ShareMaster V2 is in beta, a complete rebuild. See what is new and request access →
  1. Home
  2. Guides
  3. Audit SharePoint Permissions

How to Audit SharePoint Permissions Across Multiple Sites

Illustration: a permissions matrix of filled and empty cells.
How to Audit SharePoint Permissions Across Multiple Sites

Permission sprawl is one of the most common governance problems in SharePoint Online. It builds up gradually: a project finishes but the shared links stay live, a contractor gets owner access and never gets removed, individual files accumulate broken inheritance because someone clicked "Stop inheriting permissions" years ago. A periodic permissions audit finds and fixes this drift before it becomes a compliance issue.

This guide walks through a full permissions audit from start to finish: scoping the work, using native SharePoint tools, exporting a complete permission matrix, and remediating the findings. It covers SharePoint Online (Microsoft 365).

Before You Start: Understand the Permission Model

SharePoint permissions cascade from tenant to site collection to site to library to folder to item. By default, each level inherits from its parent. When you break that inheritance on a folder or file, SharePoint stores a separate access control list for that object. Every broken-inheritance item counts against the 50,000 unique-permissions limit for its list or library, and Microsoft recommends keeping each one under 5,000.

There are two categories of access to audit:

  • Group-based permissions: SharePoint groups (Owners, Members, Visitors) and Microsoft 365 groups tied to teams or sites.
  • Sharing links: Anyone links, Specific people links, and Organisation-wide links created via the Share button or OneDrive sync. These bypass the group model entirely and are harder to enumerate.

Step 1: Map Your Site Collections

Start by getting the complete list of sites you need to cover.

  1. Open the SharePoint admin center (https://<tenant>-admin.sharepoint.com).
  2. Navigate to Sites > Active sites.
  3. Click Export (CSV) to download the full site list. This gives you URLs, storage usage, template type, and the primary admin for each site.
  4. Filter out system sites (search, portals) and personal OneDrive sites unless your audit specifically covers OneDrive.
Scope decision: For a first audit, focus on the top 20 sites by storage or by sensitivity (sites tagged confidential or containing HR and finance data). A full-tenant audit is worth scheduling quarterly once the initial cleanup is complete.

Step 2: Identify Unique Permissions (Broken Inheritance)

For each site in scope, you want to know which libraries, folders, or items have stopped inheriting permissions from their parent.

Using the native SharePoint UI

  1. Open the site and go to Site settings > Site permissions.
  2. Click Check permissions and enter a user's name or email to see what access they have and where it comes from.
  3. In any library, select a file or folder and open Manage access (right-click or via the details pane), then its advanced settings. The classic permissions page that opens offers Delete unique permissions only when the item has broken inheritance.

Limitations of the native approach

The native UI checks permissions for one item or one user at a time. It cannot enumerate all unique-permission items across a site or across multiple sites. For that, you need either PnP PowerShell scripts or a tool that reads the SharePoint REST API.

Watch the 50,000 limit: Each list or library supports a maximum of 50,000 items with unique permissions, with 5,000 as Microsoft's recommended general limit. Libraries with deep folder structures and file-level sharing are most at risk. See the SharePoint Online Limits Reference for the full table including the performance implications as you approach this threshold.

Step 3: Review SharePoint Groups and Membership

  1. Open the site and go to Site settings > People and groups.
  2. Review each group (Owners, Members, Visitors, plus any custom groups).
  3. Look for individual user accounts added directly to site permission groups instead of via Microsoft 365 groups or Microsoft Entra security groups. Direct user assignments are harder to audit and do not move when someone leaves the organisation.
  4. Check for external users (accounts with #EXT# in the login name or UPN). Confirm each one is still an active partner or vendor with a legitimate need.
  5. Identify inactive accounts: users who are still licensed but have not signed in within the past 90 days. Flag these for review or removal.

Step 4: Audit Shared Links

Sharing links are the hardest part of a permissions audit because they bypass the group-based model. A file can have "Members" access at the library level and still be accessible to anyone in the world if someone created an "Anyone with the link" share.

Using native SharePoint tools

  1. Run the per-site sharing report: open the site's Site usage page from Settings and use Run report in the Shared with external users section. The CSV it saves covers internal shares too, with the user or group, the permission and the link type for each shared item.
  2. Set link expiry policies under Policies > Sharing in the SharePoint admin center to enforce automatic expiration on new Anyone links going forward.

Using ShareMaster's Share Link Finder

The native report has to be run site by site and gives you a CSV, but no way to act on it in bulk. ShareMaster's Share Link Finder works on the document libraries you pick on a site and writes an Excel workbook showing:

  • The hidden SharingLinks groups SharePoint creates for each link, and who is in each one.
  • What kind of link each is, read from the group's name: anyone, people in the organisation, or specific people, and whether it allows editing.
  • Each file or folder that carries a sharing link, with a hyperlink to the link it uses.

Run it in report mode first. Its Remove shared links mode then strips all sharing links from those libraries in one operation, without opening each file manually. Removing is not available on the Community licence or the trial. To remove only some kinds of link, for example only Anyone links, the ShareMaster V2 beta can filter by link scope, link type, or expired links only.

Step 5: Check Site Collection Administrators

Site collection administrators have full control over every object in the site collection, including second-stage Recycling Bin access and the ability to see all content regardless of unique permissions. This role should be kept small.

  1. In the SharePoint admin center, open Sites > Active sites.
  2. Select a site and choose Membership on the command bar to see its site admins.
  3. Confirm each listed admin has a current business reason for full control. Service accounts, project accounts for completed migrations, and former employees are common candidates for removal.

Step 6: Export a Full Permission Matrix

A permission matrix shows every user and group mapped to every site, library, folder, and item they can access. It is the deliverable most compliance auditors and security reviewers expect.

ShareMaster's Report Master produces this as the Security Matrix report. You pick the lists and libraries to cover, and it writes an Excel workbook containing:

  • Web Permissions - the role assignments held at web level.
  • SharePoint Groups - each group with its members expanded, so you are reading names rather than group titles.
  • Sharing Links - the hidden SharingLinks groups pulled out onto their own sheet, which is what makes per-file oversharing visible at all.
  • One sheet per list that has items with unique role assignments, listing those items.
  • Microsoft 365 Groups - added only when the app has Graph access. Without admin consent for Graph the report still runs and this sheet is simply left out, so check for it before concluding a site has no M365 group access.

Lists are split by whether they have unique role assignments, so you can see immediately which ones have broken inheritance rather than inferring it.

For ongoing governance, repeat this export monthly and compare it against the previous month. A diff between two exports shows who gained or lost access and where new unique permissions appeared. There is no built-in scheduler, so this is a diary entry rather than something the app does for you.

Step 7: Remediate Findings

A typical first-audit remediation involves three categories of work:

Remove inactive and external users

Use the exported matrix to identify accounts that no longer need access. Removing a direct user from a SharePoint group immediately revokes their access to every library and item that inherits from that group.

Consolidate unique permissions

For folders and files with broken inheritance, restore inheritance where possible (the "Delete unique permissions" option on the item's advanced permissions page, reached from Manage access). Move access control to the library level using groups so future changes propagate automatically.

Remove or expire shared links

Remove links with no current business purpose: one-off shares that have served their purpose, Anyone links on sensitive documents, and links used by accounts that are no longer active. ShareMaster's Share Link Finder removes every sharing link in the libraries you choose, so use it on libraries where no link should survive, and the per-item Manage access panel for the rest.

Step 8: Establish Ongoing Governance

A one-time audit decays quickly. Permissions drift comes back within weeks if no controls are in place. The minimum governance layer worth establishing after an audit:

  • Set a link expiry policy in the SharePoint admin center (30 days for Anyone links is a common starting point).
  • Restrict who can create new sites to prevent sprawl of ungoverned site collections.
  • Run a quarterly permissions export from Report Master and review the diff against the previous quarter.
  • Grant access to the most sensitive sites through Microsoft 365 or security groups and put those groups under Microsoft Entra access reviews, so group owners are asked to recertify members on a schedule. Access reviews cover Entra groups, not SharePoint groups, and need Microsoft Entra ID P2 or ID Governance licensing.

Related reading

Summary

A permissions audit covers four areas: site collection admins, group membership, unique permissions on items, and shared links. The native SharePoint admin center handles high-level reporting; a tool like ShareMaster covers the item-level enumeration and bulk remediation that native tooling lacks. Running a permission matrix export before and after remediation gives you audit evidence and a baseline for ongoing governance.

See the Share Link Finder in action

Try ShareMaster free for 14 days