User manual · v2026.09

TSO — end-to-end user guide

Everything from your first sign-in to reading a recommendations report and handing a client-ready PDF to your CFO. Twenty sections, one long read.

§ 01

What TSO is

TSO — Tenant Storage Optimizer — is a read-only audit tool for Microsoft 365 storage. It scans your SharePoint sites, OneDrive accounts, Teams-backed locations and Exchange mailboxes and tells you exactly how much space is wasted, where it lives, and how to reclaim it.

TSO never deletes, moves or edits anything in your tenant. Every finding is a recommendation for your admin to act on, at their pace, in their own admin center.

Three common ways to use it: as an audit (one scan, one PDF, one meeting with finance); as a recurring monitor (weekly scans showing reclaim progress over time); or as a service line for MSPs (one workspace per client, branded reports).

§ 02

Signing in

TSO uses Microsoft SSO. There is no separate password.

  1. Go to tso.azurewebsites.net and click Log in or Start free.
  2. Choose Sign in with Microsoft. Pick the account you use for your work Microsoft 365 tenant.
  3. On first sign-in TSO auto-creates a workspace for your organisation. You are its Owner.
  4. Subsequent sign-ins drop you straight into the last workspace you used.
To try TSO against a pre-populated demo tenant without connecting your own, click Try the demo on the sign-in page. Read-only, shared.
§ 03

Connecting a Microsoft 365 tenant

TSO reads your tenant through Microsoft Graph. A Global Admin grants the app read-only access once; the connection is then reusable across scans.

Who can do this

Only a Microsoft 365 Global Admin can grant tenant-wide (application) permissions. If that's not you, forward the connect link to whoever is.

What TSO asks for

Sites.Read.All
Enumerate SharePoint sites, libraries and file metadata (never file contents).
Files.Read.All
Read OneDrive + SharePoint file metadata for size, dates and version counts.
User.Read.All
Resolve owners and detect departed-user OneDrives.
Group.Read.All
Discover Microsoft 365 groups + Teams-backed SharePoint sites.
Reports.Read.All
Read the built-in M365 usage reports for storage and activity.
Directory.Read.All
Read tenant baseline + license posture.

Every scope is read-only. TSO never requests write scopes.

Consent flow

  1. In the portal, open Tenants and click Connect Microsoft 365.
  2. Review the permission list, then click Continue to Microsoft. You're redirected to Microsoft's own consent screen at login.microsoftonline.com.
  3. Pick the admin account, then click Accept. Microsoft records the grant against the TSO app registration in your tenant.
  4. Microsoft redirects you back to TSO. The tenant appears in Tenants, ready to scan.
If the callback bounces back to the connect page with a red banner, the message names the reason (denied, link expired, or Graph refused a probe call). If it says Graph refused, forward the technical detail to hello@logisam.com.
§ 04

Running your first scan

A scan is an inventory pass across your connected tenant. It runs asynchronously — you can close the tab and come back.

Scan kinds

Standard
Default. Every workload; full site enumeration; recommendations engine at the end. ~20–90 min.
Quick
Sizing sketch only — enough to populate the overview + top-line reclaim number. ~10–30 min.
Deep
Standard plus deeper library-level walks. Longer, more thorough. Use quarterly.
Custom
You pick the workloads. Useful if OneDrive is fine and only SharePoint matters.

Kick it off

  1. Open Tenants and click your tenant.
  2. Click Start scan and pick a kind (Standard for the first run).
  3. TSO queues the job and drops you on the scan detail page. Progress ticks up in real time.

Every scan gets an ID (e.g. 1082143a-05ba-…) that appears under the tenant name and in the URL. Bookmark it if you want to send someone straight to the result.

Reading progress

The scan detail page shows a progress bar, current stage, and per-workload tiles. The Activity button opens a live log stream. Nothing here needs to stay open; you'll get a toast when the scan finishes.

Stages run mostly in parallel: discover_workloads → SharePoint / OneDrive / Exchange / Teams crawls → score_recommendationsfinalize. Failed stages don't stop the others; you'll see a partial status if some data is missing.
§ 05

The scan overview

The Overview tab is the elevator pitch: total storage, headline recommendations, and the storage-overage card that translates it into a monthly cost.

Top row — the four tiles

  • Total storage — sum across every workload after subsite dedupe.
  • Items scanned — total sites, accounts and mailboxes inventoried.
  • Recommendations — number of ranked actions the engine surfaced.
  • Errors — anything that couldn't be read (permission, throttling). Click through for details.

Workload tiles

Under the headline row, one tile per workload (SharePoint, OneDrive, Exchange, Teams files). Each shows storage used, item count and percentage of the tenant total. Click a tile to jump to that workload's tab.

Storage-overage card

Microsoft grants you 1 TB + 10 GB × licensed users as an included SharePoint pool. TSO computes what you're currently using across SharePoint + Teams-backed sites and shows the excess at Microsoft's standard list rate for additional storage — $0.20 / GB / month — plus an annualised figure so you can see exactly which slice of the tenancy is worth reclaiming.

OneDrive is billed per-user and doesn't share the SharePoint pool, so it's excluded from the overage math on purpose.
§ 06

SharePoint sites

One row per SharePoint site collection Graph enumerates. Sort by any column, filter with the search box, export the visible rows to CSV.

Columns

  • Site — display name + URL. Click the name to open the site detail page.
  • Storage — used bytes from Microsoft's Reports API, with a drive-quota fallback for tenants that anonymise reports.
  • Libraries — document library count.
  • Files — total files stored on the site.
  • Teamsyes when the site is Teams-backed, otherwise a dash.
  • Created / Last activity / Site edited — creation date, last-user-activity (Reports API 180-day window), and Graph metadata timestamp respectively.

Bulk actions

Tick the checkbox on one or more sites, then click Detect duplicates in the toolbar. Queues a multi-site duplicate sweep and jumps you to the Duplicates tab.

§ 07

OneDrive accounts

One row per user's OneDrive. Departed users, disabled accounts and dormant drives are called out visually.

  • Rows for disabled or deleted users are shaded pale red — usually the fastest reclaim target on the list.
  • The Last activity column comes from the OneDrive Usage Report (180-day window).
  • Excel export renders storage in GB and marks the inactive rows pale red.
§ 08

Exchange mailboxes

Mailbox sizes and last-activity dates from the Exchange Usage Report.

Useful for spotting oversized shared mailboxes that nobody's touched in years and disabled-user mailboxes still consuming licenses. Export renders sizes in GB.

§ 09

Teams-backed locations

Every Microsoft Team backs itself with a SharePoint site. This tab shows that mapping.

Click the team name to open the underlying SharePoint site's detail page — you can then run duplicate detection and version scans on that site directly.

§ 10

Users & quota calculator

The Users tab lists every licensed user and shows the tenant's included SharePoint quota alongside how much of it is actually being consumed.

At the top: a summary card with 1 TB + 10 GB × N included, and the excess your tenant would be billed for. Same math as the Overview's storage-overage card, presented per-user so you can see who has an oversized OneDrive.

§ 11

Duplicate detection

Find copies of the exact same file across a tenant — same content hash, different locations — and see how many gigabytes you'd reclaim if you kept only the newest.

The Duplicates tab

Two inner tabs: Sites shows a per-site row per sweep with the number of items, status, duration and date scanned; Duplicate Files shows the merged file-level view across every sweep, sorted by reclaimable bytes descending.

Running a sweep

  1. Open the SharePoint tab.
  2. Tick one or more sites (up to the per-sweep cap shown in the toolbar).
  3. Click Detect duplicates. TSO queues an async sweep and drops you on the Duplicates tab.
  4. Refresh occasionally, or wait for the toast that says the sweep completed.

Sweeps are resumable. If a sweep hits its per-site budget it finishes with a partial status and shows a Resume button. You can also Add sites to an existing sweep so cross-site duplicates group correctly.

Group details

Every duplicate group shows the file size, number of copies, total bytes across copies, and every location. Sorted by reclaimable size by default.

§ 12

Largest files

Walks every drive and keeps the top-N files above a chosen size threshold.

On the Largest Files tab, pick a minimum size (10 MB → 50 GB) and a top-N (up to 500). Choose SharePoint, OneDrive, or both. Click Find largest files and the run queues.

Results table

  • File name and extension, size in GB, and — for each of the top-N winners — a version count fetched post-scan.
  • Workload, location, library, created and modified timestamps.
  • An open icon that jumps directly to the file in SharePoint.
Version numbers ≥ 20 render amber; 5–19 render blue; below 5 stay muted. Hover a version count to see the approximate reclaim if older versions were pruned.
§ 13

File versions

Which files are hoarding versions? Estimated reclaim if the older versions were pruned.

Available on the site detail page. Pick a minimum-versions threshold (5, 10, 20, 50, 100) and a top-N. The worker walks the site's drives and calls Graph's /versions endpoint per candidate file, returning the top-N by reclaimable bytes.

Columns

  • Size — current-version size.
  • Versions — total number of stored versions.
  • All versions total — sum of every version's stored size (from Graph when available, else approximated).
  • Reclaimable(versions − 1) × size, the naive upper bound of what pruning older versions would free.
Reclaimable is an upper bound. SharePoint uses shredded storage — successive edits often share chunks with the current version, so the actual on-disk saving from pruning older versions is usually closer to All versions total − current size.

A totals row at the bottom of the table sums the size, versions, all-versions total and reclaimable across the currently displayed rows.

§ 14

Site detail page

Click any SharePoint site title (or a Teams-backed site name) to open a per-site view with three inner tabs and a one-click duplicate detector.

Header

Four stat cards: storage used, library count, total files (with active files under it), last activity date.

Overview tab

  • Detect duplicates — queues a single-site duplicate sweep, sends you to the Duplicates tab of the scan.
  • Search largest files — jumps to the Largest Files inner tab, pre-scoped to this site.
  • Search file versions — jumps to the File Versions inner tab.

Largest Files & File Versions tabs

Behave identically to the tenant-wide equivalents but scoped to this site's drives. Both include a totals row and CSV/XLSX exports.

§ 15

Recommendations

The scoring engine ranks archive, delete and review candidates by confidence and reclaim size.

Inactive-insights cards

  • Disabled OneDrive — potential saving across all disabled-user OneDrive accounts.
  • Inactive OneDrive — 1 year+, 3 years+, 5 years+ buckets.
  • Inactive SharePoint sites — same three buckets.
  • Inactive Teams sites — same three buckets.

Recommendations table

Dedicated columns for No Owner, No Activity, Last Activity Since, workload, path and reclaim-in-GB. Sort or filter by any column. The PDF and Excel reports carry the same insights.

§ 16

No-Owners & Errors

Two utility tabs for governance and diagnostics.

No Owners lists every site and OneDrive account with no responsible owner in the directory.

Errors lists any per-item failures the crawl encountered — permission denials on individual sites, transient Graph throttling, folders that returned malformed responses.

§ 17

PDF & Excel exports

Every scan produces a client-ready PDF and a full Excel workbook. Both are available from the top-right of the scan detail page.

PDF report

  • Executive summary with total reclaim + monthly cost saving.
  • Storage overage vs. included quota, with the calculation shown.
  • Recommendations cards — Disabled OneDrive, Inactive OneDrive (1/3/5 years), Inactive SharePoint (1/3/5 years), Inactive Teams (1/3/5 years).
  • Per-workload breakdown.
  • Top-ten ranked actions with reclaim in GB.

MSPs on the appropriate plan can white-label the PDF with their own logo and primary colour under Settings → Branding.

Excel workbook

One sheet per workload plus a Summary sheet:

  • SharePoint — sites, storage in GB, file counts, last activity.
  • OneDrive — accounts in GB, inactive rows shaded pale red.
  • Exchange — mailboxes in GB.
  • Teams — teams-backed locations with linked site + file count.
  • Duplicates / Largest / Versions — the equivalent tab data with totals rows.
  • Recommendations — ranked, with No Owner / No Activity / Last Activity Since columns.
Exports are proxied through the same origin. If a download link times out, refresh the scan page and re-try — the export is regenerated on demand each time.
§ 18

Settings, billing, MFA

Profile

Your display name and email come from Microsoft SSO and can't be edited in TSO. To rotate MFA (if you're a platform admin), open Profile → Security and re-enrol.

Members

Workspace Owners can invite additional members from Settings → Members. Roles: owner, admin, analyst, viewer. Only owners can invite new owners and manage billing.

Billing

  • Microsoft commercial marketplace — if you subscribed via Azure Marketplace, your billing is handled by Microsoft. Change plan there.
  • Stripe (direct) — for customers billed by LogiSam. Card management lives in the Stripe customer portal, linked from the Billing page.

MFA

Regular workspace users rely on their own tenant's MFA. Platform admins can enable TOTP MFA on their account and get a trusted-device cookie so they don't have to re-enter the code every visit from the same browser.

§ 19

Admin console (platform admins)

A separate area at /admin for LogiSam staff. Red gradient strip at the top of every page.

Only visible to accounts flagged isPlatformAdmin. When enabled, the portal shows an Admin console button in the top-right — click to switch. Same SSO session is used; no separate password.

Sections

  • Health / Diagnostics / Audit — worker health, queue depth, event log.
  • Organisations — every workspace, with impersonate, suspend and delete actions.
  • Users — platform-wide user directory.
  • Demo requests — inbound requests from the marketing site.
  • Billing / Payments / Plans / Stripe — subscription management, Stripe credentials, plan definitions.
  • Email / SMTP / Templates — outbound email settings and per-template editor.
  • Feature flags — kill switches for individual product surfaces.
§ 20

Troubleshooting

Scan is stuck at 0%

Usually means the worker container is wedged on a hung Graph call from a previous job. Email support with the scan ID; the fix is a worker restart.

SharePoint total looks massively inflated

Older scans occasionally showed subsites double-counting their parent site collection's storage. The current version of TSO dedupes by site-collection GUID during the crawl. If you're looking at a pre-fix scan and want it corrected without re-scanning, contact support.

"Insufficient privileges" after consent

Your Global Admin clicked Accept, but Microsoft withheld one of the requested permissions. Retry consent; if it still fails, ask your Microsoft partner or Entra admin whether tenant policy is blocking application-permission grants for third-party apps.

PDF or Excel download fails

Refresh the scan page and try again — exports are generated on demand, and a first click after a long idle occasionally times out.

Contact support

Include the scan ID (from the URL) and a screenshot. Email hello@logisam.com or open the contact form.