ShareMaster V2 is in beta, a complete rebuild. See what is new and request access →
  1. Home
  2. Use Cases
  3. Contractor Offboarding

How to Remove Contractor Access from SharePoint Online

Contractor access left open after an engagement ends is one of the most common permission gaps in SharePoint Online tenants. Unlike full-time employees, contractors often accumulate permissions across multiple project sites over the course of their work, and the standard offboarding checklist rarely captures all of it.

Why Contractor Offboarding in SharePoint Is Harder Than It Looks

When should you treat contractor permission removal as a priority rather than a routine admin task? The answer depends on the type of access granted during the engagement:

  • Direct site member access: The contractor was added as a member to one or more SharePoint sites. Removing them from each site's Members group is straightforward if you know which sites they accessed.
  • Unique item or folder permissions: Someone granted the contractor access to a specific folder or document, breaking permission inheritance. These entries persist independently of group membership and are harder to find without scanning each library.
  • Shared links pointed at contractor email: Anyone-with-the-link or specific-people sharing links sent to the contractor's address remain active even after the contractor stops responding. The link does not expire automatically.
  • Guest account in Entra ID: If the contractor was invited as a Microsoft 365 guest, disabling or deleting the account removes most access, but does not clean up shared links or unique permissions already in place.

Most tenants handle the first case well. The last three are where gaps appear.

The Scenario: Bridgeford Consulting Faces a Busy Month-End

Meet Marcus, IT admin at Bridgeford Consulting, a 150-person professional services firm. Three external contractors are finishing their engagements on the same Friday: a design agency wrapping up a brand project, a developer who spent four months on a client portal build, and an independent consultant who had been embedded with the finance team for six months.

Each of these contractors had been working directly in SharePoint. The design agency accessed a dedicated project site and two shared document libraries. The developer had access to the dev team's SharePoint site, a staging environment site, and had been granted direct access to several folders in the IT library by a colleague. The finance consultant had broad read access to the finance team site and had received several specific-people sharing links to budget files.

Marcus has until end of business Friday. His HR system generates an offboarding ticket, but the ticket just says "remove Microsoft 365 access" - it doesn't enumerate the SharePoint sites. Marcus has to find them all himself.

What the Microsoft 365 Admin Centre Can and Cannot Do

The Microsoft 365 admin centre lets Marcus disable or delete accounts, which removes the users from security group memberships and, by extension, SharePoint group memberships inherited from those groups. That handles the surface-level access.

What it does not provide: a list of all SharePoint sites a user has direct access to, a view of unique permissions granted at the folder or item level, or a report of active sharing links associated with a specific user. To find those, an admin must either visit each site individually, run PowerShell against each site collection, or use a third-party tool.

In a 150-person firm with dozens of SharePoint sites, the manual approach takes hours per contractor. With three contractors and a Friday deadline, Marcus needed something faster.

Using ShareMaster to Audit Contractor Permissions

ShareMaster's Report Master and Share Link Finder give Marcus the evidence without opening every folder by hand. Both work one site at a time. Report Master's Security Matrix exports a site's permission matrix to Excel. Share Link Finder reports the sharing links and unique permissions in the libraries he picks, with each link's members, so he can search the workbook for a contractor's email address.

The output is an exportable report he can attach to the offboarding ticket, giving the security team a documented before-and-after record.

See Report Master features

Step by Step: What Marcus Did Over Two Hours

  1. Disabled the three Microsoft 365 guest accounts immediately. This blocked active sign-ins while Marcus continued the audit in the background. Disabling rather than deleting gave him 30 days to verify the cleanup before the accounts were gone.
  2. Ran a permission export on each site the contractors had worked in. Report Master's Security Matrix gave him each site's permissions in Excel, showing where each contractor appeared and the permission level assigned.
  3. Identified the folders where the developer had direct permissions not visible from the Sites list in admin centre. These had been granted by a colleague during the project, and Share Link Finder's unique permissions report on the IT library listed each one. That library held other unique permissions that had to stay, so Marcus removed the developer's entries in the browser from each folder's Manage access panel.
  4. Ran a sharing link report on each site and searched it for each contractor's email address. The finance consultant was a member of 11 active specific-people sharing links. All 11 sat in one budget library that had been shared only with him, so Share Link Finder's remove mode (it needs a Recycle Master or Clone Master licence) cleared every link in that library in one run, without navigating to each file individually.
  5. Removed group memberships. ShareMaster confirmed that group-based access for the design agency and developer had already been removed when the accounts were disabled. No additional action was needed on those.
  6. Exported the final permission state of each site to Excel and attached the files to the offboarding ticket as a completion record.
Tip: Run the permission audit before disabling the account if you want to see the full picture. Some tooling reports fewer permissions for disabled accounts. Marcus disabled accounts first because speed of lockout was the priority, then audited immediately after.

The Result: Three Contractors Fully Offboarded in Two Hours

Marcus completed all three offboardings in the same afternoon. The combination of per-site permission reports and one-run sharing link removal cut what would have been a half-day task into a two-hour one. He had a documented audit trail for each contractor and zero open sharing links by the end of business Friday.

Contractor offboarding is one of the tasks that looks simple on a checklist but hides significant complexity in a real SharePoint environment. The hidden permission entries and lingering sharing links are what create ongoing risk, and they require a tool that can surface them quickly.

For a broader look at auditing permissions across your tenant, see the guide on how to audit SharePoint permissions.

Frequently Asked Questions

Does deleting a contractor's Microsoft 365 account remove their SharePoint permissions?

Deleting an account removes the user from SharePoint group memberships, but unique item-level permissions granted directly to that user may persist as orphaned entries. Audit and revoke those unique permissions before or immediately after deleting the account to prevent these orphaned entries from lingering.

How do I see all the SharePoint sites a specific user has access to?

The Microsoft 365 admin centre does not provide a single view of all sites a user can access. Every route is site by site: SharePoint admin centre reports per site, PowerShell (Get-SPOUser across each site collection), or ShareMaster's Report Master Security Matrix run on each site to export its permissions to Excel, which you can then search for the user.

What happens to files a contractor uploaded to SharePoint when you remove their access?

Files uploaded to a SharePoint library stay in the library after a user's permissions are removed - they are not deleted. Everyone else who had access to the library can still reach the content. Only the removed user's access changes.

Try ShareMaster free for 14 days