Microsoft 365 planning tool
Microsoft Graph Permissions Advisor
Identify the least-privilege Microsoft Graph permission category for a OneDrive workflow.
Permission category
Least-privilege rationale
Consent-stage guidance
How it works
A useful answer in three clear steps.
- 1
Select the intended file operation
Complete this check before moving to the next decision.
- 2
Review delegated versus application context
Complete this check before moving to the next decision.
- 3
Confirm current Microsoft documentation before implementation
Verify the final result against your current cloud drive or organizational policy.
Frequently asked questions
Before you use this tool
Is the Graph Permissions Advisor free to use?
Yes. You can use this tool in the browser without creating an account or installing software.
How accurate is the Graph Permissions Advisor?
The recommendation follows conservative file-management rules, but it cannot inspect your actual permissions, retention obligations, version history or business context.
Can this tool delete or change my cloud-drive files?
No. This page does not connect to your cloud account and cannot rename, move or delete files. It produces an estimate, analysis or checklist for you to review.
What should I do after using the Graph Permissions Advisor?
Confirm current Microsoft documentation before implementation. Permission names and consent requirements can change; treat the result as architecture guidance, not current authorization documentation.
Keep exploring
Related business planning tools
Tenant Duplicate Savings
Estimate recoverable storage across a Microsoft 365 user population from sampled duplicate rates.
Cleanup ROI Calculator
Compare estimated cleanup savings with staff time and implementation cost.
Cleanup Hours Estimator
Estimate review effort from file count, automation coverage and manual review speed.
Ready to measure duplicate storage with real data?
Choose OneDrive or Dropbox for a read-only scan, then review exact fingerprint matches before any cleanup decision.