ShareMaster V2 is in beta, a complete rebuild. See what is new and request access →
  1. Home
  2. Guides
  3. Export Permissions to Excel

How to Export SharePoint Permissions to Excel

A SharePoint Online tenant with 50 site collections and typical inheritance breaks contains hundreds of unique permission configurations spread across libraries, folders, and individual list items. Documenting that by hand takes days. This guide shows how to get each site's permissions matrix into Excel in a single run using the Security Matrix report in ShareMaster's Report Master, and how to read the workbook it produces.

What is a SharePoint permissions matrix?

A permissions matrix is a table that answers one question: who has access to what, and at which permission level? Users and groups run down the rows, permission levels run across the columns, and a mark sits wherever the two meet. A site gets one matrix for itself, and every list, library, folder or file that stops inheriting gets a matrix of its own, because its permissions no longer follow the site.

Teams ask for one when an auditor needs the complete access picture, before a migration to see which permissions will carry over, when offboarding someone to confirm their access is really gone, and when a regulator or client sends an access questionnaire.

What a complete export has to answer

  • Who: a user, a SharePoint group (plus its members), a Microsoft 365 group, or a sharing link.
  • What: the site, a list or library, or a file, folder or item.
  • How much: the permission level (Full Control, Design, Edit, Contribute, Read, or a custom level).
  • Inherited or unique: whether the permission follows the parent hierarchy or breaks from it.

For governance reviews, inherited versus unique matters most. Every unique scope is a place where someone clicked "Stop inheriting permissions" and manually assigned access. Most of those decisions outlive the reason they were made.

What SharePoint Online does not give you natively

The SharePoint admin centre shows each site's admins, owners, members and visitors on its Membership tab, along with its external sharing setting and storage use. If your tenant has SharePoint Advanced Management (included with Microsoft 365 Copilot licences), its data access governance reports add tenant-level views of sharing links and permission state per site. None of these show library-level or item-level unique permissions for each user, and none export a per-user matrix to Excel.

The classic workaround is PnP PowerShell: enumerate every web, list, library, folder, and item, collect each access control list, write a CSV. A script that does this properly has to cover every way access is granted:

  • direct assignments to a user
  • SharePoint group membership
  • Microsoft 365 group membership, which controls access to group-connected team sites
  • sharing links, each backed by a hidden SharingLinks group
  • Entra ID security groups, including nested ones

Read only one of those and the matrix is incomplete. The approach works, but it takes time to author, test, and maintain. It also calls the same throttled SharePoint APIs as any tool, so a full tenant scan can run for hours; the saving from a tool is in not writing and maintaining the script. For a reference on what each permission level actually grants, see the SharePoint Permission Levels Reference.

Step 1: Connect as a site collection administrator

Open ShareMaster, choose Reports in the left menu and then the Security Matrix tile, enter the site URL, and sign in through the Microsoft sign-in window, so MFA works as it normally does. No Azure app registration or client secret is needed for this report. The tile is marked as needing site collection administrator access, because reading every permission assignment on a site requires it.

The SharePoint Administrator role does not by itself give you access to a site's content. If you are not already a site collection administrator on the site, add yourself in the SharePoint admin centre first. If you are running this for a client, use an account within their tenant that has that access.

Illustration: a ring of keys mapped to nested folders.
How to Export SharePoint Permissions to Excel

Step 2: Choose the lists and libraries

  1. The site's lists and libraries are shown with tick boxes. Tick the ones to include, or select them all.
  2. Tick Show Hidden Items if you also want hidden lists in the report.
  3. Click Create Report.

Any list or library with its own permissions, and any library with uniquely permissioned files or folders, gets a sheet of its own, so a narrower selection gives a shorter workbook.

Tip: each report covers one site. For a tenant review, start with the sites that hold sensitive content or have the most sharing, and work outward site by site rather than trying to document everything in one pass.

Step 3: Read the Security Matrix workbook

Report Master reads the site's role assignments, its SharePoint groups and their members, the hidden groups SharePoint creates behind sharing links, and every file or folder with unique permissions in the libraries you picked. It waits and retries if SharePoint throttles it, and when the run finishes you can save or open the Excel workbook from the progress dialog.

How the matrix is laid out

Every matrix in the workbook uses the same shape. Column A is User/Group, column B is Principal (the principal type, such as User, SharePointGroup or SecurityGroup), and each permission level in use gets a column of its own after that. A cell holds an X where the principal has that level and a dash where it does not. Limited Access is left out of the site and list matrices. A site-level matrix looks like this:

User/Group Principal Full Control Edit Read
Finance OwnersSharePointGroupX--
Finance MembersSharePointGroup-X-
Finance VisitorsSharePointGroup--X
Jordan LeeUserX--

SharePoint group names are links to that group's members on the SharePoint Groups sheet, and Microsoft 365 or security group names link to the O365 Groups sheet when that sheet is present. The sheets:

Sheet What it contains Recommended use
Web Permissions The site's own matrix. Below it, Lists which inherit Permissions names the selected lists that follow the site, then an index of the lists that have a sheet, each linked to that sheet with a count of its unique items. Check the site's owners and any direct grants to individuals, and see at a glance where inheritance is broken
SharePoint Groups Each SharePoint group with its members' display names, login names and email addresses Turn "Members group has Edit" into the names of the people who actually have it
Sharing Links The SharingLinks groups SharePoint created when files and folders were shared, with their members See who a sharing link reaches without opening each file's Manage access panel
O365 Groups Members of the Microsoft 365 and security groups that hold permissions, by display name and email, added when Microsoft Graph consent is in place. Members are listed one level deep; nested groups are not expanded. Resolve the members behind a group-connected site's Owners and Members
A sheet named after each list or library For a list or library with its own permissions: a List Permissions matrix. For a library with uniquely permissioned files or folders: one row per file or folder and principal, under File/Folder, User/Group and Principal columns followed by the permission levels. The sheet name is the list title with spaces and punctuation removed, cut to 31 characters. Find the item-level breaks, which are the noisiest in most tenants

ShareMaster V2, currently in public beta, has a rebuilt Security matrix that can take several site collections, sites, libraries or folders in one run and expands nested Microsoft 365 group membership. It is a beta, so treat it as a preview rather than the audited route.

Learn more about Report Master's export capabilities

Step 4: Filter the matrix

The highest-signal starting point is an X under Full Control for anyone outside the site's owners group, on Web Permissions or on a list with its own permissions. That is someone with site-owner-equivalent access outside the normal group structure, and each of those rows deserves a quick review. Then:

  • On SharePoint Groups, filter login names for #ext# to isolate guest accounts for an external access review.
  • Use the list index on Web Permissions to see which lists have unique permissions and how many files and folders inside each one have permissions of their own.
  • On a library sheet, filter the File/Folder column to a folder path to see every break beneath it.
  • Use the Sharing Links sheet to see who each sharing link actually reaches.
  • To check one person across several sites, search each site's workbook for their name; a per-user view across sites means combining the workbooks.

Step 5: Taking action on the results

A permission export becomes valuable when it drives a specific action rather than sitting in a folder. Practical follow-up tasks:

Remove stale and over-broad access

Filter for users who have left the organisation, changed roles, or no longer need access, and for people holding Full Control on sites they do not administer or Contribute where they only need to read. Cross-reference with your Entra ID directory to confirm current status, and fix access through SharePoint group membership rather than new direct grants. Guest accounts with permissions but no recent activity are an exposure of their own; remove their permissions and, where appropriate, run a Microsoft Entra access review of guests.

For files and folders, use ShareMaster's Share Link Finder: in the libraries you pick on a site it can remove sharing links, or all unique permissions so items inherit again. Removal needs a paid licence; the Community licence and the trial can only report. The remediation guide walks through the order to do this in.

Flatten permission breaks before a migration

Sites with hundreds of unique permission breaks are significantly harder to migrate cleanly. Running a permission cleanup before a migration means that Clone Master carries a simpler, more intentional permission structure to the destination tenant. For a full picture of what a permission audit involves before migration, see the SharePoint permissions audit guide.

Use the workbook as a SharePoint permissions audit report

Save the exported workbook with a datestamp, filter to Full Control and Edit assignments, and share it with your security or compliance team. The output is self-explanatory and requires no SharePoint access to read. It works well as evidence for internal audits, SOC 2 reviews, or pre-acquisition due diligence where an acquirer needs to understand data access scope across the Microsoft 365 tenant. Export again after a cleanup and you have a before-and-after pair for the record.

Frequently Asked Questions

Can SharePoint Online export permissions to Excel natively?

Not in full. Site Settings shows assignments one object at a time with no export to Excel. SharePoint Advanced Management, where licensed, adds data access governance reports you can download, but they summarise sites rather than list every assignment on every item. PnP PowerShell provides the raw scripting capability; Report Master's Security Matrix produces the export without requiring any code.

What is a SharePoint permissions matrix?

A table with users and groups on one axis and permission levels on the other for a site, list or item. In the Security Matrix workbook, users and groups are the rows, permission levels are the columns, and an X marks each level a principal holds.

What permission levels appear in the export?

The Security Matrix shows the permission levels in use on the site, such as Full Control, Design, Edit, Contribute and Read, plus any custom levels, as columns. Its SharePoint Groups sheet lists the members of each group, so individual users inside groups are visible in the output.

Does the export include external guest users?

Yes, wherever a guest holds a permission directly or through a SharePoint group. The SharePoint Groups sheet lists each member's display name, login name and email, so guests can be filtered out by their #ext# login name or external email domain. There is no separate user-type column.

How long does a full export take?

It depends on how many lists you select and how many files and folders in them have unique permissions, because each one is read individually. A small site finishes quickly; a site with thousands of uniquely permissioned items takes longer. Report Master waits and retries when SharePoint throttles it, so the report runs unattended to completion.

What admin role is required?

Site collection administrator access on the site you report on. The SharePoint Administrator role on its own does not grant access to a site's content, so a SharePoint Administrator should add themselves as a site collection administrator from the SharePoint admin centre before running the report.

What to do next

Nobody exports a permissions matrix for fun. The export is step one of a cleanup, and the spreadsheet usually shows more broken inheritance than expected, so fixing broken inheritance is the guide that follows this one.

If the question behind the export is whether to keep doing this by hand, PowerShell or buy works through it honestly, including the cases where a script is the right answer.

Try ShareMaster free for 14 days