In order to utilize the reporting options in SysKit Point Lite, you need to use an account with Global SharePoint Online Administrator privileges.
To achieve its functionality, SysKit Point Lite is registered as an Azure Active Directory Application. Azure Active Directory Applications can use other resources from Azure. To use these resources the user running the web application must consent to the permissions that the application requires.
When a global administrator uses SysKit Point Lite he will go through the normal consent flow where a popup with the Microsoft consent page is shown.
SysKit Point Lite requires the following delegated permissions:
Have full control of all site collections
Read all usage reports
Read all users' full profiles
Read all groups
Read directory data
Read items in all site collections
Access your data anytime
Granting delegated permissions to an application means that the application may act on behalf of a user. This means that the effective permissions that the user has are still limited by his own permissions.
If you at any time decide to revoke the given consent, you can do so by:
Go to Microsoft Azure portal.
Select Azure Active Directory.
Select Enterprise Applications.
Select SysKit Point Lite.