TSO — end-to-end user guide
Everything from your first sign-in to reading a recommendations report and handing a client-ready PDF to your CFO. Twenty sections, one long read.
What TSO is
TSO — Tenant Storage Optimizer — is a read-only audit tool for Microsoft 365 storage. It scans your SharePoint sites, OneDrive accounts, Teams-backed locations and Exchange mailboxes and tells you exactly how much space is wasted, where it lives, and how to reclaim it.
TSO never deletes, moves or edits anything in your tenant. Every finding is a recommendation for your admin to act on, at their pace, in their own admin center.
Three common ways to use it: as an audit (one scan, one PDF, one meeting with finance); as a recurring monitor (weekly scans showing reclaim progress over time); or as a service line for MSPs (one workspace per client, branded reports).
Signing in
TSO uses Microsoft SSO. There is no separate password.
- Go to tso.azurewebsites.net and click Log in or Start free.
- Choose Sign in with Microsoft. Pick the account you use for your work Microsoft 365 tenant.
- On first sign-in TSO auto-creates a workspace for your organisation. You are its Owner.
- Subsequent sign-ins drop you straight into the last workspace you used.
Connecting a Microsoft 365 tenant
TSO reads your tenant through Microsoft Graph. A Global Admin grants the app read-only access once; the connection is then reusable across scans.
Who can do this
Only a Microsoft 365 Global Admin can grant tenant-wide (application) permissions. If that's not you, forward the connect link to whoever is.
What TSO asks for
- Sites.Read.All
- Enumerate SharePoint sites, libraries and file metadata (never file contents).
- Files.Read.All
- Read OneDrive + SharePoint file metadata for size, dates and version counts.
- User.Read.All
- Resolve owners and detect departed-user OneDrives.
- Group.Read.All
- Discover Microsoft 365 groups + Teams-backed SharePoint sites.
- Reports.Read.All
- Read the built-in M365 usage reports for storage and activity.
- Directory.Read.All
- Read tenant baseline + license posture.
Every scope is read-only. TSO never requests write scopes.
Consent flow
- In the portal, open Tenants and click Connect Microsoft 365.
- Review the permission list, then click Continue to Microsoft. You're redirected to Microsoft's own consent screen at
login.microsoftonline.com. - Pick the admin account, then click Accept. Microsoft records the grant against the TSO app registration in your tenant.
- Microsoft redirects you back to TSO. The tenant appears in Tenants, ready to scan.
Running your first scan
A scan is an inventory pass across your connected tenant. It runs asynchronously — you can close the tab and come back.
Scan kinds
- Standard
- Default. Every workload; full site enumeration; recommendations engine at the end. ~20–90 min.
- Quick
- Sizing sketch only — enough to populate the overview + top-line reclaim number. ~10–30 min.
- Deep
- Standard plus deeper library-level walks. Longer, more thorough. Use quarterly.
- Custom
- You pick the workloads. Useful if OneDrive is fine and only SharePoint matters.
Kick it off
- Open Tenants and click your tenant.
- Click Start scan and pick a kind (Standard for the first run).
- TSO queues the job and drops you on the scan detail page. Progress ticks up in real time.
Every scan gets an ID (e.g. 1082143a-05ba-…) that appears under the tenant name and in the URL. Bookmark it if you want to send someone straight to the result.
Reading progress
The scan detail page shows a progress bar, current stage, and per-workload tiles. The Activity button opens a live log stream. Nothing here needs to stay open; you'll get a toast when the scan finishes.
discover_workloads → SharePoint / OneDrive / Exchange / Teams crawls → score_recommendations → finalize. Failed stages don't stop the others; you'll see a partial status if some data is missing.The scan overview
The Overview tab is the elevator pitch: total storage, headline recommendations, and the storage-overage card that translates it into a monthly cost.
Top row — the four tiles
- Total storage — sum across every workload after subsite dedupe.
- Items scanned — total sites, accounts and mailboxes inventoried.
- Recommendations — number of ranked actions the engine surfaced.
- Errors — anything that couldn't be read (permission, throttling). Click through for details.
Workload tiles
Under the headline row, one tile per workload (SharePoint, OneDrive, Exchange, Teams files). Each shows storage used, item count and percentage of the tenant total. Click a tile to jump to that workload's tab.
Storage-overage card
Microsoft grants you 1 TB + 10 GB × licensed users as an included SharePoint pool. TSO computes what you're currently using across SharePoint + Teams-backed sites and shows the excess at Microsoft's standard list rate for additional storage — $0.20 / GB / month — plus an annualised figure so you can see exactly which slice of the tenancy is worth reclaiming.
OneDrive accounts
One row per user's OneDrive. Departed users, disabled accounts and dormant drives are called out visually.
- Rows for disabled or deleted users are shaded pale red — usually the fastest reclaim target on the list.
- The Last activity column comes from the OneDrive Usage Report (180-day window).
- Excel export renders storage in GB and marks the inactive rows pale red.
Exchange mailboxes
Mailbox sizes and last-activity dates from the Exchange Usage Report.
Useful for spotting oversized shared mailboxes that nobody's touched in years and disabled-user mailboxes still consuming licenses. Export renders sizes in GB.
Teams-backed locations
Every Microsoft Team backs itself with a SharePoint site. This tab shows that mapping.
Click the team name to open the underlying SharePoint site's detail page — you can then run duplicate detection and version scans on that site directly.
Users & quota calculator
The Users tab lists every licensed user and shows the tenant's included SharePoint quota alongside how much of it is actually being consumed.
At the top: a summary card with 1 TB + 10 GB × N included, and the excess your tenant would be billed for. Same math as the Overview's storage-overage card, presented per-user so you can see who has an oversized OneDrive.
Duplicate detection
Find copies of the exact same file across a tenant — same content hash, different locations — and see how many gigabytes you'd reclaim if you kept only the newest.
The Duplicates tab
Two inner tabs: Sites shows a per-site row per sweep with the number of items, status, duration and date scanned; Duplicate Files shows the merged file-level view across every sweep, sorted by reclaimable bytes descending.
Running a sweep
- Open the SharePoint tab.
- Tick one or more sites (up to the per-sweep cap shown in the toolbar).
- Click Detect duplicates. TSO queues an async sweep and drops you on the Duplicates tab.
- Refresh occasionally, or wait for the toast that says the sweep completed.
Sweeps are resumable. If a sweep hits its per-site budget it finishes with a partial status and shows a Resume button. You can also Add sites to an existing sweep so cross-site duplicates group correctly.
Group details
Every duplicate group shows the file size, number of copies, total bytes across copies, and every location. Sorted by reclaimable size by default.
Largest files
Walks every drive and keeps the top-N files above a chosen size threshold.
On the Largest Files tab, pick a minimum size (10 MB → 50 GB) and a top-N (up to 500). Choose SharePoint, OneDrive, or both. Click Find largest files and the run queues.
Results table
- File name and extension, size in GB, and — for each of the top-N winners — a version count fetched post-scan.
- Workload, location, library, created and modified timestamps.
- An open icon that jumps directly to the file in SharePoint.
File versions
Which files are hoarding versions? Estimated reclaim if the older versions were pruned.
Available on the site detail page. Pick a minimum-versions threshold (5, 10, 20, 50, 100) and a top-N. The worker walks the site's drives and calls Graph's /versions endpoint per candidate file, returning the top-N by reclaimable bytes.
Columns
- Size — current-version size.
- Versions — total number of stored versions.
- All versions total — sum of every version's stored size (from Graph when available, else approximated).
- Reclaimable —
(versions − 1) × size, the naive upper bound of what pruning older versions would free.
A totals row at the bottom of the table sums the size, versions, all-versions total and reclaimable across the currently displayed rows.
Site detail page
Click any SharePoint site title (or a Teams-backed site name) to open a per-site view with three inner tabs and a one-click duplicate detector.
Header
Four stat cards: storage used, library count, total files (with active files under it), last activity date.
Overview tab
- Detect duplicates — queues a single-site duplicate sweep, sends you to the Duplicates tab of the scan.
- Search largest files — jumps to the Largest Files inner tab, pre-scoped to this site.
- Search file versions — jumps to the File Versions inner tab.
Largest Files & File Versions tabs
Behave identically to the tenant-wide equivalents but scoped to this site's drives. Both include a totals row and CSV/XLSX exports.
Recommendations
The scoring engine ranks archive, delete and review candidates by confidence and reclaim size.
Inactive-insights cards
- Disabled OneDrive — potential saving across all disabled-user OneDrive accounts.
- Inactive OneDrive — 1 year+, 3 years+, 5 years+ buckets.
- Inactive SharePoint sites — same three buckets.
- Inactive Teams sites — same three buckets.
Recommendations table
Dedicated columns for No Owner, No Activity, Last Activity Since, workload, path and reclaim-in-GB. Sort or filter by any column. The PDF and Excel reports carry the same insights.
No-Owners & Errors
Two utility tabs for governance and diagnostics.
No Owners lists every site and OneDrive account with no responsible owner in the directory.
Errors lists any per-item failures the crawl encountered — permission denials on individual sites, transient Graph throttling, folders that returned malformed responses.
PDF & Excel exports
Every scan produces a client-ready PDF and a full Excel workbook. Both are available from the top-right of the scan detail page.
PDF report
- Executive summary with total reclaim + monthly cost saving.
- Storage overage vs. included quota, with the calculation shown.
- Recommendations cards — Disabled OneDrive, Inactive OneDrive (1/3/5 years), Inactive SharePoint (1/3/5 years), Inactive Teams (1/3/5 years).
- Per-workload breakdown.
- Top-ten ranked actions with reclaim in GB.
MSPs on the appropriate plan can white-label the PDF with their own logo and primary colour under Settings → Branding.
Excel workbook
One sheet per workload plus a Summary sheet:
- SharePoint — sites, storage in GB, file counts, last activity.
- OneDrive — accounts in GB, inactive rows shaded pale red.
- Exchange — mailboxes in GB.
- Teams — teams-backed locations with linked site + file count.
- Duplicates / Largest / Versions — the equivalent tab data with totals rows.
- Recommendations — ranked, with No Owner / No Activity / Last Activity Since columns.
Settings, billing, MFA
Profile
Your display name and email come from Microsoft SSO and can't be edited in TSO. To rotate MFA (if you're a platform admin), open Profile → Security and re-enrol.
Members
Workspace Owners can invite additional members from Settings → Members. Roles: owner, admin, analyst, viewer. Only owners can invite new owners and manage billing.
Billing
- Microsoft commercial marketplace — if you subscribed via Azure Marketplace, your billing is handled by Microsoft. Change plan there.
- Stripe (direct) — for customers billed by LogiSam. Card management lives in the Stripe customer portal, linked from the Billing page.
MFA
Regular workspace users rely on their own tenant's MFA. Platform admins can enable TOTP MFA on their account and get a trusted-device cookie so they don't have to re-enter the code every visit from the same browser.
Admin console (platform admins)
A separate area at /admin for LogiSam staff. Red gradient strip at the top of every page.
Only visible to accounts flagged isPlatformAdmin. When enabled, the portal shows an Admin console button in the top-right — click to switch. Same SSO session is used; no separate password.
Sections
- Health / Diagnostics / Audit — worker health, queue depth, event log.
- Organisations — every workspace, with impersonate, suspend and delete actions.
- Users — platform-wide user directory.
- Demo requests — inbound requests from the marketing site.
- Billing / Payments / Plans / Stripe — subscription management, Stripe credentials, plan definitions.
- Email / SMTP / Templates — outbound email settings and per-template editor.
- Feature flags — kill switches for individual product surfaces.
Troubleshooting
Scan is stuck at 0%
Usually means the worker container is wedged on a hung Graph call from a previous job. Email support with the scan ID; the fix is a worker restart.
SharePoint total looks massively inflated
Older scans occasionally showed subsites double-counting their parent site collection's storage. The current version of TSO dedupes by site-collection GUID during the crawl. If you're looking at a pre-fix scan and want it corrected without re-scanning, contact support.
"Insufficient privileges" after consent
Your Global Admin clicked Accept, but Microsoft withheld one of the requested permissions. Retry consent; if it still fails, ask your Microsoft partner or Entra admin whether tenant policy is blocking application-permission grants for third-party apps.
PDF or Excel download fails
Refresh the scan page and try again — exports are generated on demand, and a first click after a long idle occasionally times out.
Contact support
Include the scan ID (from the URL) and a screenshot. Email hello@logisam.com or open the contact form.
