Home > Appendices

Export to PDF

Appendices

The following table details the appendices included in this document.

AppendixDescription
Appendix A: Data Aggregation DetailsLists the sections and columns in Insights reports where the data is aggregated daily.
Appendix B: Exposure and Sensitivity Scan Supported and Unsupported ListLists the supported object levels in which exposure and sensitivity information can be scanned.
Appendix C: Data Update IntervalsLists the intervals for data updates for each event.
Appendix D: Objects Skipped in ScanLists the relative URLs of objects that will be skipped in the data scan of Insights.
Appendix E: Supported and Unsupported Action List of Sharing LinksLists the supported and unsupported actions for sharing links of objects at different levels.
Appendix F: Custom Azure App Permissions ListLists the basic app permissions and additional app permissions for specific features in Insights that need to be added to custom Azure app profiles.
Appendix G: How to Assign a Role to an App?Introduces how to assign a role to an app in Microsoft Entra admin center or Microsoft Azure portal.
Appendix H: Collected Microsoft 365 Activity ListLists the Microsoft 365 activities of each activity type that are collected in Activity explorer.
Appendix I: Permission Difference Between Standard User and VisitorLists the permission difference between standard user and visitor in Insights.

Appendix A: Data Aggregation Details

The table below lists the sections on the dashboard, sections, and columns in Insights reports where the data is aggregated daily. The analysis and aggregation results will be available when the aggregation is completed.

Insights for Microsoft 365

Functional moduleFunctional moduleElement
DashboardAll Microsoft 365 workspaces and Power BIContributing factors
DashboardAll Microsoft 365 workspaces and Power BIOverall risk
DashboardAll Microsoft 365 workspaces and Power BITop 5 sensitive info types
DashboardAll Microsoft 365 workspaces and Power BITop 5 sensitivity labels
DashboardAll Microsoft 365 workspaces and Power BITop 5 trainable classifiers
DashboardOverviewExternal users with the most permissions
UsersOverviewUser trends
UsersExternal usersSites with direct access
UsersExternal usersLast sign-in
UsersExternal usersLast interactive sign-in
UsersExternal usersLast non-interactive sign-in
UsersOrphaned usersSites with direct access
UsersGroups with external usersExternal users
Full scan detailsFull scan detailsTotal sites trend / Total workspaces trend
Activity explorerOverview (Preview)Summary
Activity explorerOverview (Preview)Sign-in distribution
NOTE

For the other sections on the dashboard and other elements of the exposure report, the data is aggregated in real-time based on the scanned data. However, data and permission changes in Microsoft 365 that occur after the scan completes will take Insights some time to show the updated statistics since this is based on the updates of the Microsoft 365 Activity Feed and the data volume.

Insights for Google

Functional moduleFunctional moduleElement
Dashboard
Dashboard
Contributing factors
Dashboard
Dashboard
Overall risk
Dashboard
Dashboard
File security and classification
Dashboard
Dashboard
External users with the most permissions
Dashboard
Dashboard
Identity and Access Management
ExposureSharing linksSensitive items
UsersExternal usersDrives with direct access
UsersGroups with external usersExternal users
UsersUnmanaged usersRequest status
UsersUnmanaged usersRequests sent
UsersUnmanaged usersDrives with direct access
Full scan detailsFull scan detailsTotal drives trend

Insights for Salesforce

Functional moduleElement
Dashboard
Contributing factors
Dashboard
Overall risk
Dashboard
Objects

Appendix B: Exposure and Sensitivity Scan Supported and Unsupported List

Refer to the following table for the supported object levels in which exposure and sensitivity information can be scanned.

√ – Supported; × – Unsupported.

Object level / What to scanExposure informationSensitivity information
Site Collection
Site×
List/Library×
Folder×
File
Item
Workspace×
Artifact

The following table illustrates the supported and unsupported statuses of sensitive info types and sensitivity labels for each element.

Element / What to scanMicrosoft 365 sensitive info typesCustom information typesSensitivity labels
Site Collection PropertiesUnsupportedUnsupportedSupported
File ContentSupportedSupportedUnsupported
File PropertiesUnsupportedSupportedUnsupported
File ColumnsUnsupportedSupportedSupported
Item ContentUnsupportedUnsupportedUnsupported
Item ColumnsUnsupportedSupportedUnsupported
Item Attachment ContentUnsupportedSupportedUnsupported
WorkspaceUnsupportedUnsupportedUnsupported
ArtifactUnsupportedUnsupportedSupported

Appendix C: Data Update Intervals

The following table lists the events that trigger a full scan, database data update, or incremental scan of Insights for Microsoft 365 and the intervals of data updates for the events.

Trigger typeEventDetails
Full scanUpdate risk definition profileEvent triggered.
1 week for changes to no more than 10,000 site collections; 1 month for changes to 10,000–100,000 site collections; over 1 month for changes to more than 100,000 site collections.
Full scanEnable containersEvent triggered.
1 week for changes to no more than 10,000 site collections; 1 month for changes to 10,000–100,000 site collections; over 1 month for changes to more than 100,000 site collections.
Full scanPrioritize in scanEvent triggered.
1 week for changes to no more than 10,000 site collections; 1 month for changes to 10,000–100,000 site collections; over 1 month for changes to more than 100,000 site collections.
Database data updateMove site collections to other containersEvent triggered.
3 days for changes to no more than 10,000 site collections; 2 weeks for changes to more than 10,000 site collections.
Database data updateUpdate settings for user identificationEvent triggered.
3 days for changes to no more than 10,000 site collections; 2 weeks for changes to more than 10,000 site collections.
Database data updateUpdate settings for library exclusionsEvent triggered.
3 days for changes to no more than 10,000 site collections; 2 weeks for changes to more than 10,000 site collections.
Database data updateUpdate site location, site name, team name, and group nameEvent triggered.
3 days for changes to no more than 10,000 site collections; 2 weeks for changes to more than 10,000 site collections.
Database data updateDisable containersThe related data will be retained for 15 days.
Incremental scanMicrosoft 365 activity feeds are detected by Insights, triggered by one of the following actions (not limited to these) in Microsoft 365:
Upload new sensitive data or update existing sensitive data;
Update permissions of objects (granting permissions to users, generating sharing links, etc.);
Apply label to site collections or files.
Event triggered.
For most customers, the data will be updated in a few hours, and up to 2 days based on the data volume.
*Note: Incremental scans rely on the last modified time of items. Newly uploaded items with a last modified time older than one hour may not be detected by an incremental scan and will require a full scan for updates, which is up to 7 days.
Data aggregationNo event related.The interval is 24 hours.
NOTE

Enabling more sensitivity definitions will impact the performance of Insights.

Appendix D: Objects Skipped in Scan

Refer to the following list for the relative URLs of system lists and libraries that will be skipped in the data scan of Insights.

  • /formservertemplates/

  • /style library/

  • /searchcenter/

  • /searchresults/

  • /reports list/

  • /reusablecontent/

  • /lists/categories/

  • /lists/members/

  • /_layouts/

  • /_catalogs/masterpage/

  • /_catalogs/theme/

  • /siteassets/

  • /user photos/

  • /publishingimages/

  • /publishedfeed/

  • /sitecollectionimages/

  • /social/

Insights offers reports on sharing links of the objects in the configured data scope. Based on the user scopes with whom the objects are shared, the sharing link types of objects are defined as follows:

  • Anyone link – The link type for objects of which the link is shared with anyone.

  • Organization link – The link type for objects of which the link is shared with people in organization.

  • Specific link – The link type for objects of which the link is shared with people you choose.

The table below illustrates the supported and unsupported actions for sharing links of objects at different levels.

Object levelLink typeRemove accessSet expiration date
ListAnyone linkSupportedSupported
ListOrganization LinkSupportedUnsupported
ListSpecific linkSupportedUnsupported
Folder (Library)Anyone linkSupportedSupported
Folder (Library)Organization LinkSupportedUnsupported
Folder (Library)Specific linkSupportedUnsupported
Folder (List)Anyone linkNot applicableNot applicable
Folder (List)Organization LinkNot applicableNot applicable
Folder (List)Specific linkSupportedUnsupported
FileAnyone linkSupportedSupported
FileOrganization LinkSupportedUnsupported
FileSpecific linkSupportedUnsupported
ItemAnyone linkSupportedSupported
ItemOrganization LinkSupportedUnsupported
ItemSpecific linkSupportedUnsupported

Appendix F: Custom Azure App Permissions List

To use Insights, you need to create an app for Microsoft 365 to connect AvePoint Online Services to your Microsoft 365 tenant. For more details on app profiles, refer to Permissions for App Authorization.

If you want to manually create an app profile in your Microsoft Entra ID, you need to add API permissions to the custom app. The tables below detail the Insights features and the required permissions.

Basic App Permissions for Microsoft 365

Insights for Microsoft 365 featureAPIRequired app permission
Generate basic reports in InsightsMicrosoft GraphDirectory.Read.All
Generate basic reports in InsightsMicrosoft GraphGroup.Read.All
Generate basic reports in InsightsMicrosoft GraphChannelMember.Read.All
Generate basic reports in InsightsMicrosoft GraphChannelSettings.Read.All
Generate basic reports in InsightsMicrosoft GraphTeamSettings.Read.All
Generate basic reports in InsightsMicrosoft GraphTeamMember.Read.All
Generate basic reports in InsightsMicrosoft GraphFiles.Read.All
Generate basic reports in InsightsMicrosoft GraphSites.Read.All
Generate basic reports in InsightsMicrosoft GraphReports.Read.All
Generate basic reports in InsightsSharePoint/Office 365 SharePoint OnlineSites.FullControl.All
Generate basic reports in InsightsSharePoint/Office 365 SharePoint OnlineUser.Read.All
Generate basic reports in InsightsOffice 365 Management APIsActivityFeed.Read
View sensitivity labelsMicrosoft Information Protection Sync Service
*Note: This is under the APIs my organization uses tab.
UnifiedPolicy.Tenant.Read
Show user photos and metadataMicrosoft GraphUser.Read.All
Show the last sign-in time of external usersMicrosoft GraphAuditLog.Read.All
Automatically sync Microsoft 365 sensitive info typesOffice 365 Exchange OnlineExchange.ManageAsApp (Manage Exchange As Application)
*Note: The app must have the Compliance Administrator role. For details, refer to Appendix G: How to Assign a Role to an App?

App Permissions Required for Additional Features

Insights for Microsoft 365 featureAPIRequired app permission
Add owners to TeamsMicrosoft GraphTeamMember.ReadWrite.All
Remove owners from TeamsMicrosoft GraphTeamMember.ReadWrite.All
Add owners to private channelsMicrosoft GraphChannelMember.ReadWrite.All
Remove owners from private channelsMicrosoft GraphChannelMember.ReadWrite.All
Add owners to Microsoft 365 GroupsMicrosoft GraphGroup.ReadWrite.All
Remove owners from Microsoft 365 GroupsMicrosoft GraphGroup.ReadWrite.All
Apply sensitivity labels with encryption to filesMicrosoft Rights Management Services
*Note: Make sure your organization has a subscription (or service principal) for the Azure Rights Management Services API.
Content.SuperUser
Apply sensitivity labels with encryption to filesMicrosoft Rights Management Services
*Note: Make sure your organization has a subscription (or service principal) for the Azure Rights Management Services API.
Content.Writer
Apply sensitivity labels to site collectionsMicrosoft GraphGroup.ReadWrite.All
Use sensitivity labels in site collection level sensitivity definitionsMicrosoft GraphInformationProtectionPolicy.Read.All
Remove external users from Microsoft EntraMicrosoft GraphUser.ReadWrite.All
Block external users from signing in to Microsoft 365Microsoft GraphUser.ReadWrite.All
Unblock external usersMicrosoft GraphUser.ReadWrite.All
Obtain risky user infoMicrosoft GraphIdentityRiskyUser.ReadWrite.All
Dismiss user riskMicrosoft GraphIdentityRiskyUser.ReadWrite.All
Confirm user compromisedMicrosoft GraphIdentityRiskyUser.ReadWrite.All
Obtain risk detentions information of risky usersMicrosoft GraphIdentityRiskEvent.Read.All
Reset password for risky usersMicrosoft GraphUserAuthenticationMethod.ReadWrite.All
Sync retention labelsMicrosoft GraphRecordsManagement.Read.All
Enable AI Agent workspaces in InsightsMicrosoft GraphUser.Read (Sign in and read user profile)
Enable AI Agent workspaces in InsightsMicrosoft GraphUser.Read.All (Read all users' full profiles)
Enable AI Agent workspaces in InsightsMicrosoft GraphApplication.Read.All (Read applications)
Enable AI Agent workspaces in InsightsMicrosoft GraphOrganization.Read.All (Read organization information)
Enable AI Agent workspaces in InsightsMicrosoft GraphGroup.Read.All (Read all groups)
Enable SharePoint agent workspace in InsightsMicrosoft GraphSites.Read.All (Read items in all site collections)
Enable SharePoint agent workspace in InsightsSharePoint/Office 365 SharePoint OnlineSites.FullControl.All (Have full control of all site collections)
Enable Copilot Studio workspace in InsightsCommercial environment: Dynamics CRM
GCC or GCC High environment: Dataverse
user_impersonation (Access Common Data service as organization users)
Enable Copilot Studio workspace in InsightsAzure Service Managementuser_impersonation (Access Azure Resource Manager as organization users)
Enable PowerApps workspace in InsightsCommercial environment: PowerApps Service
GCC environment: PowerApps Service – GCC
GCC High environment: PowerApps Service – GCC L4
User (Access the PowerApps Service API)
Enable Microsoft Foundry workspace in InsightsAzure Machine Learning Servicesuser_impersonation (Access Azure Machine Learning Services as organization users)

Appendix G: How to Assign a Role to an App?

To block the users that are members or owners of role-assignable groups from signing in to Microsoft 365, the Privileged Authentication Administrator or Global Administrator role must be assigned to the app configured in the app profile, which is a requirement from Microsoft. For detailed information, refer to the Microsoft article Who can perform sensitive actions.

To automatically sync Microsoft 365 sensitive info types either through a daily sync job or by clicking Automatically sync when adding conditions in a sensitivity definition, the Compliance Administrator role must be assigned to the app configured in the app profile, which is required to connect to Security & Compliance PowerShell. For more details, refer to the Microsoft article Assign Microsoft Entra roles to the application.

To assign the role to the app, refer to the following steps:

  1. Log in to Microsoft Entra admin center (or Microsoft Azure portal), and go to Microsoft Entra ID.

  2. Click Roles & admins (or Roles and administrators) in the left pane, and click the Privileged Authentication Administrator or Global Administrator role you want to assign.

    Clicking the Privileged Authentication Administrator role.

  3. On the Assignments page that opens, click Add assignments.

  4. On the Add assignments page, you can enter an application ID in the search box to search for the app to which you want to assign the role.

    NOTE

    You can get an app’s application ID when you create/re-authorize the related app profile in AvePoint Online Services and the Microsoft 365 account sign-in page appears. The application ID will be displayed as the value of the client_id in the URL.

    The value of the client ID in the URL of the Microsoft 365 account sign-in page.

  5. Select the app, and click Add to assign the role. Note that the assigned role will take effect in about 30 minutes.

Appendix H: Collected Microsoft 365 Activity List

The table below lists the activities of each activity type that are collected based on Microsoft 365 activity feeds in activity explorer.

Activity typeActivity
File and page activitiesRemoved retention label
File and page activitiesApplied retention label
File and page activitiesAccessed file
File and page activitiesRecycled a file
File and page activitiesChecked in file
File and page activitiesChecked out file
File and page activitiesCopied file
File and page activitiesDeleted file
File and page activitiesDeleted file from recycle bin
File and page activitiesDiscarded file checkout
File and page activitiesDownloaded file
File and page activitiesModified file
File and page activitiesMoved file
File and page activitiesRenamed file
File and page activitiesRestored file
File and page activitiesUploaded file
File and page activitiesViewed page
File and page activitiesAccessed file continually
File and page activitiesChanged retention label for a file
File and page activitiesChanged record status to locked
File and page activitiesChanged record status to unlocked
File and page activitiesDeleted file marked as a record
File and page activitiesDetected document sensitivity mismatch
File and page activitiesDetected malware in file
File and page activitiesRecycled all minor versions of file
File and page activitiesView signaled by client
File and page activitiesPrefetched page
File and page activitiesPreviewed file
File and page activitiesViewed page continually
File and page activitiesModified file continually
File and page activitiesRecycled all versions of file
File and page activitiesRecycled version of file
Synchronization activitiesAllowed computer to sync files
Synchronization activitiesBlocked computer from syncing files
Synchronization activitiesDownloaded files to computer
Synchronization activitiesDownloaded file changes to computer
Synchronization activitiesUploaded files to document library
Synchronization activitiesUploaded file changes to document library
Folder activitiesCopied folder
Folder activitiesCreated folder
Folder activitiesRecycled a folder
Folder activitiesAdd shortcut to OneDrive
Folder activitiesDeleted folder
Folder activitiesDeleted folder from recycle bin
Folder activitiesModified folder
Folder activitiesMoved folder
Folder activitiesRenamed folder
Folder activitiesRestored folder
Sharing and access request activitiesAccepted access request
Sharing and access request activitiesDenied access request
Sharing and access request activitiesAccepted sharing invitation
Sharing and access request activitiesBlocked sharing invitation
Sharing and access request activitiesCreated a company shareable link
Sharing and access request activitiesCreated access request
Sharing and access request activitiesCreated an anyone link
Sharing and access request activitiesCreated sharing invitation
Sharing and access request activitiesRemoved a company shareable link
Sharing and access request activitiesRemoved an anyone link
Sharing and access request activitiesShared file, folder, or site
Sharing and access request activitiesUpdated an anyone link
Sharing and access request activitiesUsed an anyone link
Sharing and access request activitiesUnshared file, folder, or site
Sharing and access request activitiesUsed a company shareable link
Sharing and access request activitiesWithdrew sharing invitation
Sharing and access request activitiesCreated secure link
Sharing and access request activitiesDeleted secure link
Sharing and access request activitiesUpdated access request
Sharing and access request activitiesUpdated sharing invitation
Sharing and access request activitiesUsed secure link
Sharing and access request activitiesUser added to secure link
Sharing and access request activitiesUser removed from secure link
Sharing and access request activitiesUpdated secure link
Sharing and access request activitiesUsed sharing link
Sharing and access request activitiesUser added to sharing link
Sharing and access request activitiesUpdated sharing link
Sharing and access request activitiesCreated sharing link
Sharing and access request activitiesDeleted sharing link
Sharing and access request activitiesUser removed from sharing link
Sharing and access request activitiesUpdated company link
Site administration activitiesAdded exempt user agent
Site administration activitiesAllowed user to create groups
Site administration activitiesChanged exempt user agents
Site administration activitiesChanged a sharing policy
Site administration activitiesCreate sent to connection
Site administration activitiesCreated site collection
Site administration activitiesDelete sent to connection
Site administration activitiesDeleted site
Site administration activitiesEnabled document preview
Site administration activitiesEnabled legacy workflow
Site administration activitiesEnable office on demand
Site administration activitiesEnabled RSS feeds
Site administration activitiesEnable result source for people searches
Site administration activitiesModified site permissions
Site administration activitiesRenamed site
Site administration activitiesInvoked site design
Site administration activitiesChanged file version trimming settings
Site administration activitiesRemoved from shared with me
Site administration activitiesScheduled site rename
Site administration activitiesSet host site
Site administration activitiesRemoved from site collection
Site administration activitiesAdded allowed data location
Site administration activitiesAdded geo location admin
Site administration activitiesCanceled site geo move
Site administration activitiesChanged device access policy
Site administration activitiesChanged network access policy
Site administration activitiesCompleted site geo move
Site administration activitiesDeleted orphaned hub site
Site administration activitiesJoined site to hub site
Site administration activitiesRegistered hub site
Site administration activitiesRemoved allowed data location
Site administration activitiesRemoved geo location admin
Site administration activitiesScheduled site geo move
Site administration activitiesSet storage quota for geo location
Site administration activitiesUnjoined site from hub site
Site administration activitiesUnregistered hub site
SharePoint list activitiesViewed list
SharePoint list activitiesViewed list item
SharePoint list activitiesDeleted list
SharePoint list activitiesCreated list
SharePoint list activitiesCreated list item
SharePoint list activitiesCreated site column
SharePoint list activitiesDeleted list item
SharePoint list activitiesRecycled list item
SharePoint list activitiesRestored list
SharePoint list activitiesRestored list item
SharePoint list activitiesUpdated list
SharePoint list activitiesUpdated list item
SharePoint list activitiesList design involved
SharePoint permissions activitiesAdded site collection admin
SharePoint permissions activitiesChanged site status to locked
SharePoint permissions activitiesAdded user or group to SharePoint group
SharePoint permissions activitiesCreated group
SharePoint permissions activitiesDeleted group
SharePoint permissions activitiesRemoved user or group from SharePoint group
SharePoint permissions activitiesRequested site admin permissions
SharePoint permissions activitiesUpdated group
SharePoint permissions activitiesRestored sharing inheritance
SharePoint permissions activitiesBroke sharing inheritance
SharePoint permissions activitiesBroke permission level inheritance
SharePoint permissions activitiesModified access request setting
SharePoint permissions activitiesModify 'Members Can Share' setting
SharePoint permissions activitiesRemoved site collection admin
SharePoint permissions activitiesModified access request approver setting
SharePoint permissions activitiesModified access request site description
Information barrier activitiesApplied information barriers mode to site
Information barrier activitiesChanged information barriers mode of site
Sensitivity label activitiesApplied sensitivity label to site
Sensitivity label activitiesChange sensitivity label applied to site
Sensitivity label activitiesRemoved sensitivity label from site
Sensitivity label activitiesApplied sensitivity label to file
Sensitivity label activitiesChanged sensitivity label applied to file
Sensitivity label activitiesRemoved sensitivity label from file
Microsoft Teams activitiesAdded channel
Microsoft Teams activitiesAdded members to team
Microsoft Teams activitiesChanged channel setting
Microsoft Teams activitiesChanged role of members
Microsoft Teams activitiesChanged Teams settings
Microsoft Teams activitiesCreated team
Microsoft Teams activitiesDeleted channel
Microsoft Teams activitiesDeleted team
Microsoft Teams activitiesRemoved members from team
Microsoft Teams activitiesAdded bot to team
Microsoft Teams activitiesAdded connector
Microsoft Teams activitiesAdded tab
Microsoft Teams activitiesChanged organization setting
Microsoft Teams activitiesRemoved bot from team
Microsoft Teams activitiesRemoved connector
Microsoft Teams activitiesRemoved tab
Microsoft Teams activitiesUpdated connector
Microsoft Teams activitiesUpdated tab
Microsoft Teams activitiesUser signed in to Teams
Microsoft Teams activitiesResponded to invitee response to shared channel
Microsoft Teams activitiesAdded details about Teams meeting
Microsoft Teams activitiesInstalled app
Microsoft Teams activitiesUninstalled app
Microsoft Teams activitiesAdded information about meeting participants
Microsoft Teams activitiesCreated a chat
Microsoft Teams activitiesDeleted all organization apps
Microsoft Teams activitiesDeleted app
Microsoft Teams activitiesEdited a message with a URL link in Teams
Microsoft Teams activitiesExported messages
Microsoft Teams activitiesExported recordings
Microsoft Teams activitiesExported transcripts
Microsoft Teams activitiesFailed to validate invitation to shared channel
Microsoft Teams activitiesFetched chat
Microsoft Teams activitiesFetched all hosted content of a message
Microsoft Teams activitiesPerformed action on card
Microsoft Teams activitiesPosted a new message
Microsoft Teams activitiesPublished app
Microsoft Teams activitiesRead a message
Microsoft Teams activitiesRead hosted content of a message
Microsoft Teams activitiesRemoved sharing of team channel
Microsoft Teams activitiesRestored sharing of team channel
Microsoft Teams activitiesResponded to invitation for shared channel
Microsoft Teams activitiesRetrieved messages
Microsoft Teams activitiesSent a message with a URL link in Teams
Microsoft Teams activitiesSent change notification for message creation
Microsoft Teams activitiesSent change notification for message deletion
Microsoft Teams activitiesSent change notification for message update
Microsoft Teams activitiesSent invitation for shared channel
Microsoft Teams activitiesSubscribed to message change notifications
Microsoft Teams activitiesUpdated application
Microsoft Teams activitiesUpdated a chat
Microsoft Teams activitiesUpdated a message
Microsoft Teams activitiesUpgraded app
Microsoft Teams activitiesDeleted a message
Microsoft Fabric activitiesCopied Power BI dashboard
Microsoft Fabric activitiesCreated Power BI dashboard
Microsoft Fabric activitiesDeleted Power BI dashboard
Microsoft Fabric activitiesRenamed Power BI dashboard
Microsoft Fabric activitiesShared Power BI dashboard
Microsoft Fabric activitiesViewed Power BI dashboard
Microsoft Fabric activitiesCreated Power BI semantic model
Microsoft Fabric activitiesShared Power BI semantic model
Microsoft Fabric activitiesCreated Power BI report
Microsoft Fabric activitiesDeleted Power BI report
Microsoft Fabric activitiesDownloaded Power BI report
Microsoft Fabric activitiesEdited Power BI report
Microsoft Fabric activitiesRenamed Power BI report
Microsoft Fabric activitiesShared Power BI report
Microsoft Fabric activitiesViewed Power BI report
Microsoft Fabric activitiesCreated Power BI dataflow
Microsoft Fabric activitiesDeleted Power BI dataflow
Microsoft Fabric activitiesUpdated Power BI dataflow
Microsoft Fabric activitiesPublished dataflow
Microsoft Fabric activitiesAdded admin personal workspace access
Microsoft Fabric activitiesRestored Power BI workspace
Microsoft Fabric activitiesChanged sensitivity label
Microsoft Fabric activitiesApplied sensitivity label to Power BI item
Microsoft Fabric activitiesDeleted sensitivity label from Power BI item
Microsoft Fabric activitiesCreated Power BI folder
Microsoft Fabric activitiesUpdated Power BI folder access
Microsoft Fabric activitiesDeleted Power BI folder
Microsoft Fabric activitiesUpdated Power BI folder
Microsoft Fabric activitiesDeleted Power BI folder access
Microsoft Fabric activitiesDeleted group workspace
Microsoft Fabric activitiesEdited Power BI dashboard
Microsoft Fabric activitiesPrinted Power BI dashboard
Microsoft Fabric activitiesDeleted Power BI semantic model
Microsoft Fabric activitiesEdited Power BI semantic model
Microsoft Fabric activitiesExported Power BI dataflow
Copilot activitiesInteracted with Copilot

Appendix I: Permission Difference Between Standard User and Visitor

Insights provides the management of two user roles in Insights, standard user and visitor. For details about how to edit user roles, refer to Manage Members.

Insights for Microsoft 365

The following table illustrates the permission difference between standard user and visitor in Insights for Microsoft 365.

√ – Supported; × – Unsupported.

Module - PageActionStandard userVisitor
DashboardExport××
Risk analysis - OverviewManage sensitivity label×
Risk analysis - OverviewTrust××
Risk analysis - OverviewRemove from trusted list××
Risk analysis - OverviewRescan×
Risk analysis - OverviewSave×
Risk analysis - OverviewSave as new view×
Risk analysis - Overviewset as default view×
Risk analysis - OverviewDelete view×
Risk analysis - OverviewSet as favorite×
Risk analysis - OverviewRemove from favorites×
Risk analysis - OverviewAdd channel owner×
Risk analysis - OverviewAdd channel member×
Risk analysis - OverviewAdd owner×
Risk analysis - OverviewAdd member×
Risk analysis - OverviewRemove owner×
Risk analysis - OverviewRemove member×
Risk analysis - OverviewDemote owner to member×
Risk analysis - OverviewPromote member to owner×
Risk analysis - OverviewAdd comment×
Risk analysis - OverviewDelete comment××
Risk analysis - OverviewRemove access×
Risk analysis - OverviewRemove
(Remove shared permission of user or group for shared link)
×
Risk analysis - OverviewRevert××
Risk analysis - OverviewRemove permissions×
Risk analysis - OverviewEdit permissions×
Risk analysis - OverviewRemove
(Remove group from SharePoint group list)
×
Risk analysis - OverviewRemove
(Remove user or group from All people list)
×
Risk analysis - OverviewRemove
(Remove user from the Site collection administrators group)
×
Risk analysis - OverviewAdd user
(Add user to the Site collection administrators group)
×
Risk analysis - OverviewRemove users/groups
(Remove shadow users/groups from Team or Microsoft 365 Group)
×
Risk analysis – Overview > Details > Copilot readinessRemove access
(Remove access to sensitive items from Everyone, Everyone except external users, All Users (membership), and All Users (windows) groups)
×
Risk analysis – Overview > Details > Copilot readinessRemove access
(Remove access to sensitive items via links)
×
Risk analysis - Detailed records
Notify×
Risk analysis - Detailed records
Add tag×
Risk analysis - Detailed records
Break inheritance×
Risk analysis - Detailed records
Inherit permissions×
Exposure - Sharing links
Set expiration data×
Exposure - Sharing links
Remove
(Remove shared permission from specific link)
×
Exposure - Sharing links
Remove access×
Exposure - Sharing links
Notify×
Activity - Full scan detailsPrioritize in scan×
Activity – Job Monitor > Download centerDownload×
Activity – Job Monitor > Download centerTerminate×

Insights for Google

The following table illustrates the permission difference between standard user and visitor in Insights for Google.

√ – Supported; × – Unsupported.

Module - PageActionStandard userVisitor
Risk analysis – OverviewExport×
Risk analysis – OverviewTrust××
Risk analysis – OverviewRescan×
Risk analysis – OverviewRemove from trusted list××
Risk analysis – OverviewManage members×
Risk analysis – Overview > Gemini readinessRemove access×
Risk analysis – Overview > View shared linksRemove access×
Risk analysis – Overview > View shared linksEdit permission×
Risk analysis – Detailed recordsExport×
Risk analysis – Detailed recordsAdd tag×
Risk analysis – Detailed recordsManage label×
Risk analysis – Detailed recordsUnshare×
Risk analysis – Detailed recordsEdit permission×
Risk analysis – Detailed recordsRemove permissions×
Risk analysis – Detailed recordsSet expiration time×
Exposure – Sharing linksRemove access×
Exposure – Sharing linksEdit permission×
Activity – Full scan detailsPrioritize in scan×
Activity – Job monitor > Download centerDownload×
Activity – Job monitor > Download centerTerminate×