Rate limiting and API throttling behavior

Forcepoint DSPM automatically manages Microsoft Graph API rate limits during SharePoint Online discovery, classification, and streaming scans. No additional configuration is required.

How it works

When Microsoft SharePoint Online returns an HTTP 429 (Too Many Requests) or HTTP 503 (Service Unavailable) response, Forcepoint DSPM reads the Retry-After value in the response header and automatically pauses all API requests to that connector for the specified duration. Scanning resumes automatically once the cooldown period expires. This behavior applies across all scan types — discovery, classification, and streaming.

This centralized circuit breaker logic improves overall scan performance and prevents unnecessary consumption of your organization's Microsoft Graph API quota during periods of elevated activity or service throttling.