{"id":14462,"date":"2023-06-28T23:53:05","date_gmt":"2023-06-29T06:53:05","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/?p=14462"},"modified":"2023-06-30T07:28:25","modified_gmt":"2023-06-30T14:28:25","slug":"microsoft-365-developer-proxy-v0-9-with-over-consenting-guidance","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/microsoft-365-developer-proxy-v0-9-with-over-consenting-guidance\/","title":{"rendered":"Microsoft 365 Developer Proxy v0.9 with over-consenting guidance"},"content":{"rendered":"<p>In the latest preview version of the Microsoft 365 Developer Proxy, we are introducing the preview ability to detect over-consented apps that use Microsoft Graph.<\/p>\n<p><a href=\"https:\/\/aka.ms\/m365\/proxy\/download\">Download Microsoft 365 Developer Proxy v0.9<\/a> and check if your apps properly handle API errors.<\/p>\n<h2>Detect over-consented apps that use Microsoft Graph<\/h2>\n<p>Previously, we introduced support for detecting minimal permissions for calling Microsoft Graph APIs. By recording a series of API requests, you can have the Developer Proxy automatically detect what minimal permissions your app needs to call these APIs. This feature is not only great for your productivity, but also helps you build apps that are secure.<\/p>\n<p>In this version, we continued our work related to minimal permissions and introduce a new plugin which helps you find if your app has more permissions than what it needs (also known as over-consenting).<\/p>\n<p>Similarly to the minimal permissions plugin we introduced previously, the new plugin uses the Developer Proxy\u2019s recording mode to capture the series of Microsoft Graph API requests issued by your app. When you stop the recording, the plugin will compare the scopes\/roles on the access token with the minimal permissions needed to call the captured APIs and warn you if your token uses more\/broader permissions.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1.png\"><img decoding=\"async\" class=\"aligncenter wp-image-14463 size-full\" src=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1.png\" alt=\"Terminal with Microsoft 365 Developer Proxy running and warning about over-consented app\" width=\"1418\" height=\"960\" srcset=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1.png 1418w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1-300x203.png 300w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1-1024x693.png 1024w, https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-content\/uploads\/sites\/73\/2023\/06\/image1-768x520.png 768w\" sizes=\"(max-width: 1418px) 100vw, 1418px\" \/><\/a><\/p>\n<p><strong>We compare permissions from the access token with minimal permissions locally and are not uploading your access token to any external API.<\/strong><\/p>\n<p>This new plugin detects over-consenting for both application- and delegated permissions. For more information about how it works, see the <a href=\"https:\/\/github.com\/microsoft\/m365-developer-proxy\/wiki\/Check-if-you-are-using-excessive-Microsoft-Graph-API-permissions\">documentation<\/a>.<\/p>\n<p>We\u2019re releasing this feature in preview and will continue to improve its accuracy. We\u2019d love to hear feedback on how it works and how we can make it better.<\/p>\n<h2>New name, the same awesome tool<\/h2>\n<p>Following our <a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/microsoft-graph-developer-proxy-v0-8-with-minimal-permissions-detection-and-improved-simulating-throttling\/\">announcement<\/a> in May, we\u2019re releasing this version under the new name of <strong>Microsoft 365 Developer Proxy<\/strong>. We hope that it will make it clearer that you can use this tool with Microsoft Graph and any other API on Microsoft 365 and beyond.<\/p>\n<p>As a part of the rename, we <a href=\"https:\/\/github.com\/microsoft\/m365-developer-proxy\">renamed the repository<\/a> and moved it to the Microsoft organization on GitHub. We\u2019ve also changed the name of the executable to <strong>m365proxy<\/strong> which you\u2019ll now use to start the proxy on your machine.<\/p>\n<h2>Try it now<\/h2>\n<p><a href=\"https:\/\/aka.ms\/m365\/proxy\/download\">Download Microsoft 365 Developer Proxy v0.9<\/a> and check if your apps properly handle API errors.<\/p>\n<p>We\u2019re excited about this new version and can\u2019t wait for you to try it out. We look forward to <a href=\"https:\/\/github.com\/microsoft\/m365-developer-proxy\/wiki\/Get-help-and-support\">hearing from you<\/a> about these improvements and how we can continue to make the Microsoft 365 Developer Proxy even better.<\/p>\n<p>Follow us on Twitter <a href=\"https:\/\/twitter.com\/Microsoft365Dev\">@Microsoft365Dev<\/a> to stay up to date on the latest developer news and announcements.<\/p>\n<p>Happy coding!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this new version of the Microsoft 365 Developer Proxy, we are introducing the preview ability to detect over-consented apps that use Microsoft Graph.<\/p>\n","protected":false},"author":74222,"featured_media":14507,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3],"tags":[222],"class_list":["post-14462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-graph","tag-developer-proxy"],"acf":[],"blog_post_summary":"<p>In this new version of the Microsoft 365 Developer Proxy, we are introducing the preview ability to detect over-consented apps that use Microsoft Graph.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/14462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/users\/74222"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/comments?post=14462"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/posts\/14462\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media\/14507"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/media?parent=14462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/categories?post=14462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/microsoft365dev\/wp-json\/wp\/v2\/tags?post=14462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}