Microsoft 365 Files (OneDrive & SharePoint)
Overview
Microsoft 365 provides two file storage surfaces: OneDrive (personal, per-user) and SharePoint (team/department libraries). Both are accessible through the same Microsoft Graph /drives endpoint. MSP support tasks include investigating access issues, checking storage quotas, managing sharing permissions, and transferring file access during offboarding.
Anti-triggers
- Files on the machine this session is running on — "read the file", "find the config", "list the directory" almost always mean the local filesystem, which Claude Code's own file tools handle. This skill only reaches a customer's cloud storage through Graph, and loading it for local work wastes the call.
- Restoring a deleted or ransomware-encrypted file — past the
recycle bin and retention window, Graph has nothing to return; use
the
backup-packorkaseya/datto-saas-protection. - MSP documentation, runbooks, and stored credentials — those live
in the documentation platform, not the customer's OneDrive; use
kaseya/it-glueorhudu. - A tenant-wide external-sharing posture review — this skill
inspects one item's permissions; the policy question across the
tenant or the fleet is
m365-securityorcipp.
Core Concepts
| Surface | Use | Graph Resource |
|---|---|---|
| OneDrive Personal | Individual user's documents | /users/{id}/drive |
| SharePoint Site Drive | Team/department files | /sites/{id}/drives |
| SharePoint Library | Document library within a site | /drives/{driveId} |
Graph API Patterns
Get a User's OneDrive Info (Quota)
GET /v1.0/users/{userId}/drive?$select=id,name,quota
Response:
{
"id": "drive-guid",
"name": "OneDrive",
"quota": {
"used": 5368709120,
"remaining": 1127428915200,
"total": 1132797624320,
"state": "normal"
}
}
state values: normal, nearing, critical, exceeded
List Files in Root
GET /v1.0/users/{userId}/drive/root/children?$select=id,name,size,lastModifiedDateTime,webUrl,folder,file
List Files in a Specific Folder
GET /v1.0/users/{userId}/drive/items/{folderId}/children?$select=id,name,size,lastModifiedDateTime,webUrl
Search for Files Across OneDrive
GET /v1.0/users/{userId}/drive/root/search(q='budget 2024')?$select=id,name,parentReference,lastModifiedDateTime,webUrl
Get File Sharing Permissions
GET /v1.0/drives/{driveId}/items/{itemId}/permissions
Response includes:
{
"value": [
{
"id": "perm-id",
"roles": ["write"],
"grantedToV2": {
"user": { "displayName": "Bob Manager", "email": "bmanager@contoso.com" }
},
"link": null
},
{
"id": "link-id",
"roles": ["read"],
"link": {
"type": "view",
"scope": "anonymous",
"webUrl": "https://contoso-my.sharepoint.com/..."
}
}
]
}
Share a File (Create Sharing Link)
POST /v1.0/drives/{driveId}/items/{itemId}/createLink
Content-Type: application/json
{
"type": "view",
"scope": "organization"
}
type: view, edit, embed
scope: anonymous, organization, users
Grant Direct Access to a File/Folder
POST /v1.0/drives/{driveId}/items/{itemId}/invite
Content-Type: application/json
{
"requireSignIn": true,
"sendInvitation": false,
"roles": ["read"],
"recipients": [
{ "email": "manager@contoso.com" }
],
"message": "Shared as part of employee transition"
}
Remove a Permission
DELETE /v1.0/drives/{driveId}/items/{itemId}/permissions/{permissionId}
Transfer OneDrive Access (Offboarding)
Grant another user access to the departing employee's entire OneDrive:
POST /v1.0/users/{departingUserId}/drive/root/invite
Content-Type: application/json
{
"requireSignIn": true,
"sendInvitation": false,
"roles": ["write"],
"recipients": [{ "email": "manager@contoso.com" }]
}
Full ownership transfer (changing site admin) requires SharePoint admin PowerShell:
Set-SPOSite -Identity <url> -Owner <email>
SharePoint Document Libraries
List SharePoint Sites
GET /v1.0/sites?search=*&$select=id,displayName,webUrl,createdDateTime
List Drives (Document Libraries) in a Site
GET /v1.0/sites/{siteId}/drives?$select=id,name,driveType,quota
Get Files from a SharePoint Library
GET /v1.0/drives/{driveId}/root/children?$select=id,name,size,lastModifiedDateTime,webUrl
Common MSP Workflows
User Can't Access a File
- Get the file's current permissions:
GET /items/{id}/permissions - Check if user has direct access or if it's link-based
- Check if user is in a group that has access:
GET /users/{id}/memberOf - If sharing link expired: create new sharing link
- If direct access missing: add via
/invite
Pre-Offboarding Data Review
Before offboarding, identify files the user owns that are widely shared:
GET /v1.0/users/{userId}/drive/root/search(q='*')?$select=id,name,permissions,parentReference
Look for items with scope: anonymous sharing links — these should be cleaned up or ownership transferred.
OneDrive Quota Alert
Check users approaching quota limits:
GET /v1.0/users/{userId}/drive?$select=quota
If quota.state is nearing (>80%) or critical (>90%), alert for cleanup or quota increase.
Error Handling
| Error | Cause | Resolution |
|---|---|---|
itemNotFound |
File or folder doesn't exist | Check path or item ID |
accessDenied |
No Files.Read permission | Grant permission and admin consent |
quotaLimitReached |
OneDrive full | Clean up or expand quota |
sharingDisabled |
Tenant sharing policy blocks external | Review SharePoint admin settings |
Permissions Required
| Task | Microsoft Graph Permission |
|---|---|
| Read user's files | Files.Read.All |
| Read/write files | Files.ReadWrite.All |
| Read SharePoint sites | Sites.Read.All |
| Manage sharing | Files.ReadWrite.All |
| SharePoint admin | Sites.ReadWrite.All |
Related Skills
- M365 Users - User offboarding, OneDrive transfer
- M365 Security - Audit external sharing
- M365 API Patterns - Search syntax, pagination