PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The fastest way to test a Microsoft Graph request is to run it in Graph Explorer, inspect the status, JSON body, and response headers, then repeat it in Postman or code once authentication and permissions are correct. Use a Microsoft 365 Developer sandbox for write operations, choose delegated or application authentication deliberately, and treat HTTP 429 responses according to their Retry-After value.
Choose a safe test environment first
Microsoft Graph requests can read, create, update, or delete tenant data. Microsoft Learn recommends signing in to a Microsoft 365 Developer sandbox rather than a production tenant so that experiments do not unintentionally affect live data.
- Use a sandbox for POST, PATCH, and DELETE requests.
- Use a test account with only the data and permissions needed for the scenario.
- Record the tenant, cloud, API version, endpoint, method, headers, and body for every test.
A request that fails is not necessarily malformed. Authentication, consent, tenant configuration, cloud endpoints, permissions, throttling, and the URL or body can each be the cause.
Free tools Windows power users keep installed
One-click scans. No signup required.
Test a request in Graph Explorer
Graph Explorer is the best starting point for a quick, interactive check. You can run sample queries without signing in; signing in allows requests against your tenant and enables operations that require user context.
- Open Graph Explorer and select a sample query or enter a Graph URL.
- Choose the HTTP method and API version, normally
v1.0for supported production APIs orbetawhen the endpoint documentation specifically requires it. - Add request headers such as
Content-Type: application/jsonand anAcceptheader when the operation needs them. - For a write operation, enter the JSON body exactly as the endpoint documentation specifies.
- Sign in to the sandbox tenant if the request needs delegated access, approve the requested consent when appropriate, and run the request.
- Inspect the response preview, then open the response-headers and code-snippet views to see what was returned and how to reproduce it.
Start with a harmless read, such as a resource that exposes sample data, before attempting a write. A successful read proves only that this particular identity can perform this particular operation; it does not prove that another endpoint or user has the same access.
Construct the request correctly
Endpoint and version
Use the Graph service root followed by the documented resource path and query options. Keep v1.0 and beta tests separate: beta APIs can change and should not be treated as stable production contracts. Include query parameters such as $select, $filter, $top, or $expand only when the endpoint supports them.
Headers and body
JSON writes normally need Content-Type: application/json. Send only properties accepted by that operation. A property with the wrong type, an omitted required field, or an invalid relationship identifier can produce a 400 response even when the URL is correct.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Delegated versus application access
Delegated authentication calls Graph on behalf of a signed-in user. Application authentication (app-only) runs without a signed-in user, using permissions granted to the app. Consult the endpoint’s permission table and match the permission type, scope or role, and administrator consent to the flow you are testing.
Rank #2
Repeatable testing with Postman
Postman is useful when a request must be saved in a collection, shared with a team, or run repeatedly with variables. Microsoft documents a Microsoft Graph Postman collection and separate setup paths for delegated and app-only authentication.
- Import Microsoft’s Graph collection or create a collection with variables for the tenant ID, client ID, client secret or certificate, API version, and resource identifiers.
- Register or select an app in the intended tenant. Add the exact delegated scopes or application roles required by the endpoint.
- Configure OAuth 2.0 for the selected flow. Delegated tests require an interactive user sign-in; app-only tests require the application’s credential and admin consent where required.
- Acquire a token and confirm its audience is Microsoft Graph. Inspect the token’s scopes or roles when diagnosing authorization.
- Set the request URL, method, headers, and body. Save a working request before adding filters, expansions, or writes.
- Use Postman’s console and response panels to compare successful and failing requests.
Postman’s documented defaults target the global cloud. For a national cloud, change both the Graph service root and the authorization and token endpoints to that cloud’s values. A token issued by one cloud is not automatically valid for another cloud’s Graph endpoint.
Runnable request examples
The following examples use a read request. Replace the URL with an endpoint your account and permissions support, and supply a valid bearer token. Never commit tokens or client secrets to source control.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchescURL
curl -i
-H "Authorization: Bearer $GRAPH_TOKEN"
-H "Accept: application/json"
"https://graph.microsoft.com/v1.0/me?$select=id,displayName,userPrincipalName"
Python
import os
import requests
url = "https://graph.microsoft.com/v1.0/me"
headers = {
"Authorization": f"Bearer {os.environ['GRAPH_TOKEN']}",
"Accept": "application/json",
}
response = requests.get(url, headers=headers, timeout=30)
print(response.status_code)
print(dict(response.headers))
print(response.text)
response.raise_for_status()
Node.js
const token = process.env.GRAPH_TOKEN;
const url = 'https://graph.microsoft.com/v1.0/me?$select=id,displayName,userPrincipalName';
const res = await fetch(url, {
headers: {
Authorization: `Bearer ${token}`,
Accept: 'application/json'
}
});
console.log(res.status, Object.fromEntries(res.headers));
console.log(await res.text());
For a JSON write, add Content-Type: application/json and pass the documented body. Test that operation in the sandbox first, because a 2xx response means the tenant data was actually changed.
Rank #3
- Contains one (1) API 5-IN-1 TEST STRIPS Freshwater and Saltwater Aquarium Test Strips 25-Count Box
- Monitors levels of pH, nitrite, nitrate carbonate and general water hardness in freshwater and saltwater aquariums
- Dip test strips into aquarium water and check colors for fast and accurate results
- Helps prevent invisible water problems that can be harmful to fish and cause fish loss
- Use for weekly monitoring and when water or fish problems appear
Read every part of the response
Status code
- 2xx: the operation completed; inspect the body because a successful status can still contain an empty collection or a continuation link.
- 400: check URL syntax, query options, required fields, JSON types, and API-version support.
- 401: the token is missing, expired, malformed, or issued for the wrong audience.
- 403: the identity is authenticated but lacks the endpoint’s permission, consent, role, or tenant access.
- 404: verify the resource ID, tenant, cloud, path, and whether the object is visible to the calling identity.
- 429: Graph throttled the request; follow the retry procedure below.
Body and headers
Read the complete JSON error object, including its code, message, and any nested details. Capture the request-id response header for support and correlation. Some operations also return Retry-After or Location. A Location header can identify an asynchronous-operation URL that must be polled according to that endpoint’s documentation.
Handle throttling and batches
A throttled request returns HTTP 429. If Retry-After is present, wait that many seconds before retrying. If it is absent, use exponential backoff with jitter rather than immediately repeating the request. Reduce concurrency, avoid polling faster than necessary, and request only the fields you need.
JSON batching does not eliminate throttling. Each subrequest is evaluated independently. A batch can have a top-level HTTP 200 while one or more operations inside it returned 429 or another error. Parse every subresponse, wait for each failed operation’s retry delay, and retry only the failed operations in a later batch or individually.
Diagnose failures systematically
| Symptom | Likely cause | What to check |
|---|---|---|
| 401 Unauthorized | Invalid, expired, or wrongly targeted token | Acquire a fresh token, verify its audience, and send it as Authorization: Bearer. |
| 403 Forbidden | Missing permission or consent | Compare the endpoint permission table with the token’s scopes or roles; obtain required admin consent. |
| 400 Bad Request | Malformed URL, query, body, or unsupported property | Remove optional parameters, validate JSON, and compare the request with the endpoint example. |
| 404 Not Found | Wrong cloud, ID, path, or visibility | Confirm tenant and service root, then test the parent resource with the same identity. |
| Works in Explorer but not Postman | Different identity or authentication flow | Compare tenant, token audience, scopes, roles, headers, and API version. |
| Intermittent 429 | Service throttling | Honor Retry-After, back off, lower parallelism, and avoid unnecessary polling. |
A practical test checklist
- Is this the correct tenant and cloud?
- Is the API version supported for the resource?
- Does the token use delegated or application authentication as intended?
- Does the token contain the endpoint’s required scope or role, with consent granted?
- Are method, URL encoding, headers, and JSON types correct?
- Are you testing writes in a developer sandbox?
- Did you save status, body, headers, request ID, and timing?
- If throttled, did you obey the retry delay instead of looping immediately?
Or skip the browser setup
If your goal is to capture a visual record of a Graph-powered web page, ScreenshotNeo can return a screenshot or PDF with one request; it is separate from calling Graph itself. Before capture, it accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo documentation for the remaining capture options. Every plan includes full-page and element capture, device and retina settings, PDF controls, custom CSS and JavaScript, click and wait actions, request blocking, headers, cookies, user agents, timezone and geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage data, and an OpenAPI specification. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
Frequently Asked Questions
Should I use Graph Explorer or Postman first?
Use Graph Explorer for a quick endpoint or permission check. Move to Postman when you need saved collections, variables, or repeatable delegated and app-only authentication.
Does a 200 response from a Graph batch mean every request worked?
No. Inspect each subresponse; individual operations can fail or be throttled even when the batch envelope is 200.
What should I save when reporting a failed request?
Save the method, URL, API version, sanitized headers and body, status, full error JSON, request-id, retry headers, tenant/cloud, and authentication flow.
The Bottom Line
Test safely in Graph Explorer, verify the authentication flow and endpoint permissions, reproduce repeatable cases in Postman or code, and diagnose failures from the full status, body, and headers rather than from the URL alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

