TechRam For IT Leaders

How do you find out who can actually access a SharePoint site?

Access to a SharePoint site comes from four places at once: site groups, Microsoft 365 group membership, sharing links, and permissions inherited from a parent. The admin centre shows each separately, so answering who can reach a site means resolving all four together rather than reading one.

Many access points converging on a single document, showing how many routes lead to one file

Four places permission comes from

Ask an administrator who can reach a site and you’ll usually get the site’s permission groups. That’s one of four answers, and on its own it’s close to useless.

SourceWhat it grantsWhere you see it
Site groupsOwners, Members, Visitors on that siteSite permissions
Microsoft 365 groupEveryone in the connected group, including guestsEntra ID / Teams
Sharing linksWhoever holds the URL, depending on link typeEach item, individually
InheritanceWhatever the parent granted, unless brokenAdvanced permissions

A person can reach a document through any one of these, and the four don’t appear on the same screen. That’s the whole problem.

Why the admin centre won’t answer it

The Microsoft 365 admin centre is built to show you what was configured. The question “who can reach this” is a different shape: it’s the resolved union of four systems, and resolving it means walking every site, every library and every item with unique permissions.

Nobody does that by hand twice. It’s why the answer in most organisations is a shrug, and why the answer matters more than it used to — Copilot surfaces what a user can already see, so an unknown permission model is now an unknown AI blast radius.

The order to work it out in

1. Start with the sharing links, not the groups. An “Anyone with the link” URL needs no sign-in and no account. It works for whoever holds it, including whoever it was forwarded to. These are the permissions that don’t appear in any group listing at all.

2. Then the Microsoft 365 group. If the site is Teams-connected, everyone in that team is a member of the site, and guests in the team are members too. This is the one that surprises people: nobody granted them site access directly.

3. Then broken inheritance. Any library or folder where inheritance was broken has its own permission set, frozen at whatever it was when somebody broke it. These drift silently for years.

4. Groups last. By the time you get here, the site groups are usually the part that’s correct.

What a clean answer looks like

For each site: a named owner, access granted by group rather than by individual, no unique permissions below the library level, and a list of external links with an expiry on each.

That isn’t a tidier version of what you have. It’s a different model, and getting there is a remediation project rather than a settings change — which is what Governance & Cleanup is.

Where to start without committing to anything

The Permission Visualiser resolves the four sources for one site and shows which one grants each person their access. Ask for it on the page and we’ll send the package and the setup notes.

If you want the whole estate rather than one site, that read is the Environment Baseline: two to three weeks, read-only, ending in a prioritised plan you own.

The tool this article is about Permission Visualiser Shows who can actually reach a site, and by which group, link or inherited permission. Request access →

The service behind this: Governance & Cleanup →

Common questions

01. Why doesn't the Microsoft 365 admin centre answer this?

It's built to show what was configured. Who can reach a site is the resolved union of four separate systems, and resolving it means walking every site, every library and every item with unique permissions.

02. Which of the four permission sources should you check first?

Sharing links. An “Anyone with the link” URL needs no sign-in and no account, it works for whoever holds it including whoever it was forwarded to, and it appears in no group listing at all.

03. Why do Teams-connected sites catch people out?

If the site is Teams-connected, everyone in that team is a member of the site, and guests in the team are members too. Nobody granted them site access directly, so nothing in the site's own permissions records the decision.

04. What does a site with a clean permission model look like?

A named owner, access granted by group rather than by individual, no unique permissions below the library level, and a list of external links with an expiry on each. That's a different model, not a tidier version of what you have.

Victor Khalil

Co-founder — CTO

LinkedIn

Run the Permission Visualiser on your own tenant first.

It deploys into the Microsoft 365 tenant you already pay for, on the licences you already hold, and nothing leaves your environment.

Request access →