The OneDrive list
The list is built from Microsoft's seven-day OneDrive usage report. That is one read for the whole tenant rather than one request per user, so it remains practical in a large tenant. Each row shows the owner, site address, used and allocated storage, quota state, file count and last activity date. Search matches the owner, username and site address; the quota-state filter can narrow the list to drives that are healthy, nearing their limit, full or unknown.
Usage reports are not live. Microsoft can take up to 48 hours to refresh them, so the status line shows Report data from 2026-08-26 rather than pretending the figures were produced when you pressed Refresh. CloudSergeant normally keeps that report for 12 hours; Refresh asks Microsoft for it again immediately.
Microsoft 365 can conceal user, group and site names in every usage report. When that tenant setting is on, OneDrive owners and addresses are opaque hashes. CloudSergeant checks the setting first and does not fetch or display the report as if those hashes were real data.
A Global Administrator can choose Show names in reports on the page. The app confirms first because this changes a tenant-wide Microsoft 365 privacy setting, not a CloudSergeant preference. Microsoft rebuilds the report daily, so the list may remain empty until the next day even after the setting is changed.
Opening a OneDrive
Choose Edit on the OneDrive list, or use Edit OneDrive on a user's card. The latter can open an existing drive directly in your own tenant even when the usage report is unavailable. In a delegated customer tenant, the report list is the only way into the card because Microsoft's per-user drive endpoint does not accept the partner identity.
An account having no OneDrive is ordinary: it is provisioned only after a licensed user first signs in to OneDrive or SharePoint. The Storage section explains that state instead of reporting a permission failure or creating a drive merely by looking for it.
The list can show report-based storage even when Microsoft omitted the site's address from that report. The card needs the address before it can read or change live SharePoint settings. In a customer tenant CloudSergeant derives Microsoft's normal personal-site address and accepts it only after SharePoint confirms that the returned owner matches the selected user.
Microsoft can append a number or GUID when a OneDrive address conflicts with an older site. If the report also omits that exceptional address, CloudSergeant will not guess: the card explains the limitation and waits for Microsoft's daily report to provide the authoritative URL.
Storage
Storage shows used, allocated and remaining space, recycle-bin size, quota state, file count and activity dates where Microsoft makes them available. You can change the storage quota and warning level in GB; the warning level must be lower than the quota. If one source omits a figure, the card falls back from the Graph drive to the usage report and then to SharePoint. Unknown remains unknown — it is never displayed as zero.
Sharing
The Sharing section controls the OneDrive site's:
- external sharing level, from organisation-only through anonymous links;
- default sharing-link type and whether that link grants view or edit access; and
- optional allow-list or block-list of external domains.
A OneDrive cannot be more permissive than the tenant's SharePoint sharing policy. SharePoint applies these changes asynchronously; when a save has been accepted but is not visible yet, CloudSergeant says so and offers a refresh instead of submitting the write again.
Access
There are two deliberately different ways to let another person reach a OneDrive:
- Site collection administrator
- Full control of the whole OneDrive that survives the owner being deleted. This is the durable handover for offboarding. You can add or remove administrators immediately.
Administrator changes take effect immediately; the card's Save button has nothing else to write in this section. The OneDrive owner is never offered as an additional administrator and cannot be removed from the administrator list. Ordinary file and folder sharing stays in Microsoft's OneDrive UI, where the owner can manage both grants and sharing links.
Lock state
Set a OneDrive to normal access, read-only, or no access. Read-only preserves a leaver's files while a handover is arranged; no access prevents anybody, including the owner, from opening it. CloudSergeant confirms either restriction and explains its effect before applying it. The same section controls whether unmanaged devices get full, browser-only or blocked access.
A recycled OneDrive site can still be inspected where Microsoft returns it, but its settings are read-only.
Permissions and roles
| Permission | Used for | Microsoft role |
|---|---|---|
Files.ReadWrite.All |
Reading an existing drive, the OneDrive file tools, and handing a leaver's files to someone else during offboarding. It includes the read, so there is no separate Files.Read.All. |
SharePoint Administrator for the administrative operations |
Reports.Read.All |
The whole-tenant OneDrive usage report | Reports Reader, SharePoint Administrator or Global Reader |
ReportSettings.ReadWrite.All |
Checking whether report names are concealed and, after confirmation, showing them | A report-reading role for the check; Global Administrator for the change |
SharePoint AllSites.FullControl |
Quota, sharing, lock state, unmanaged-device access and site collection administrators | SharePoint Administrator |
The three Graph permissions are baseline delegated permissions requested at sign-in.
Files.ReadWrite.All is not an optional or on-demand permission.
AllSites.FullControl belongs to Office 365 SharePoint Online, a different Microsoft
API, so it is acquired separately in the same way Exchange permissions are.
AllSites.FullControl is included.
Adding or reapproving Graph Files.ReadWrite.All does not grant access to quota,
sharing or lock settings.
What works through GDAP
A partner identity can reach SharePoint's tenant-admin plane but not the customer's OneDrive file plane. CloudSergeant gates the individual capabilities rather than disabling the page.
| Capability in a customer tenant | Available |
|---|---|
| List OneDrives from the usage report | Yes |
| Read and change quota, sharing and lock settings | Yes, through SharePointRequires AllSites.FullControl, SharePoint Administrator and a report URL or owner-verified standard URL |
| Add a site collection administrator | Yes, through SharePointThe existing administrator list remains unavailable |
| Read recycle-bin size, drive dates and the Graph drive URL | No |
| List or remove existing site collection administrators | No |
| Copy / Move, Export / Import, or filtered Cleanup | Separate sign-in onlyUse an account in the customer tenant that can already open the drive |
| Read or empty the recycle bin | NoHome tenant and primary sign-in only |
Adding an administrator still works because it is a tenant-level SharePoint operation. The card cannot read the existing administrator list afterwards, so it points you to the customer's SharePoint admin center for verification. The delete-user wizard's OneDrive handover uses the unavailable Graph file action and therefore remains disabled in a customer tenant; add a site collection administrator from the OneDrive card instead.