Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1011142

Microsoft OneNote: App-only authentication for OneNote Microsoft Graph APIs will retire

Plan for Change
Major Change

Message ID

MC1011142
View in Admin Center

Services

Microsoft 365 suite
Microsoft 365 for the web
Microsoft 365 apps

Summary

Microsoft OneNote will retire app-only authentication for Microsoft Graph APIs on March 31, 2025. Organizations using app-only tokens must switch to delegated authentication tokens to avoid unauthorized errors. This change aims to enhance data security. Transition steps and further details are provided in the message.

Details

Note: If your organization uses Microsoft OneNote, please read.

As part of the Microsoft Secure Future Initiative and to address the growing number of cyber threats, we will change the authentication flow for Microsoft Graph OneNote APIs.

What is the update?

Effective March 31, 2025, we will retire support for authentication tokens with application permissions (app-only tokens) for MSGraph OneNote APIs. We will continue to support authentication tokens that have delegated permissions. While app-only tokens are easy to use, they may be more easily exploited compared to more sophisticated authorization methods. Requests to the Notes API endpoints using tokens with application permissions will return 401 unauthorized errors starting March 31, 2025.

How do I know if this update impacts my service?

  1. Your service will be impacted if you have a custom third party or internal application that performs operations using app-only authentication tokens. Overview of Microsoft Graph permissions - Microsoft Graph | Microsoft Learn documents the difference between delegated access and app-only access.
  2. Your service will not be impacted by these changes if you do not use a third-party or a custom internal application (an “app”) to perform operations on OneNote Notebooks.
  3. Your service will not be impacted by these changes if you use an app, but it performs operations only using “delegated access” (also known as app+user) permissions.

What action is required on my part?

Before March 31, 2025, third-party applications using app-only tokens will need to migrate to using delegated authentication tokens. This update is necessary to enhance the security of your data.

To introduce a more secure form of authorization, please take these steps:

  1. Share this message if you rely on a system integrator partner or other third-party solution to perform operations on OneNote notebooks so that they can take further action.
  2. Transition to using a delegated authentication model if you have your own custom internal application that performs operations on OneNote notebooks and that requires each user to approve the app or an admin to approve on behalf of the user(s).
  3. Transition to using a delegated authentication model with admin consent flow if you are a system integrator partner and your app uses app-only authentication. To do this you will need to make changes to your app using the links in the Learn more section. After those changes are complete, a Global tenant admin will need to approve the app for all users in their tenant through the Microsoft Entra admin center.

Learn more

  • Learn how to configure delegated access for the impacted apps: Get access on behalf of a user - Microsoft Graph | Microsoft Learn
  • If you have questions about user consent vs admin consent flows for delegated access, please review Microsoft Entra app consent experiences - Microsoft identity platform | Microsoft Learn

We appreciate your cooperation in making these necessary changes to ensure the security of your data.

Timeline

📅
Published
Feb 20, 2025
Message published to Message Center
✏️
Updated
Feb 20, 2025
Message content updated
⚠️
Action Required By
Mar 30, 2025
Action deadline
🏁
End Date
May 30, 2025
Message timeline ends

Tags

#User impact#Admin impact#Retirement

Category

📋Plan for Change

Related Messages

Similar updates

MC1189912●

Retirement of Insert Document and Insert PPT feature in Microsoft Whiteboard

Nov 25, 2025
MC884762●

Microsoft PowerPoint: QuickStarter feature retires starting October 2024

Sep 6, 2024
MC720763●

European Digital Markets Act (DMA) Impact on LinkedIn in Microsoft 365 profile card experiences

Feb 28, 2024
MC1041179

Microsoft Viva Engage: Monitoring keywords in the new Communications Dashboard

Mar 25, 2025
MC1182709●

Microsoft Word: The "Send to Kindle" feature will retire

Nov 4, 2025