is permissions for sharing a site via ShareSite changed

%3CLINGO-SUB%20id%3D%22lingo-sub-183123%22%20slang%3D%22en-US%22%3Eis%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-183123%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3EI%20have%20a%20SharePoint%20app%20that%20tries%20to%20invite%20people%20to%20a%20site%20via%20the%20PnP%20ShareSite%20method.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAbout%20a%20month%20ago%20the%20app%20stopped%20working%20and%20now%20I%20see%20that%20I%20get%20a%20StatusCode%20of%20Access%20Denied%20when%20I%20try%20to%20share%20even%20though%20the%20app%20has%20full%20Control.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-183123%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAPIs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDeveloper%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPnP%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-401396%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-401396%22%20slang%3D%22en-US%22%3EI%20did%20a%20workaround%20solution%20for%20this%20issue%20by%202%20steps.%20Firstly%2C%20I%20invite%20external%20users%20to%20AD%20as%20guest%20via%20a%20graph%20api.%20Secondly%2C%20I%20share%20the%20site%20using%20PnP%20library.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-401301%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-401301%22%20slang%3D%22en-US%22%3EI%20have%20also%20same%20Issue.%20I%20create%20a%20support%20ticket%20for%20it%20but%20no%20response.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392710%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392710%22%20slang%3D%22en-US%22%3EHi%20Bart%20Kapitein%2C%3CBR%20%2F%3EDid%20you%20have%20a%20solution%20to%20work%20with%20App%20Only%20Authentication%3F%20I%20have%20the%20same%20issue%20as%20well.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-239440%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-239440%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20having%20exactly%20the%20same%20issue.%20Sharing%20a%20site%20using%20a%20ClientContext%20with%20App%20Only%20credentials%20was%20working%20before%2C%20but%20now%20we%20receive%20errors.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20sharing%20a%20site%20using%20a%20ClientContext%20that%20has%20authenticated%20with%20SharePointOnlineCredentials%20the%20sharing%20succeeds.%20Using%20the%20same%20code%20but%20a%20ClientContext%20that%20has%20authenticated%20with%20App%20Only%20credentials%20the%20sharing%20fails%20with%20error%20message%3A%20'%3CEM%3EThe%20user%20has%20insufficient%20permissions%20to%20create%20an%20invitation%3C%2FEM%3E'.%20The%20app%20has%20tenant%20full%20control%20permissions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20think%20the%20SharePoint%20Online%20Sharing%20API%20has%20changed%20and%20the%20change%20is%20causing%20this%20issue%20now.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-183760%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-183760%22%20slang%3D%22en-US%22%3E%3CP%3EAre%20you%20trying%20to%20share%20with%20external%20users%3F%20Can%20you%20please%20provide%20some%20screenshots%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20Service%20Advisory%20in%20O365%20Admin%20Center%20for%20External%20Sharing%20access%20errors.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-904350%22%20slang%3D%22en-US%22%3ERe%3A%20is%20permissions%20for%20sharing%20a%20site%20via%20ShareSite%20changed%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-904350%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20seeing%20this%20now%20as%20well%2C%20and%20maybe%20I%20can%20provide%20some%20additional%20context.%20I'm%20inviting%20external%20users%20via%20app-only%20context.%20This%20used%20to%20work%2C%20and%20now%20it%20does%20not.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20believe%20it%20has%20something%20to%20do%20with%20classic%20versus%20Modern%20sites.%20I%20have%20a%20tenant%20where%20app-only%20invitations%20still%20work%20on%20classic%20team%20sites%20but%20fail%20on%20Modern%20sites.%20Tenant%20and%20site%20settings%20are%20configured%20to%20allow%20sharing%20to%20existing%20and%20new%20external%20users.%20I%20have%20another%20newer%20tenant%2C%20where%20the%20functionality%20is%20disabled%20altogether.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20running%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Evar%20group%20%3D%20ctx.Web.SiteGroups.GetByName(groupName)%3B%3CBR%20%2F%3Ectx.Load(group)%3B%3CBR%20%2F%3Ectx.ExecuteQuery()%3B%3C%2FP%3E%3CP%3Egroup.InviteExternalUser(%22user%40domain.com%22%2C%20true)%3B%3CBR%20%2F%3Ectx.ExecuteQuery()%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20the%20code%20does%20not%20throw%20exceptions%20but%20the%20invite%20is%20not%20sent.%20Sniffing%20the%20traffic%20with%20Fiddler%20I%20can%20see%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20user%20has%20insufficient%20permissions%20to%20create%20an%20invitation%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnybody%20know%20what's%20going%20on%20here%3F%20Really%20would%20like%20to%20avoid%20the%20Graph%20workaround%20if%20possible.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi!

I have a SharePoint app that tries to invite people to a site via the PnP ShareSite method.

 

About a month ago the app stopped working and now I see that I get a StatusCode of Access Denied when I try to share even though the app has full Control.

7 Replies
Highlighted

Are you trying to share with external users? Can you please provide some screenshots

 

There is Service Advisory in O365 Admin Center for External Sharing access errors.

Highlighted

We are having exactly the same issue. Sharing a site using a ClientContext with App Only credentials was working before, but now we receive errors.

 

When sharing a site using a ClientContext that has authenticated with SharePointOnlineCredentials the sharing succeeds. Using the same code but a ClientContext that has authenticated with App Only credentials the sharing fails with error message: 'The user has insufficient permissions to create an invitation'. The app has tenant full control permissions.

 

I think the SharePoint Online Sharing API has changed and the change is causing this issue now.

Highlighted
Hi Bart Kapitein,
Did you have a solution to work with App Only Authentication? I have the same issue as well.
Highlighted
I have also same Issue. I create a support ticket for it but no response.
Highlighted
I did a workaround solution for this issue by 2 steps. Firstly, I invite external users to AD as guest via a graph api. Secondly, I share the site using PnP library.
Highlighted

I'm seeing this now as well, and maybe I can provide some additional context. I'm inviting external users via app-only context. This used to work, and now it does not.

 

I believe it has something to do with classic versus Modern sites. I have a tenant where app-only invitations still work on classic team sites but fail on Modern sites. Tenant and site settings are configured to allow sharing to existing and new external users. I have another newer tenant, where the functionality is disabled altogether. 

 

I'm running: 

 

var group = ctx.Web.SiteGroups.GetByName(groupName);
ctx.Load(group);
ctx.ExecuteQuery();

group.InviteExternalUser("user@domain.com", true);
ctx.ExecuteQuery();

 

and the code does not throw exceptions but the invite is not sent. Sniffing the traffic with Fiddler I can see:

 

The user has insufficient permissions to create an invitation

 

Anybody know what's going on here? Really would like to avoid the Graph workaround if possible.

 

Highlighted

Is there anyone who has been able to resolve this issue.

 

We have a provisioning application as well (.NET) which adds a user to a site and group, through .ShareSite(email, group, false).

 

Sometimes it works, sometimes we get the "The user has insufficient permissions to create an invitation" error.