Known differences

SharePoint

A SharePoint Online tenant that answers Microsoft Graph's sites, drives, lists and pages, SharePoint's classic _api REST and SOAP reads for the official client libraries, plus an MCP server.

Vendor reference: https://learn.microsoft.com/en-us/sharepoint/dev/sp-add-ins/get-to-know-the-sharepoint-rest-service ↗. Machine-readable: compat/sharepoint.json.

Surfaces

KindPathNotes
REST/v1.0Microsoft Graph sites, drives, driveItems, lists, list items, pages, permissions, delta and subscriptions; $batch
REST/_apiSharePoint REST (also /sites/{name}/_api) for webs, lists, items, files, folders, search, comments and likes; $batch
OAuth/{tenant}/oauth2/v2.0/tokenclient credentials with Graph and SharePoint scopes, Sites.Selected site grants
MCP/mcpStreamable HTTP

API versions: Microsoft Graph v1.0, SharePoint REST (`_api`)

Supported

Not supported

Known differences and test guidance

ScenarioDifference from SharePointIn your tests
Site group membershipMembership is derived from the site's grants and served read-only; adding a member through _api is refused.Grant access through site permissions instead of group membership.
Comment entities in Office365-REST-Python-ClientThe client keys a Comment on Id while the service sends id, as SharePoint Online does, so a comment read from a collection is not addressable as is.Address a fetched comment as Comments({id}) before calling like() or delete_object().

Fault injection

KeyWhat the client sees
throttle429 with Retry-After, the way SharePoint Online throttles

Applies to every system