What we see
- The check's report: file names, paths, dates and who has access
- We review it in your tenant with read access you grant, or together on a shared screen
- Log entries, if you give us access to them for support
Our solutions run in your Microsoft 365 tenant and your Azure subscription in the EU region you choose, get only the permissions each job needs, and change files or permissions only after you approve.
App permissions · illustrative example
read-onlyread-onlySites.Selectedone mailboxNot needed
Sites.FullControl.All
A managed identity in your Azure subscription
01
All resources are created in one resource group in your Azure subscription, in the EU region you choose. In our test that was the Sweden Central region. Microsoft bills you for them.
| Part | Where it runs | How it signs in |
|---|---|---|
| Document and access check | An Azure Functions app in your subscription | Managed identity, read permissions only |
| Text recognition (OCR) | Azure Document Intelligence in your subscription | The same managed identity, no key |
| Teams bot and filing | The same Azure Functions app and an Azure Bot resource | A separate managed identity, write on one site only |
| Email reminders | A shared mailbox in your Exchange Online | An app that can send from that mailbox only |
| Reports and bot state | An Azure storage account in the same resource group | Managed identity |
| Logs | Application Insights and Log Analytics in the same region | Your Azure subscription |
The storage account keeps its copies in one region (LRS), accepts HTTPS only with TLS 1.2 or later, and allows no public access to files. Microsoft Graph requests are processed by Microsoft's cloud under your agreement with Microsoft; Microsoft does not publish which region processes each Graph request.
02
Your administrator approves the permissions and sees the list before approving. Microsoft Graph application permissions can only be approved by a Global Administrator or a Privileged Role Administrator.
| Permission | Why it is needed | Access | Used by |
|---|---|---|---|
Files.Read.All | Read the file list and sharing permissions in libraries and OneDrives | Read | Check (option A) |
Sites.Read.All | Find SharePoint sites and libraries | Read | Check (option A) |
User.Read.All | Tell active, disabled and deleted accounts apart; identify the person responsible | Read | Check (options A and B) |
Sites.Selected (read) | Read one named site only | Read | Check (option B) |
Sites.Selected (write) | Move, rename and upload files on one site only | Write, one site | Filing, Teams bot |
| Exchange “Application Mail.Send” | Send reminders from one shared mailbox only | Send, one mailbox | Reminders |
| Azure “Cognitive Services User” | Read the text of scanned PDFs without a key | Read | Text recognition |
We do not ask for Sites.FullControl.All, and we do not ask for the right to send email from every mailbox. In our test the access check found the same with read permissions as with Sites.FullControl.All. If files to be filed are kept in personal OneDrives, write access to one site is not enough; we discuss that case separately.
03
We do not download documents. To tune the rules we need file names, so you choose how we see them.
04
05
Every run and every bot request is written to Application Insights in your subscription: when, which user, which file and which action, such as filed, refused or asked. Document contents are not written to the logs.
Every reminder stays in the shared mailbox's Sent Items. You decide how long logs are kept, because they sit in your subscription.
06
On request we sign a data processing agreement under the GDPR and, before work starts, a confidentiality agreement, on your template or ours. The agreement sets out which data we see and for what purpose.
Microsoft 365 and Azure data is processed by Microsoft under your agreement with Microsoft. Where your Microsoft 365 data is stored depends on your tenant's settings; we deploy the Azure resources in the EU region you choose.
07
01
The Azure Functions app, its managed identities with all their permissions, the storage and the logs go with it.
02
Remove the app's right to send from the shared mailbox, the reminder app's registration and, if no longer needed, the mailbox itself. A token already issued stays valid for up to 60 to 90 minutes.
03
Remove the bot's app from your organisation's catalogue.
04
If you gave us rights in the resource group or elsewhere during setup, remove them. Every step is written down in the handover document.
08
In our own Microsoft 365 test environment with invented data, on 2026-10-08 and 2026-10-09:
Something else on your mind?
No. The apps run in your Microsoft 365 tenant and your Azure subscription, and we do not copy documents to our own servers. When text has to be read, the app in your subscription reads it. We see file names only while tuning the rules, and only in the way you choose.
The EU region you choose, in your Azure subscription. In our test it was Sweden Central. Where your Microsoft 365 data is stored depends on your tenant's settings.
Yes. After rollout we have no standing access to your tenant. Deleting the resource group stops and removes every app and its identities. After an app registration is deleted, a token already issued stays valid for up to 60 to 90 minutes.
No. We do not ask for passwords. Your administrator approves the permissions from their own account, and the check and the bot sign in with managed identities.
Yes, on request. Before work starts we can also sign a confidentiality agreement, on your template or ours.
Microsoft Graph application permissions can be approved by a Global Administrator or a Privileged Role Administrator. An Application Administrator or Cloud Application Administrator cannot approve them. The Exchange and Teams steps are done by an administrator with the rights for them.
No. Areza is an independent company and is not affiliated with Microsoft. We use publicly documented Microsoft 365, Microsoft Graph and Azure capabilities inside your tenant.