Organizations may have questions about how delegated permissions are leveraged by ODM when certain Microsoft Graph API actions are not fully supported with application permissions alone. Specifically, users often need clarification on:
The Microsoft Graph API does not support all migration actions using application permissions only. For instance, reading guest account memberships on the source tenant and writing content (impersonation) to the target tenant often requires delegated permissions. Because of these limitations, ODM must request both application and delegated permissions to complete the full scope of migration tasks.
Use of Delegated Permissions
Account and Token Management
Connection Setup and Security