A SharePoint permission audit helps administrators verify:

  • Who has access to SharePoint sites, libraries, folders, and files
  • Understand how that access was granted
  • Detect changes for security reasons or data misuse

What Is a SharePoint Permission Audit?

A SharePoint Permission audit is the process of reviewing who has access to a SharePoint site, subsite, and its content. It also helps verify that: 

  • Which users and groups have access
  • What permission levels they have
  • Whether those permissions are still required

In simple terms, an audit can examine:

  • SharePoint permissions levels
  • Microsoft 365 group permissions
  • SharePoint groups
  • Individual user permissions
  • Document library permissions
  • Folder level permissions
  • File level permissions
  • External user access
  • Permission inheritance
  • Unique permissions
  • Permission changes
  • Sharing links and access settings

Regularly reviewing these permissions minimizes the risk of data leaks or loss. 

However, reviewing permissions alone does not protect the SharePoint data from accidental deletion or corruption. For an additional layer of protection, administrators can use a SysTools SharePoint Backup Tool to create a separate backup of important SharePoint data. 

Download Now Purchase Now

Why Should You Audit SharePoint Permissions?

Managing SharePoint permissions can become hectic, especially with a large team. Employees can change:

  • Departments
  • Projects end
  • External collaborators leave
  • Administrators modify access

So, without regular reviews, users keep access they no longer need.

Here are some major reasons to audit SharePoint permissions:

  1. An audit helps to find those users who have access to a confidential site without a requirement. 
  2. SharePoint permission auditing helps the administrator to know which team members have which level of permission access, i.e. Full, Control, Edit, or Contribute. This ensures that every team member has only required site access.  
  3. As per the parent site of the library, SharePoint gives the same permission level to files and folders. However, an administrator can set different permissions for individual files, folders, or libraries, which can be time-consuming. 
  4. Organizations need to share SharePoint files with external users or clients for business deals or communication. In these types of cases, a permission audit helps to identify whether they still need access or not.

A SharePoint Online permissions audit will show that every team member has only the required site access and permission level, which makes SharePoint management easy.

What Should You Check During a SharePoint Permission Audit?

Most the administrator thinks that only checking the list of users is a permission audit, but that’s not true. They have to check the complete permission structure:

#1. For users and groups review: 

  • Who has access?
  • Which SharePoint groups are they members of?
  • Are there any inactive users?
  • Are former employees still assigned permissions?
  • Are guest users still required?

#2. Check whether users have:

  • Full Control
  • Edit
  • Contribute
  • Read
  • Limited Access
  • Custom permission levels

Pay more attention to those users who have “Full Control” permission access. It is recommended to limit Full Control access to minimize the chances of data leaks. 

#3. This is a small step but necessary to verify: check if any sites, libraries, folders, or files have different permissions from their parent. Too many different permissions can make SharePoint difficult to manage. 

#4. Monitor and confirm that external users still require access. Always ensure you do not share sensitive information or site access with untrustworthy clients or users. It is necessary to review guest accounts and external sharing links.

#5. Administrators should also audit SharePoint permission changes to understand when access was:

  • Granted
  • Removed
  • Modified
  • Where available
  • Who acted

Till now, I explained what and why to audit, and I hope the concept is clear to you. Next, I’ll share how to audit SharePoint permissions. 

How to Audit SharePoint Permissions?

Permission auditing depends on the size and criticality of the SharePoint environment. As I’m a SharePoint administrator, I know there are several common ways to audit SharePoint permissions in minimal time. Let me explain them one by one:

#Method 1. Review Site Permissions Manually

This approach is suitable for smaller SharePoint environments, as you can review permissions directly from the SharePoint interface. Not only smaller environments, but if you are in a hurry to check any user’s permission access level, then this method is best among all:

  1. Open the SharePoint site.
  2. Go to Settings
  3. Open Site permissions.
  4. Review available SharePoint groups.
  5. Check members within each group.
  6. Review permission levels.
  7. Check users who should no longer have access.
  8. Review advanced permission settings when necessary.

This method can work for individual sites, but manually checking multiple sites or libraries can become time-consuming. That’s why it is not suitable for large SharePoint environments.

If you are planning to move SharePoint data to another site, tenant, or Microsoft 365 environment, managing permissions during the migration is also important. A SysTools SharePoint Migration Tool can help migrate SharePoint data without needing PowerShell or scripting.

Download Now Purchase Now

#Method 2. Use SharePoint Permission Reports

For large SharePoint environments, there is an option to generate permission reports, where you will find:

  • Users and their permissions
  • SharePoint groups
  • Permission levels
  • Unique permissions
  • External users
  • Site access
  • Library access
  • Folder-level permissions

This approach is better than checking every SharePoint location manually.

#Method 3. Use Microsoft 365 Audit Logs

Microsoft 365 auditing helps administrators track activity in SharePoint and OneDrive. It can also help find out if someone changed permissions.

For example, if an administrator finds an unexpected change in access, they want to know: 

  • When the activity occurred
  • Which account performed the action
  • Which SharePoint resource was affected
  • What type of activity occurred

This is especially useful when the goal is to audit SharePoint permission changes, rather than simply review the current permission configuration.

How to Audit SharePoint Permission Changes?

Auditing current permissions tells you who has access now. Auditing permission changes answers a different question: how did the access change?

This distinction is important.

Suppose an employee suddenly has access to a confidential library. A current permission report shows that the employee has access, but it does not explain how that access was obtained, or who gave the access. 

So, when investigating a permission change, administrators should check the available audit logs and related activities, which include:

  1. Find the affected SharePoint site.
  2. Check the user’s current permission level.
  3. Check if the permission is unique.
  4. Review relevant Microsoft 365 audit activity.
  5. Find the account associated with the change.
  6. Try to find when the activity occurred.
  7. Remove unnecessary access if required.

Maintaining historical audit information is equally important because current permissions alone cannot provide enough points for security investigations. When deep audit is needed, then the previous reports help to address the issue, if any. 

SharePoint Online Permissions Audit vs. Permission Change Audit

These two concepts are related but different in many ways.

A SharePoint Online permissions audit is only for the current access configuration.

It answers questions such as:

  • Who can access this site?
  • Which users can edit this library?
  • Which groups have access?
  • Which files have unique permissions?
  • Are external users accessing sensitive content?

A permission-change audit tracks how permissions have changed over time.

It answers questions such as:

  • When was access changed?
  • What activity occurred?
  • Which account acted?
  • Was a permission-related change expected?
  • Can the change be connected to an administrative action?

For better SharePoint security, organizations should review both current permissions and past permission changes

SharePoint Permission Audit Checklist

Use the following checklist when performing an audit:

  • Review all SharePoint sites and site collections.
  • Identify users with access to sensitive sites, especially those who have “Full Control access.
  • Review SharePoint and Microsoft 365 group membership.
  • Review external and guest users.
  • Identify unique permissions.
  • Check for direct user permissions.
  • Review document and library permissions.
  • Investigate unexpected permission changes.
  • Review available Microsoft 365 audit activity.
  • Remove unnecessary permissions.
  • Document important findings.
Author’s Verdict

A comprehensive SharePoint Permission audit can help organizations:

  • Identify excessive access
  • Review external users
  • Detect unique permissions
  • Maintain better control over sensitive information

At the same time, administrators should audit SharePoint permission changes when investigating unexpected access.