Home > Manage App Profiles > API Permissions Required by AvePoint Apps > Apps for Individual Services > Cloud Backup for Microsoft 365 > Cloud Backup for Microsoft 365 (SharePoint Permissions)
Export to PDFWhen you create a Cloud Backup for Microsoft 365 (SharePoint permissions) app profile in AvePoint Online Services, the AvePoint Cloud Backup forMicrosoft365 (SharePoint Permissions) app will be automatically set up in your Microsoft Entra ID.
The table below lists the permissions that should be accepted when you authorize the AvePoint Cloud Backup for Microsoft365 (SharePoint Permissions) app.
| API | Permission | Type | Purpose |
|---|---|---|---|
| Microsoft Graph | Sites.ReadWrite.All(Read and write items in all site collections) | Application | Back up and restore the OneDrive content. |
| Microsoft Graph | Sites.Manage.All(Create, edit, and delete items and lists in all site collections) | Application | Back up and restore the lists in OneDrive, and it is required if the SharePoint list has content approval settings enabled. |
| Microsoft Graph | Files.ReadWrite.All(Read and write files in all site collections) | Application | Back up and restore the OneDrive files. |
| Microsoft Graph | Directory.Read.All(Read directory data) | Application | Retrieve your Microsoft 365 tenant information. |
| Microsoft Graph | User.Read.All(Read all users' full profiles) | Application | Retrieve the UPN for the authors or editors. |
| Microsoft Graph | Sites.FullControl.All(Have full control of all site collections) | Application | Back up some files in specific conditions, such as DLP-sensitive files. |
| Microsoft Graph | Reports.Read.All(Read all usage reports) | Application | Retrieve data size directly, which improves the efficiency of the Subscription Consumption Report. |
| Microsoft Information Protection Sync Service | UnifiedPolicy.Tenant.Read(Read all unified policies of the tenant) | Application | Retrieve information of published sensitivity labels from Microsoft 365. |
| Office 365 Management APIs | ActivityFeed.Read(Read activity data for your organization) | Application | Retrieve activity data in your organization to generate reports. |
| SharePoint/Office 365 SharePoint Online | Sites.FullControl.All(Have full control of all site collections) | Application | Retrieve information of SharePoint Online site collections that are scanned by auto discovery. |
| SharePoint/Office 365 SharePoint Online | User.ReadWrite.All(Read and write user profiles) | Application | Retrieve information of Microsoft 365 user profiles related to OneDrive that are scanned by auto discovery. |
| SharePoint/Office 365 SharePoint Online | TermStore.ReadWrite.All(Read and write managed metadata) | Application | Back up and restore Managed Metadata Service of SharePoint Online site collections and Microsoft 365 Group team sites. |
| Windows Azure Active Directory | User.Read (Sign in and read user profile) | Delegated | Support signing into Cloud Backup for Microsoft 365 with Microsoft 365 accounts. |