The AWS managed client app for SharePoint accesses SharePoint sites via the SharePoint REST APIs. It requires the following permissions to be granted:

Sites.Read.All - Allows the app to read metadata about sites across the organization. List.Read.All - Allows the app to read lists and document libraries across sites. Web.Read.All - Allows the app to read web parts and other metadata about pages. Profile.Read.All - Allows the app to read user profile information. TermStore.Read.All - Allows the app to read taxonomy metadata.

