brillientaKnowledge base

Knowledge base / Intranet Builder / Security & data

Security

1 min read · Intranet Builder 2.4.0

Security is enforced by SharePoint and Microsoft 365, not just by hiding buttons. Provisioning uses either the administrator's own permissions or the worker's managed identity, limited to granted sites.

Your tenant, your data

All intranet data lives in your SharePoint sites and moves only through SharePoint and Microsoft Graph. No certificates, secrets or elevated tokens are stored in bundles, lists or settings.

Least privilege

Delegated permissions for components; the administrator's own permissions (administrator-run) or Sites.Selected (automated) for provisioning. Site creation, app catalog and hubs stay separate from routine site changes.

Server-side authorization

The provisioning API validates token issuer, audience, tenant, scope and role, derives the tenant from the verified token and authorizes every target site. UI checks only improve the experience.

Approved content only

Only validated configurations of approved templates and packages; package files are checked against SHA-256 hashes; never uploaded scripts.

Audit

Job records (requester, executor, operation, outcome), migration records and SharePoint version history of settings. Logs and telemetry leave out personal data and credentials.

Presentation is not authorization

Audience targeting and hidden navigation never protect content; SharePoint permissions do. Approvers receive a custom Intranet Approver level on moderated lists.

Telemetry is off by defaultUnless an administrator sets an Application Insights connection string. Only allow-listed, non-personal properties are sent: component, module, error code, operation and correlation ID.
This article is about Brillienta Intranet Builder.See the productView plansBook a demo
Still need help?Our team answers product questions by email, and we can walk you through it on a call.
Open in the full guideContact support