Read-only analysis
The Lens scan is intended for inventory and analysis. It does not move, modify, archive, or delete SharePoint files.
Lens is designed to inventory SharePoint storage without making changes to your Microsoft 365 content.
The Lens scan is intended for inventory and analysis. It does not move, modify, archive, or delete SharePoint files.
Your organization creates and controls the Microsoft Entra application used by Lens for tenant access.
Lens uses Microsoft 365 and SharePoint metadata required to measure storage, file age, sites, and version history.
The required permissions are documented below so administrators can review them before granting consent.
Lens currently requires two Microsoft Graph application permissions. Administrator consent is required.
Review the permission list for the version of Lens you are deploying before granting administrator consent.
The setup guide walks through the Entra application registration, certificate authentication, Graph permissions, and first scan.