ShareMaster V2 is in beta, a complete rebuild. See what is new and request access →
  1. Home
  2. Demos
  3. Shared links & permissions

Find & remove SharePoint shared links and unique permissions

Scan, report, and clean up shared links and broken inheritance across SharePoint document libraries.

Five and a half minutes, start to finish: a read-only scan of a site, what the report actually tells you, and then revoking the links you decided to revoke. Nothing changes until you approve it.

The walkthrough covers reporting links and unique permissions to Excel, the difference between the two, which sign-in you need, choosing scope across whole sites, individual libraries and subsites, and the filters that make a big tenant readable: link scope (anyone, organisation, specific people), link type, expired links only, direct grants, and narrowing by file or folder name.

Over time, SharePoint document libraries become messy as staff share links freely and break permissions without realising the long-term impact.

The result is permission sprawl - files with unique permissions, anonymous or external sharing links, and content accessible to people who should no longer have access.

ShareMaster's Shared Links & Permissions Cleanup scans multiple document libraries within a SharePoint site, reports on shared links and unique permissions, and removes them in bulk to restore inherited access.
ShareMaster SharePoint shared links and permissions report

What this feature does

Report mode

  • Scan multiple document libraries in a SharePoint site
  • Detect all shared links
  • Identify unique permissions
  • See who content is shared with
  • Export a clear, auditable report

Removal mode

  • Remove shared links in bulk
  • Remove unique permissions
  • Restore inherited permissions
  • Clear a backlog of stale shares in a single pass

Why this matters

Shared links are often created casually - "just for a minute" - but they frequently remain long after the original need has passed. That creates security risk, audit gaps, and compliance concerns.

ShareMaster makes it easy to see exactly what is shared, who it's shared with, and take action confidently - either by exporting a report or actively cleaning up access.

A sharing link and a unique permission are not the same thing

This trips up most clean-ups, and the video spends time on it because removing the wrong one leaves the access you were trying to close.

A sharing link is a URL with a token in it. Anyone holding that URL gets in on the terms the link was created with: an Anyone link needs no sign-in at all, an Organisation link admits any account in your tenant, and a Specific people link is tied to named recipients. Revoking the link kills that URL for everybody who has it, wherever they saved it.

A unique permission is broken inheritance: the file or folder stopped taking its permissions from the library above it and now carries its own, usually because somebody was granted access directly. Removing it restores inheritance, so the item goes back to being governed by the library rather than by a decision made once and forgotten.

Neither removal touches content. Files stay exactly where they are, and people who still have access through the library keep it. What goes is the extra access that was granted on top.

This is a clean-up, not a guard

Worth being straight about, because plenty of tools in this space imply otherwise. ShareMaster reads your tenant when you run it and stops when the run finishes. It does not sit in the background watching, there is nothing to schedule, and a link somebody creates the following morning will not be caught until you scan again.

Removing a link also does not stop the same file being shared again. Whether people can create Anyone links at all is a tenant and site sharing setting in the SharePoint admin centre, and that is where you change it. The right pairing is usually both: tighten the policy so the problem stops growing, then run this to clear what the old policy already let through.

Most teams run it on a rhythm they choose - quarterly, or before an audit, or when someone leaves - and compare the new report against the last one. That is a habit, not a feature we are claiming.

Scan first, revoke second

Report mode is read-only, and it is the sane way to start: scan a site, export the result, and look at what a filter would actually catch before anything is revoked. The filters in the video exist for that reason. Expired links only, or Anyone links only, turns "we have thousands of shares" into a list somebody can defend in a change request.

How it works

1. Select document libraries

Choose one or multiple document libraries within a SharePoint site to scan.

2. Analyse permissions and links

The app detects shared links, identifies unique permissions, and records who content is shared with and how.

3. Report or remove

Generate a report for review, or remove shared links and unique permissions in bulk to restore inherited access. The run ends there: what it found is a picture of the tenant at the moment it read it.

Try it yourself. Discover and clean up SharePoint shared links and unique permissions across your document libraries.