Reads
Settings and metadata only
A posture scan requests configuration objects: conditional access policies, role assignments, sharing settings, transport rules, audit-log configuration, key vault and storage account properties. It reads the shape of your tenant, not its contents.
It does not read the body of emails, the contents of documents in SharePoint, OneDrive or Google Drive, chat messages, or any customer data your business holds. Where an API returns a document identifier or a mailbox name as part of a configuration object, that identifier is stored; the document is not fetched.