API Permissions Required by Default AvePoint Apps for Microsoft Tenants

You do not need any permissions or Microsoft licenses other than those listed in this guide.

Which AvePoint Default Apps Have Permission Updates?

- Both **Cloud** **Governance** **for Power Platform** and **EnPower for Power Platform** service apps now include the **PowerPages.Websites.Read** and **PowerPages.Websites.Write** Power Platform API delegated permissions, supporting to manage Power Pages. - The **MyHub** service app now includes the **InformationProtectionPolicy.Read** Microsoft Graph delegated permission to retrieve sensitivity labels that users have access. - The **Cloud Backup for Azure** service app now includes the **DeviceManagementScripts.ReadWrite.All** Microsoft Graph application permission to allow the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts, without a signed-in user.

If your organization has configured app profiles for any of the service apps above, navigate to AvePoint Online Services > Management > App management to re-authorize the app profiles. This will apply the new API permissions and enable access to the related features.

*Note: Reauthorization is only required if you want to use the new features. Existing functionalities will remain unaffected if no action is taken.