to access standard, non-sensitive tenant properties that are stored directly in the SharePoint app catalog.

SharePoint Framework natively supports reading global configurations stored as tenant properties in the App Catalog. This approach is highly efficient for publicly readable configuration strings but is limited to read-only operations for the web part.

1
Deploy properties to the App Catalog

Ensure that your required tenant properties are already defined and stored within your SharePoint App Catalog.

2
Construct the REST API call

In your SPFx web part code, use the SPHttpClient class to construct a GET request to the REST endpoint: /_api/web/GetStorageEntity('YourPropertyName').

3
Parse the configuration data

Retrieve the JSON response from the REST API call and parse the configuration value to apply it to your web part's logic.

Use SharePoint REST API for App Catalog Tenant Properties
Scope Limitation: This method is best suited for globally accessible configuration data that does not contain highly sensitive credentials or require write access.
Free Microsoft Office alternative

Switch to WPS Office for a Lightweight Document Solution

While managing complex SharePoint environments and SPFx web parts requires a Microsoft 365 ecosystem, you might be looking for a simpler, cost-effective office suite for your team's daily document tasks. WPS Office is a free, lightweight alternative that offers robust capabilities without enterprise overhead.

  1. 1. Download the installer: Visit the WPS Office website and click the free download button for your operating system.
  2. 2. Install the software: Run the downloaded installation file and follow the simple on-screen instructions to set up the suite.
  3. 3. Open your files: Launch WPS Office and instantly open any existing Microsoft Word, Excel, or PowerPoint documents with full formatting preserved.
Free and lightweight office suite for daily productivity.Fully compatible with Microsoft Office formats including .docx, .xlsx, and .pptx.Familiar user interface for seamless migration and zero learning curve.Includes powerful built-in PDF editing and conversion tools.
microsoft office alternative - wps office

Frequently Asked Questions

Can SPFx web parts write directly to tenant properties?

No, standard tenant properties stored in the SharePoint app catalog are read-only when accessed directly from an SPFx web part using SPHttpClient. For any write operations, you must use a secured backend API configured with the appropriate elevated permissions.

Why can't I access admin-only settings natively from my web part?

SPFx web parts execute entirely within the client's browser and operate under the context of the currently logged-in user. To prevent security vulnerabilities, web parts do not automatically inherit tenant-level administrative privileges, restricting access to admin-only configurations.

What is AadHttpClient used for in SPFx development?

The AadHttpClient is an SPFx utility class used to securely authenticate and communicate with APIs protected by Azure Active Directory. It is essential when your web part needs to call custom backends, like Azure Functions, that handle sensitive tenant configurations.