OneDrives

Every OneDrive in the active tenant, followed by one card for storage, sharing, access and lock settings. Microsoft Graph supplies the drive and usage report; SharePoint supplies the settings an administrator can change.

Looking for file Cleanup, Copy / Move or Export / Import? See OneDrive tools.

The OneDrive list

The list is built from Microsoft's seven-day OneDrive usage report. That is one read for the whole tenant rather than one request per user, so it remains practical in a large tenant. Each row shows the owner, site address, used and allocated storage, quota state, file count and last activity date. Search matches the owner, username and site address; the quota-state filter can narrow the list to drives that are healthy, nearing their limit, full or unknown.

Usage reports are not live. Microsoft can take up to 48 hours to refresh them, so the status line shows Report data from 2026-08-26 rather than pretending the figures were produced when you pressed Refresh. CloudSergeant normally keeps that report for 12 hours; Refresh asks Microsoft for it again immediately.

Hidden report names stop the list before it starts

Microsoft 365 can conceal user, group and site names in every usage report. When that tenant setting is on, OneDrive owners and addresses are opaque hashes. CloudSergeant checks the setting first and does not fetch or display the report as if those hashes were real data.

A Global Administrator can choose Show names in reports on the page. The app confirms first because this changes a tenant-wide Microsoft 365 privacy setting, not a CloudSergeant preference. Microsoft rebuilds the report daily, so the list may remain empty until the next day even after the setting is changed.

Opening a OneDrive

Choose Edit on the OneDrive list, or use Edit OneDrive on a user's card. The latter can open an existing drive directly in your own tenant even when the usage report is unavailable. In a delegated customer tenant, the report list is the only way into the card because Microsoft's per-user drive endpoint does not accept the partner identity.

An account having no OneDrive is ordinary: it is provisioned only after a licensed user first signs in to OneDrive or SharePoint. The Storage section explains that state instead of reporting a permission failure or creating a drive merely by looking for it.

The list and the live card use different data

The list can show report-based storage even when Microsoft omitted the site's address from that report. The card needs the address before it can read or change live SharePoint settings. In a customer tenant CloudSergeant derives Microsoft's normal personal-site address and accepts it only after SharePoint confirms that the returned owner matches the selected user.

Microsoft can append a number or GUID when a OneDrive address conflicts with an older site. If the report also omits that exceptional address, CloudSergeant will not guess: the card explains the limitation and waits for Microsoft's daily report to provide the authoritative URL.

Storage

Storage shows used, allocated and remaining space, recycle-bin size, quota state, file count and activity dates where Microsoft makes them available. You can change the storage quota and warning level in GB; the warning level must be lower than the quota. If one source omits a figure, the card falls back from the Graph drive to the usage report and then to SharePoint. Unknown remains unknown — it is never displayed as zero.

Sharing

The Sharing section controls the OneDrive site's:

  • external sharing level, from organisation-only through anonymous links;
  • default sharing-link type and whether that link grants view or edit access; and
  • optional allow-list or block-list of external domains.

A OneDrive cannot be more permissive than the tenant's SharePoint sharing policy. SharePoint applies these changes asynchronously; when a save has been accepted but is not visible yet, CloudSergeant says so and offers a refresh instead of submitting the write again.

Access

There are two deliberately different ways to let another person reach a OneDrive:

Site collection administrator
Full control of the whole OneDrive that survives the owner being deleted. This is the durable handover for offboarding. You can add or remove administrators immediately.

Administrator changes take effect immediately; the card's Save button has nothing else to write in this section. The OneDrive owner is never offered as an additional administrator and cannot be removed from the administrator list. Ordinary file and folder sharing stays in Microsoft's OneDrive UI, where the owner can manage both grants and sharing links.

Lock state

Set a OneDrive to normal access, read-only, or no access. Read-only preserves a leaver's files while a handover is arranged; no access prevents anybody, including the owner, from opening it. CloudSergeant confirms either restriction and explains its effect before applying it. The same section controls whether unmanaged devices get full, browser-only or blocked access.

A recycled OneDrive site can still be inspected where Microsoft returns it, but its settings are read-only.

Permissions and roles

PermissionUsed forMicrosoft role
Files.ReadWrite.All Reading an existing drive, the OneDrive file tools, and handing a leaver's files to someone else during offboarding. It includes the read, so there is no separate Files.Read.All. SharePoint Administrator for the administrative operations
Reports.Read.All The whole-tenant OneDrive usage report Reports Reader, SharePoint Administrator or Global Reader
ReportSettings.ReadWrite.All Checking whether report names are concealed and, after confirmation, showing them A report-reading role for the check; Global Administrator for the change
SharePoint AllSites.FullControl Quota, sharing, lock state, unmanaged-device access and site collection administrators SharePoint Administrator

The three Graph permissions are baseline delegated permissions requested at sign-in. Files.ReadWrite.All is not an optional or on-demand permission. AllSites.FullControl belongs to Office 365 SharePoint Online, a different Microsoft API, so it is acquired separately in the same way Exchange permissions are.

If information loads but changes fail: the tenant may still have an older, read-only SharePoint grant. Reapprove CloudSergeant with a Global Administrator and confirm that the Office 365 SharePoint Online delegated permission AllSites.FullControl is included. Adding or reapproving Graph Files.ReadWrite.All does not grant access to quota, sharing or lock settings.

What works through GDAP

A partner identity can reach SharePoint's tenant-admin plane but not the customer's OneDrive file plane. CloudSergeant gates the individual capabilities rather than disabling the page.

Capability in a customer tenantAvailable
List OneDrives from the usage reportYes
Read and change quota, sharing and lock settingsYes, through SharePointRequires AllSites.FullControl, SharePoint Administrator and a report URL or owner-verified standard URL
Add a site collection administratorYes, through SharePointThe existing administrator list remains unavailable
Read recycle-bin size, drive dates and the Graph drive URLNo
List or remove existing site collection administratorsNo
Copy / Move, Export / Import, or filtered CleanupSeparate sign-in onlyUse an account in the customer tenant that can already open the drive
Read or empty the recycle binNoHome tenant and primary sign-in only

Adding an administrator still works because it is a tenant-level SharePoint operation. The card cannot read the existing administrator list afterwards, so it points you to the customer's SharePoint admin center for verification. The delete-user wizard's OneDrive handover uses the unavailable Graph file action and therefore remains disabled in a customer tenant; add a site collection administrator from the OneDrive card instead.