Flag Obsolete Content

Uncover Hidden Permission Exceptions Across SharePoint

SharePoint permissions are designed to inherit through the content hierarchy, but over time exceptions accumulate. Files are shared directly, folders receive unique permissions, and inheritance is broken to support specific business needs. These exceptions can become difficult to identify, increasing governance complexity and creating potential security blind spots.

The Find Files or Folders with Security Different from the Direct Parent skill helps organizations identify SharePoint files and folders whose access differs from the item immediately above them.

By comparing each item only to its direct parent, the skill highlights unique permissions, broken inheritance, and direct sharing differences while reducing false positives that can occur when comparing content against broader library or site-level access patterns.

Importantly, this skill is analysis-only. It does not change permissions, modify metadata, restore inheritance, or alter access settings. Instead, it generates a structured report that helps administrators, governance teams, and content owners identify permission exceptions that may require review.

What You’ll Get

  • A detailed Excel workbook documenting SharePoint permission differences
  • Visibility into files and folders with unique permissions
  • Identification of broken permission inheritance
  • Findings categorized as Extra Access, Restricted, or Equal
  • Direct hyperlinks to reviewed SharePoint content
  • Supporting permission evidence for flagged items
  • Manual-review indicators where permission information is incomplete
  • A complete inventory of reviewed files and folders

How it works

Determine the Review Scope

The skill identifies the selected SharePoint site, library, folder, file collection, or user-specified location for analysis.

Evaluate Parent-Child Permissions

Each file and folder is compared against its immediate parent rather than a broader site or library baseline.

Analyze Permission Differences

The skill reviews available permission information to identify items whose security profile differs from their parent.

Classify Findings

Results are grouped into categories including:

  • Extra Access – Access appears broader than the parent item
  • Restricted – Access appears more limited than the parent item
  • Equal – Available permission signals align with the parent item
  • Needs Manual Review – Additional review is required before a reliable determination can be made

Generate Reporting

All findings are compiled into a structured Excel workbook for investigation and remediation planning.

Return Results

A concise summary, status counts, findings overview, and report location are provided.

When to use this

  • Reviewing SharePoint permission inheritance
  • Finding files or folders with unique permissions
  • Identifying content shared directly with users
  • Auditing permission exceptions
  • Supporting governance and compliance reviews
  • Preparing SharePoint environments for Microsoft 365 Copilot
  • Assessing security consistency across document libraries
  • Investigating unexpected access to content
  • Creating a documented record of permission differences

Output

The generated workbook includes:

Summary

A high-level overview of the scan scope, findings, status counts, and review methodology.

Findings

A focused list of files and folders whose permissions differ from their immediate parent, including supporting evidence and reasons for classification.

Full Scope Review

A complete inventory of evaluated content, including inherited, flagged, and manual-review outcomes.

Upon completion, the skill returns a concise findings summary and the location of the generated workbook.

Why this matters

SharePoint permissions evolve over time. Departments collaborate, projects expand, and users grant access to specific files and folders. While these actions are often necessary, they can create exceptions that are difficult to track and review.

Without visibility into these exceptions, organizations may struggle to understand who has access to sensitive information and why. This challenge becomes increasingly important as organizations expand their use of Microsoft 365 and AI-powered experiences.

Because Microsoft 365 Copilot respects existing permissions, understanding where access differs from the expected folder structure can help organizations strengthen governance, improve confidence in search results, and better understand security exceptions across their content repositories.

The SharePoint Access Review skill provides a repeatable way to identify and document these differences without changing access or disrupting users.

The result is greater visibility into SharePoint permissions, stronger governance oversight, and more informed security reviews.

Prerequisites

  • Access to the target SharePoint site, library, folder, or selected content
  • Permission to retrieve file, folder, and permission metadata
  • Available permission information to support parent-child comparisons
  • Permission to generate and save Excel reports

 

Want to see it in action?

Try the skill in your SharePoint environment or connect with our team to explore how you can scale metadata, search, and content governance across Microsoft 365.