On April 1, 2027, SharePoint Online and OneDrive will begin removing pre-authenticated URLs, the self-issued tokens SharePoint embeds directly in a URL, commonly seen as the tempauth query parameter. After that date, URLs returned by the affected Microsoft Graph file APIs will require Entra authentication. If your application downloads, uploads, previews, converts, or monitors file operations through Microsoft Graph, now is the time to plan your move to Microsoft Entra ID access tokens. Key message URLs returned by the affected Microsoft Graph file APIs will stop carrying embedded authorization. Any URL that previously worked without an Authorization header must now be called with a valid Microsoft Entra ID access token. Where a Microsoft Graph alternative exists, a new tenant setting lets administrators opt your app in to receiving Microsoft Graph URLs you redeem with the Graph token you already hold. Everywhere else, acquire a SharePoint Online token and present it. Background...