Solution · M365 Governance

SharePoint permissions.One overviewinstead of many dialogs.

Conbool M365 Governance reads the permissions of all sites, libraries and OneDrives, shows them in one list and assesses every share against fixed rules.

Why SharePoint permissions get out of hand

SharePoint shows permissions per item. The auditor's question is: who has access overall?

Broken inheritance

Every share of a folder or file creates its own permission scope. After a few years nobody knows how many there are.

No report across all sites

The built-in tools answer the question site by site. For the whole tenant you need scripts that someone has to write and maintain.

Groups hide people

A permission for a group does not say who is behind it. Guests in nested groups show up in no view.

OneDrive is left out

Most sharing happens in personal storage. It does not appear in site reports.

How the overview is created

Three steps, no agent and no script.

1. Grant consent

A global administrator consents to the application. It reads sites, libraries, groups, guests and permissions. File contents are never read.

2. The scan records every permission

Each permission shows object, item, recipient, role and expiry, split into links and direct grants, for SharePoint and OneDrive.

3. Rules assess, you decide

13 fixed rules turn permissions into findings with a severity. Intended shares are recorded as exceptions, the rest can be cleaned up.

What the audit delivers

Everything in one interface, for the whole tenant.

View and filter permissions

Filter by recipient type: internal, guest, external, anyone with the link, organisation, everyone. Search by name or path.

External domains and addresses

Summary of the domains and addresses with the most grants. One click filters the list.

Expand group members

Who gains access through a group is shown right at the permission, nested groups included.

Permissions report as PDF and CSV

The report summarises score, findings and exceptions. The list of permissions is available as CSV.

Findings on inheritance and ownership

Many unique permission scopes and objects with no owner or only one owner appear as separate findings.

Clean-up with a dry run

Remove the share, set an expiry date or reduce to read access. First as a dry run, then with approval by a second person.

Managing permissions with and without Conbool

What changes day to day.

 
Conbool M365 Governance
Dialogs and scripts
Overview
One list for SharePoint and OneDrive
One dialog per site and per item
Assessment
13 rules with severity and score
Judgement by hand
Groups
Members including nested groups visible
Group name without people
Report
PDF and CSV at the push of a button
Script output to be prepared manually
Clean-up
Dry run and approval by a second person
One by one, without a preview
Ongoing control
Scheduled scan reporting new findings
Repeated when someone remembers

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

FAQ on SharePoint permissions

How do I get an overview of all SharePoint permissions?
With built-in tools only per site or through your own scripts. Conbool M365 Governance reads the permissions of all sites, libraries and OneDrives and shows them in a filterable list, down to the single item with its own share.
Are OneDrive permissions included?
Yes. Shares from users' OneDrives appear in the same list as those from SharePoint and are assessed against the same rules.
What does broken inheritance mean?
A folder or file inherits the permissions of its library. When an item is shared individually, it gets its own permission scope. Above a configurable number of such scopes M365 Governance reports the object as a finding.
Does Conbool read my files for this?
No. Names, paths, recipients and roles are recorded. The content of a file is not opened.
Can I also change permissions with it?
Yes, in three fixed actions: remove the share, set an expiry date, reduce a direct grant to read access. Every change starts with a dry run and needs approval by a second person. Ownership is not touched.
Is this a tool for an access concept?
It documents the actual state in Microsoft 365 and shows deviations from a template. The concept itself, meaning who should have which rights, is yours to define. File servers and SAP are out of scope.

See who can access what.

From the first scan to the report in one interface.