Microsoft SharePoint and OneDrive
SharePoint and OneDrive Graph scopes, file metadata boundaries, evidence outputs, and troubleshooting.
Microsoft SharePoint and OneDrive
Noru connects to SharePoint and OneDrive through Microsoft Graph to collect document access, site, library, file-sharing, and permission evidence.
Files.Read.All is a broad read scope
Microsoft Graph Files.Read.All can technically read files the consenting
tenant allows. Noru documents the current collector as metadata and permission
evidence, but the requested provider scope is broader than metadata-only.
Permission reference
Prop
Type
Setup
What Noru collects
- SharePoint site and library metadata
- OneDrive and SharePoint file metadata where exposed by the collector
- sharing links, permissions, and access configuration metadata
- document access evidence for control operation
What Noru does not collect
- write access to SharePoint, OneDrive, files, sites, or libraries
- file bodies in the current collector path
- password or credential secrets
Evidence produced
SharePoint and OneDrive evidence supports document control, access review, policy management, retention, sharing, and sensitive document governance controls.
Troubleshooting
Disconnect behavior
Disconnecting stops future syncs. Revoke the OAuth grant or Enterprise Application permission in Microsoft Entra to remove provider-side authorization.
Scope minimization
Use SharePoint/OneDrive consent only when document access evidence is needed.
Review tenant-level file permissions before granting Files.Read.All.