Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Namespace: microsoft.graph
Revoke access to a listItem or driveItem granted via a sharing link by removing the specified driveRecipient entries from the link.
Recipients who already redeemed the link and recipients who only received an invitation both lose access. Revoking a grant removes the recipient from this sharing link only; it doesn't remove any access the recipient has through a different sharing link, a direct grant, or membership in a group that has access.
Note
This action is only supported on sharing links that are scoped to specific users.
This API is available in the following national cloud deployments.
| Global service | US Government L4 | US Government L5 (DOD) | China operated by 21Vianet |
|---|---|---|---|
| ✅ | ✅ | ✅ | ✅ |
Permissions
Choose the permission or permissions marked as least privileged for this API. Use a higher privileged permission or permissions only if your app requires it. For details about delegated and application permissions, see Permission types. To learn more about these permissions, see the permissions reference.
| Permission type | Least privileged permissions | Higher privileged permissions |
|---|---|---|
| Delegated (work or school account) | Files.ReadWrite | Files.ReadWrite.All, Sites.ReadWrite.All |
| Delegated (personal Microsoft account) | Not supported. | Not supported. |
| Application | Files.ReadWrite.All | Sites.ReadWrite.All |
HTTP request
POST /drives/{drive-id}/items/{item-id}/permissions/{perm-id}/revokeGrants
POST /groups/{group-id}/drive/items/{item-id}/permissions/{perm-id}/revokeGrants
POST /me/drive/items/{item-id}/permissions/{perm-id}/revokeGrants
POST /sites/{site-id}/drive/items/{item-id}/permissions/{perm-id}/revokeGrants
POST /sites/{site-id}/lists/{list-id}/items/{listItem-id}/driveItem/permissions/{perm-id}/revokeGrants
POST /users/{user-id}/drive/items/{item-id}/permissions/{perm-id}/revokeGrants
Request headers
| Name | Description |
|---|---|
| Authorization | Bearer {token}. Required. Learn more about authentication and authorization. |
| Content-Type | application/json. Required. |
Request body
In the request body, supply a JSON representation of the parameters.
The following table shows the parameters that can be used with this action.
| Parameter | Type | Description |
|---|---|---|
| grantees | driveRecipient collection | Required. A collection of recipients whose access to the sharing link is revoked. |
Response
If successful, this action returns a 200 OK response code and a permission in the response body that represents the updated state of the sharing link.
The grantedToIdentitiesV2 property of the returned permission lists the recipients on the link after the specified grants are revoked.
This action applies only to sharing links. It can't be used to revoke a direct grant on an item; use Delete permission instead. Supplying the identifier of a permission that isn't a sharing link returns a 400 Bad Request response code.
The sharing link must be scoped to specific users. Links whose scope is anonymous or organization don't track individual grantees. Because these links have no individual grants to revoke, the request returns a 400 Bad Request response code.
For more information about how errors are returned, see Microsoft Graph error responses and resource types.
Examples
Request
The following example shows how to revoke access for a single user on a sharing link.
POST https://graph.microsoft.com/v1.0/me/drive/items/016GVDAP3RCQS5VBQHORFIVU2ZMOSBL25U/permissions/2687a7e0-1b4d-4656-ae32-a4ea393321e1/revokeGrants
Content-Type: application/json
{
"grantees": [
{
"email": "ryan@contoso.com"
}
]
}
Response
The following example shows the response.
Note: The response object shown here might be shortened for readability.
HTTP/1.1 200 OK
Content-Type: application/json
{
"id": "2687a7e0-1b4d-4656-ae32-a4ea393321e1",
"roles": ["write"],
"grantedToIdentitiesV2": [
{
"user": {
"id": "e6842c7e-33a1-4207-8b5a-2710922ac2b2",
"displayName": "Megan Bowen"
},
"siteUser": {
"id": "12",
"displayName": "Megan Bowen",
"loginName": "Megan Bowen"
}
}
],
"link": {
"type": "edit",
"scope": "users",
"webUrl": "https://contoso-my.sharepoint.com/personal/ellen_contoso_com/..."
}
}