← CBITS Lens overview SETUP GUIDE

Run your first Lens scan.

Install Lens, configure secure Microsoft 365 access, and run your first SharePoint storage analysis.

STEP 1

Install Lens from the Microsoft Store

Install CBITS Lens from the Microsoft Store on the Windows workstation you’ll use to run the analysis.

Go to the download page →
STEP 2

Create the Lens app registration

In Microsoft Entra ID, create an application registration for Lens. This application is controlled by your organization and is used by Lens to access the SharePoint metadata required for analysis. When prompted for supported account types, select Accounts in this organizational directory only (Single tenant).

STEP 3

Configure certificate authentication

Create the Lens certificate pair using your approved process. Once created, upload the public certificate in your Lens app registration:

Certificates & secrets → Certificates → Upload certificate → lens-public-cert.pem

Protect the corresponding private key. Do not upload or distribute the private key with public documentation.

STEP 4

Add Microsoft Graph permissions

In your Lens app registration, navigate to:

API permissions → Add a permission → Microsoft Graph → Application permissions

Select the two permissions below, then grant administrator consent:

Sites.Read.All Allows Lens to read SharePoint site and document-library metadata used for tenant inventory.
Files.Read.All Allows Lens to read file and version metadata required for storage analysis without write access.
STEP 5

Launch Lens and run the scan

Open Lens, enter the tenant and application details requested by the application, verify connectivity, and begin the SharePoint analysis. Large tenants can take substantially longer to inventory than smaller environments.

When the scan completes, review the Lens dashboard for storage totals, inactive content, version storage, savings estimates, and site-level opportunities.