An authorization policy either grants or excludes permission to a user or user group, acting in one of more roles, to perform an operation on an type of object, for a resource which is scoped by its resource type.
- Add-in-only policy. When the add-in-only policy is used, SharePoint checks only the permissions of the add-in principal. …
- User-only policy. When the user-only policy is used, SharePoint checks only the permissions for the user. …
- User+add-in policy.
Authorization is the function of specifying access rights/privileges to resources, which is related to general information security and computer security, and to access control in particular. More formally, “to authorize” is to define an access policy.