SharePoint permissions.One overviewinstead of many dialogs.
Conbool M365 Governance reads the permissions of all sites, libraries and OneDrives, shows them in one list and assesses every share against fixed rules.
Why SharePoint permissions get out of hand
SharePoint shows permissions per item. The auditor's question is: who has access overall?
Broken inheritance
Every share of a folder or file creates its own permission scope. After a few years nobody knows how many there are.
No report across all sites
The built-in tools answer the question site by site. For the whole tenant you need scripts that someone has to write and maintain.
Groups hide people
A permission for a group does not say who is behind it. Guests in nested groups show up in no view.
OneDrive is left out
Most sharing happens in personal storage. It does not appear in site reports.
How the overview is created
Three steps, no agent and no script.
1. Grant consent
A global administrator consents to the application. It reads sites, libraries, groups, guests and permissions. File contents are never read.
2. The scan records every permission
Each permission shows object, item, recipient, role and expiry, split into links and direct grants, for SharePoint and OneDrive.
3. Rules assess, you decide
13 fixed rules turn permissions into findings with a severity. Intended shares are recorded as exceptions, the rest can be cleaned up.
What the audit delivers
Everything in one interface, for the whole tenant.
View and filter permissions
Filter by recipient type: internal, guest, external, anyone with the link, organisation, everyone. Search by name or path.
External domains and addresses
Summary of the domains and addresses with the most grants. One click filters the list.
Expand group members
Who gains access through a group is shown right at the permission, nested groups included.
Permissions report as PDF and CSV
The report summarises score, findings and exceptions. The list of permissions is available as CSV.
Findings on inheritance and ownership
Many unique permission scopes and objects with no owner or only one owner appear as separate findings.
Clean-up with a dry run
Remove the share, set an expiry date or reduce to read access. First as a dry run, then with approval by a second person.
Managing permissions with and without Conbool
What changes day to day.
Conbool M365 Governance | Dialogs and scripts | |
|---|---|---|
| Overview | One list for SharePoint and OneDrive | One dialog per site and per item |
| Assessment | 13 rules with severity and score | Judgement by hand |
| Groups | Members including nested groups visible | Group name without people |
| Report | PDF and CSV at the push of a button | Script output to be prepared manually |
| Clean-up | Dry run and approval by a second person | One by one, without a preview |
| Ongoing control | Scheduled scan reporting new findings | Repeated when someone remembers |
As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.
FAQ on SharePoint permissions
How do I get an overview of all SharePoint permissions?
Are OneDrive permissions included?
What does broken inheritance mean?
Does Conbool read my files for this?
Can I also change permissions with it?
Is this a tool for an access concept?
Related solutions
M365 Governance
Berechtigungen und Freigaben in Microsoft 365 erfassen, bewerten, bereinigen.
Copilot und Oversharing
Zu weite Freigaben finden, bevor Copilot eingeführt wird.
Microsoft-365-Sicherheitscheck
Mandanteneinstellungen gegen eine Vorlage, dazu der Bestand an Freigaben.
Microsoft 365 Backup
Acht Quellen in einem Zeitplan, Rückholung einzelner Elemente.
Microsoft 365 E-Mail-Sicherheit
Schutz des Mailwegs vor Exchange Online.
Vergleich mit Hornetsecurity
Conbool und Hornetsecurity im Überblick.
See who can access what.
From the first scan to the report in one interface.