Areza
Security and data

What runs where, which permissions, and what we can see

Our solutions run in your Microsoft 365 tenant and your Azure subscription in the EU region you choose, get only the permissions each job needs, and change files or permissions only after you approve.

App permissions · illustrative example

Microsoft Graph

The narrowest permissions needed

Access check
read-only
Document check
read-only
Teams bot
Sites.Selected
Reminders
one mailbox

Not needed

Sites.FullControl.All

A managed identity in your Azure subscription

01

What runs where

All resources are created in one resource group in your Azure subscription, in the EU region you choose. In our test that was the Sweden Central region. Microsoft bills you for them.

Security
PartWhere it runsHow it signs in
Document and access checkAn Azure Functions app in your subscriptionManaged identity, read permissions only
Text recognition (OCR)Azure Document Intelligence in your subscriptionThe same managed identity, no key
Teams bot and filingThe same Azure Functions app and an Azure Bot resourceA separate managed identity, write on one site only
Email remindersA shared mailbox in your Exchange OnlineAn app that can send from that mailbox only
Reports and bot stateAn Azure storage account in the same resource groupManaged identity
LogsApplication Insights and Log Analytics in the same regionYour Azure subscription

The storage account keeps its copies in one region (LRS), accepts HTTPS only with TLS 1.2 or later, and allows no public access to files. Microsoft Graph requests are processed by Microsoft's cloud under your agreement with Microsoft; Microsoft does not publish which region processes each Graph request.

02

Permissions, and why each is needed

Your administrator approves the permissions and sees the list before approving. Microsoft Graph application permissions can only be approved by a Global Administrator or a Privileged Role Administrator.

Security
PermissionWhy it is neededAccessUsed by
Files.Read.AllRead the file list and sharing permissions in libraries and OneDrivesReadCheck (option A)
Sites.Read.AllFind SharePoint sites and librariesReadCheck (option A)
User.Read.AllTell active, disabled and deleted accounts apart; identify the person responsibleReadCheck (options A and B)
Sites.Selected (read)Read one named site onlyReadCheck (option B)
Sites.Selected (write)Move, rename and upload files on one site onlyWrite, one siteFiling, Teams bot
Exchange “Application Mail.Send”Send reminders from one shared mailbox onlySend, one mailboxReminders
Azure “Cognitive Services User”Read the text of scanned PDFs without a keyReadText recognition

We do not ask for Sites.FullControl.All, and we do not ask for the right to send email from every mailbox. In our test the access check found the same with read permissions as with Sites.FullControl.All. If files to be filed are kept in personal OneDrives, write access to one site is not enough; we discuss that case separately.

03

What we can and cannot see

We do not download documents. To tune the rules we need file names, so you choose how we see them.

What we see

  • The check's report: file names, paths, dates and who has access
  • We review it in your tenant with read access you grant, or together on a shared screen
  • Log entries, if you give us access to them for support

What we do not see

  • Document contents: when text has to be read, the app in your subscription reads it
  • Sharing link addresses: the app learns that a link exists and who it is for, but does not receive its address
  • Passwords or keys for the check and the bot: they sign in with managed identities, so none exist
  • Your tenant after rollout, unless you grant access for a specific task

04

What happens only after you approve

How this works in document control
  • Every new permission: your administrator approves it
  • Changes to files or permissions after the access check: only from the list you approved, as a separate step
  • A new version of the app: deployed only with your agreement
  • Our temporary access to the resource group during setup: you grant it and you remove it
  • Uncertain files: when the app is unsure, it leaves the file alone and asks a person

05

Logs

Every run and every bot request is written to Application Insights in your subscription: when, which user, which file and which action, such as filed, refused or asked. Document contents are not written to the logs.

Every reminder stays in the shared mailbox's Sent Items. You decide how long logs are kept, because they sit in your subscription.

06

Data processing agreement and confidentiality

On request we sign a data processing agreement under the GDPR and, before work starts, a confidentiality agreement, on your template or ours. The agreement sets out which data we see and for what purpose.

Microsoft 365 and Azure data is processed by Microsoft under your agreement with Microsoft. Where your Microsoft 365 data is stored depends on your tenant's settings; we deploy the Azure resources in the EU region you choose.

07

How access is removed at the end

  1. 01

    Delete the resource group

    The Azure Functions app, its managed identities with all their permissions, the storage and the logs go with it.

  2. 02

    Remove the Exchange right

    Remove the app's right to send from the shared mailbox, the reminder app's registration and, if no longer needed, the mailbox itself. A token already issued stays valid for up to 60 to 90 minutes.

  3. 03

    Remove the Teams app

    Remove the bot's app from your organisation's catalogue.

  4. 04

    Remove our temporary rights

    If you gave us rights in the resource group or elsewhere during setup, remove them. Every step is written down in the handover document.

08

What we checked in our test

The access check before Copilot

In our own Microsoft 365 test environment with invented data, on 2026-10-08 and 2026-10-09:

  • The app could send email only from its own mailbox; Microsoft refused sending as another person (HTTP 403).
  • An unsigned or forged request to the bot's address got HTTP 401.
  • The Azure Functions app's identity held three read permissions only: Files.Read.All, Sites.Read.All and User.Read.All.
  • The access check did not need Sites.FullControl.All: the results were identical.
  • The bot refused to file a document for another person's client and wrote nothing.

Common questions.

Something else on your mind?

Book a call
Does our data leave our Microsoft 365?

No. The apps run in your Microsoft 365 tenant and your Azure subscription, and we do not copy documents to our own servers. When text has to be read, the app in your subscription reads it. We see file names only while tuning the rules, and only in the way you choose.

Which region does the solution run in?

The EU region you choose, in your Azure subscription. In our test it was Sweden Central. Where your Microsoft 365 data is stored depends on your tenant's settings.

Can we remove your access at any time?

Yes. After rollout we have no standing access to your tenant. Deleting the resource group stops and removes every app and its identities. After an app registration is deleted, a token already issued stays valid for up to 60 to 90 minutes.

Do you need our passwords?

No. We do not ask for passwords. Your administrator approves the permissions from their own account, and the check and the bot sign in with managed identities.

Will you sign a data processing agreement?

Yes, on request. Before work starts we can also sign a confidentiality agreement, on your template or ours.

Who in our company has to approve the permissions?

Microsoft Graph application permissions can be approved by a Global Administrator or a Privileged Role Administrator. An Application Administrator or Cloud Application Administrator cannot approve them. The Exchange and Teams steps are done by an administrator with the rights for them.

Is Areza affiliated with Microsoft?

No. Areza is an independent company and is not affiliated with Microsoft. We use publicly documented Microsoft 365, Microsoft Graph and Azure capabilities inside your tenant.

Let's agree where to start

In a 30-minute call we find out where your documents are kept, which permissions would be needed and whether to start with a read-only check or a pilot. You are welcome to bring your IT administrator.

Book a free call

30 min · free · price in writing, excluding VAT

A free 30-minute call

After the call we send a fixed price for the check or the pilot in writing, excluding VAT.

  • Where your documents are kept and which permissions would be needed
  • Where to start: a read-only check or a pilot
  • What your IT team would need to do

1 of 2 · How can we reach you?

It takes less than a minute.