Microsoft OneNote: App-only authentication for OneNote Microsoft Graph APIs will retire
Microsoft OneNote will retire app-only authentication for Microsoft Graph APIs on March 31, 2025. Organizations using app-only tokens must switch to delegated authentication tokens to avoid unauthorized errors. This change aims to enhance data security. Transition steps and further details are provided in the message. Note: If your organization uses Microsoft OneNote, please read. As part of the Microsoft Secure Future Initiative and to address the growing number of cyber threats, we will change the authentication flow for Microsoft Graph OneNote APIs. What is the update? Effective March 31, 2025, we will retire support for authentication tokens with application permissions (app-only tokens) for MSGraph OneNote APIs. We will continue to support authentication tokens that have delegated permissions. While app-only tokens are easy to use, they may be more easily exploited compared to more sophisticated authorization methods. Requests to the Notes API endpoints using tokens with application permissions will return 401 unauthorized errors starting March 31, 2025. How do I know if this update impacts my service? Your service will be impacted if you have a custom third party or internal application that performs operations using app-only authentication tokens. Overview of Microsoft Graph permissions – Microsoft Graph | Microsoft Learn documents the difference between delegated access and app-only access. Your service will not be impacted by these changes if you do not use a third-party or a custom internal application (an “app”) to perform operations on OneNote Notebooks. Your service will not be impacted by these changes if you use an app, but it performs operations only using “delegated access” (also known as app+user) permissions. What action is required on my part? To introduce a more secure form of authorization, please take these steps: Learn more Before March 31, 2025, third-party applications using app-only tokens will need to migrate to using delegated authentication tokens. This update is necessary to enhance the security of your data. Share this message if you rely on a system integrator partner or other third-party solution to perform operations on OneNote notebooks so that they can take further action. Transition to using a delegated authentication model if […]
The post Microsoft OneNote: App-only authentication for OneNote Microsoft Graph APIs will retire appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft OneNote: App-only authentication for OneNote Microsoft Graph APIs will retire
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Purview: Auto-labeling scalability, policy management, and reporting enhancements
Microsoft Purview is improving auto-labeling capabilities to help organizations manage and validate labeling policies at enterprise scale. The...
Updates available for Microsoft 365 Apps for all channels
We’ve released updates to the following update channels for Microsoft 365 Apps: Current Channel Monthly Enterprise Channel Semi-Annual E...
Microsoft Purview | Data Lifecycle Management – Graph API Support for archive mailboxes
Microsoft is retiring Exchange Web Services (EWS) in Exchange Online by April 2027 and expanding Microsoft Graph API support for archive mailb...
[Whiteboard] Legacy Whiteboard migration to OneDrive
Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...
Microsoft Publisher: Reminder that support ends in October 2026
Microsoft Publisher support ends October 1, 2026; it will no longer be available in Microsoft 365 subscriptions. Users should convert or migra...
[Whiteboard] Standalone app deprecation (Windows, Mobile)
Microsoft will retire standalone Whiteboard apps for Windows, iOS, and Android on October 16, 2026. Users must switch to accessing Whiteboard ...
Microsoft Entra: Optimized passkey registration campaign experience
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoptio...
The September 2026 Scan Cab is available
IMPORTANT: This notice only affects environments where Scan Cab is used to check for update compliance. What and why: The September 2026 Scan ...
Teams admin center device state rules and health alerts retire; use Teams Rooms Pro Management portal
Teams admin center’s device state rules and health alerts will retire by late September 2026. Device health monitoring moves to the Team...
Build apps in Microsoft Copilot Studio and Copilot Cowork
Microsoft announces a preview of app-building in Copilot Cowork starting September 8, 2026, with Copilot Studio following soon. Users with lic...