This script removes broad Microsoft Graph and SharePoint application permissions from an existing Azure AD application and replaces them with Sites.Selected permissions for both Microsoft Graph and SharePoint.
Migration Administrators / Azure AD Administrators can use this script instead of manually editing the On Demand Migration for OneDrive Minimal & Full application permissions in Azure.
Script Usage
Note: The script does not assign site permissions – it only configures the application to support Sites.Selected. For more information on assigning permissions, please see the following KB: https://support.quest.com/kb/4382683
Required Customer Inputs
Migration Administrators / Azure AD Administrators must provide:
What the Script Does Not Do
How This Will Change in the Future
This script is required only in the current phase because Sites.Selected is enabled by modifying the existing OneDrive Migration application.
In a future release: