TechRam For IT Leaders
How do you find out who can actually access a SharePoint site?
Access to a SharePoint site comes from four places at once: site groups, Microsoft 365 group membership, sharing links, and permissions inherited from a parent. The admin centre shows each separately, so answering who can reach a site means resolving all four together rather than reading one.
Four places permission comes from
Ask an administrator who can reach a site and you’ll usually get the site’s permission groups. That’s one of four answers, and on its own it’s close to useless.
| Source | What it grants | Where you see it |
|---|---|---|
| Site groups | Owners, Members, Visitors on that site | Site permissions |
| Microsoft 365 group | Everyone in the connected group, including guests | Entra ID / Teams |
| Sharing links | Whoever holds the URL, depending on link type | Each item, individually |
| Inheritance | Whatever the parent granted, unless broken | Advanced permissions |
A person can reach a document through any one of these, and the four don’t appear on the same screen. That’s the whole problem.
Why the admin centre won’t answer it
The Microsoft 365 admin centre is built to show you what was configured. The question “who can reach this” is a different shape: it’s the resolved union of four systems, and resolving it means walking every site, every library and every item with unique permissions.
Nobody does that by hand twice. It’s why the answer in most organisations is a shrug, and why the answer matters more than it used to — Copilot surfaces what a user can already see, so an unknown permission model is now an unknown AI blast radius.
The order to work it out in
1. Start with the sharing links, not the groups. An “Anyone with the link” URL needs no sign-in and no account. It works for whoever holds it, including whoever it was forwarded to. These are the permissions that don’t appear in any group listing at all.
2. Then the Microsoft 365 group. If the site is Teams-connected, everyone in that team is a member of the site, and guests in the team are members too. This is the one that surprises people: nobody granted them site access directly.
3. Then broken inheritance. Any library or folder where inheritance was broken has its own permission set, frozen at whatever it was when somebody broke it. These drift silently for years.
4. Groups last. By the time you get here, the site groups are usually the part that’s correct.
What a clean answer looks like
For each site: a named owner, access granted by group rather than by individual, no unique permissions below the library level, and a list of external links with an expiry on each.
That isn’t a tidier version of what you have. It’s a different model, and getting there is a remediation project rather than a settings change — which is what Governance & Cleanup is.
Where to start without committing to anything
The Permission Visualiser resolves the four sources for one site and shows which one grants each person their access. Ask for it on the page and we’ll send the package and the setup notes.
If you want the whole estate rather than one site, that read is the Environment Baseline: two to three weeks, read-only, ending in a prioritised plan you own.
The service behind this: Governance & Cleanup →
Common questions
01. Why doesn't the Microsoft 365 admin centre answer this?
It's built to show what was configured. Who can reach a site is the resolved union of four separate systems, and resolving it means walking every site, every library and every item with unique permissions.
02. Which of the four permission sources should you check first?
Sharing links. An “Anyone with the link” URL needs no sign-in and no account, it works for whoever holds it including whoever it was forwarded to, and it appears in no group listing at all.
03. Why do Teams-connected sites catch people out?
If the site is Teams-connected, everyone in that team is a member of the site, and guests in the team are members too. Nobody granted them site access directly, so nothing in the site's own permissions records the decision.
04. What does a site with a clean permission model look like?
A named owner, access granted by group rather than by individual, no unique permissions below the library level, and a list of external links with an expiry on each. That's a different model, not a tidier version of what you have.