← CBITS Lens overview SECURITY & PERMISSIONS

Know what Lens can access before you run it.

Lens is designed to inventory SharePoint storage without making changes to your Microsoft 365 content.

Read-only analysis

The Lens scan is intended for inventory and analysis. It does not move, modify, archive, or delete SharePoint files.

Customer-controlled identity

Your organization creates and controls the Microsoft Entra application used by Lens for tenant access.

Metadata-focused

Lens uses Microsoft 365 and SharePoint metadata required to measure storage, file age, sites, and version history.

Transparent setup

The required permissions are documented below so administrators can review them before granting consent.

MICROSOFT GRAPH

Required application permissions

Lens currently requires two Microsoft Graph application permissions. Administrator consent is required.

Permission Why Lens uses it
Sites.Read.All Read SharePoint site and document-library metadata required to inventory files and storage across the tenant.
Files.Read.All Read file and version metadata used by the storage analysis without granting write access.

Review the permission list for the version of Lens you are deploying before granting administrator consent.

READ-ONLY BY DESIGN

What Lens does not do during a scan

  • Delete files or folders
  • Move or archive SharePoint content
  • Change permissions or sharing settings
  • Modify version history
  • Replace files with archive stubs
NEXT STEP

Review the setup process before deployment.

The setup guide walks through the Entra application registration, certificate authentication, Graph permissions, and first scan.