M365 Permissions Required for Archival & Deletion (OneDrive, SharePoint, Outlook)
Customer-facing documentation for write-level Microsoft Graph permissions and how LightBeam uses them.
Purpose
Summary of Required Permissions
How Archival and Deletion Works in LightBeam
Archival (files)
Deletion (files)
Who can trigger archive/delete in LightBeam
Auditability
Permission-by-Permission Explanation
OneDrive — Files.ReadWrite.All
What the permission allows
Why LightBeam needs it
Impact if not granted
SharePoint — Sites.ReadWrite.All
What the permission allows
Why LightBeam needs it
Impact if not granted
Outlook — Mail.ReadWrite
What the permission allows
Why LightBeam needs it
Impact if not granted
Are these write permissions risky?
PreviousM365 Permissions Required for Archival & Deletion (OneDrive, SharePoint, Outlook)NextAudit Logs
Last updated