Microsoft 365

SharePoint permissions audit: Which evidence do you need?

GovernSafe Team
Published
Last reviewed
7 min read
GovernSafe

You have a report showing guest permissions on a SharePoint site. Your audit search returns no matching sharing event. Check what each source covers and when it was collected before drawing a conclusion about access.

For a SharePoint permissions audit, write down the question first. Do you need to establish reported access at a particular time, investigate how someone shared a resource, or document whether access still has a business reason? Each question needs different evidence. Combining the answers takes care, especially when the dates do not line up.

Choose evidence for the question

EvidenceQuestion answeredEvidence and time scopeLimits and next verification
Permission snapshotWhat permission state did this report capture?A dated view of reported permissions within the report's coverage.Check lag, exclusions and export scope. Verify the relevant access before making a current-state decision.
Sharing-event historyWhat sharing activity was recorded?Events returned for the chosen search period and criteria.Read the event type and context. A past event does not establish that access persists today.
Human review recordWhat did the reviewer decide, and why?Your record of the evidence considered and decision made at the review time.A decision is not proof that someone executed a change. Record unresolved questions and the next check.

A SharePoint Online permissions audit can use all three. Keep their conclusions separate in the review record so another person can follow how you reached the decision.

Check the report's prerequisites and coverage

Microsoft's site-permissions snapshot requires SharePoint Advanced Management (SAM). Confirm an eligible Microsoft 365 or Office 365 base subscription and the applicable SAM entitlement. Microsoft's prerequisites describe qualifying Copilot access and SAM add-on routes. The administrator also needs an appropriate role, such as SharePoint Administrator or SharePoint Advanced Management Administrator. Owning a Microsoft 365 subscription alone does not establish availability. Check the current SAM prerequisites for your tenant.

The snapshot can lag behind changes. Record its stated reporting date, generation details and your collection time separately. Microsoft excludes archived sites and sites locked with NoAccess. The portal's ranked site view is a subset; the downloadable CSV covers a wider set of sites within the report's limits. Its guest-permission count is not a named guest list. Use the snapshot documentation to interpret the fields before treating an omitted site or a summary total as a conclusion.

Read the sharing event before interpreting it

Microsoft distinguishes several actions in its sharing audit guidance:

  • SharingInvitationCreated records an invitation that does not yet grant access. SharingInvitationAccepted records acceptance and access being assigned through that invitation flow.
  • Sharing with someone who already has a guest account can assign permissions immediately and produce AddedToGroup and SharingSet events. Do not assume every guest must accept a new invitation.
  • AnonymousLinkCreated records creation of an Anyone link. AnonymousLinkUsed records its use. Creating a link does not demonstrate that somebody opened the resource.
  • SecureLinkCreated records a specific-people link. AddedToSecureLink identifies a person added to it; those records should not be treated as evidence of use.

Use the event name to identify the recorded action. Read the resource, actor, target and time in context, then verify current permissions separately.

Treat missing events as an open question

Before relying on a search, confirm audit ingestion is enabled and the search has completed. Search requires the Audit Logs or View-Only Audit Logs role. Event availability can lag, and Microsoft does not guarantee a fixed ingestion time. Check the UTC date range, exact activities and other filters against the question. Follow Microsoft's audit search guidance.

Also check the administrator's visibility. Administrative-unit assignments can restrict what the reviewer can search. A search made with restricted visibility cannot establish an organization-wide absence of activity.

Keep three time limits distinct: the period requested by a search, how long its completed search job remains available, and retention of the underlying audit events. The first two are search mechanics; event retention depends on applicable licensing and policies. See audit search and the Audit overview. SharePoint content retention concerns retaining or deleting content, so it should not be used as a promise about available sharing history.

When no matching event appears, record that result and its limits. Do not convert it into "no access" or invent an explanation for the gap.

A synthetic review of Site A

This example is synthetic. Site A, Guest A and Reviewer A are invented labels; the record below is an illustrative working record, not a Microsoft report or universal control requirement.

At T1, a snapshot reports guest permissions on Site A. Reviewer A collects it later, at T2, alongside a completed sharing-event search covering Window B, a different period. That search has no matching result. Guest A is a person the reviewer has been asked to investigate, but the snapshot's aggregate count does not identify them.

The supported conclusion is limited: the snapshot reported guest permissions at T1; this search has not established their historical origin. Guest A's current access and the reason for any continuing access still need verification.

Review fieldIllustrative entry
ScopeSite A within Organization A; Guest A is the person under review.
QuestionWhat guest access needs explanation, and can Guest A currently access the relevant resource?
Source referenceSnapshot A and completed sharing search B, retained with their settings.
Report or event periodSnapshot point T1; event search Window B. These periods differ.
Collection timeT2 for both evidence items; source dates retained separately.
Known gapsHistorical origin unestablished; aggregate count does not identify Guest A; current access unverified.
ReviewerReviewer A.
Decision and statusOpen, pending current verification and a business-owner decision. No removal recorded.
RationaleThe available evidence does not support closing the question or attributing access to Guest A.
Next checkVerify Guest A's current access through an authorized review, check search coverage, and ask the responsible owner to decide any required action.

If the next check confirms access, add the evidence and decision. If it leaves a gap, keep that gap visible. Do not label a proposed action as completed remediation.

Direct-team and MSP reviews have different owners

For an Australian IT or security team reviewing its own organization, start with the site and the business question that prompted the review. Ask the responsible business owner why access is needed. Set a follow-up date that fits your organization's policy and the unresolved issue. This example does not prescribe an Australian legal requirement or review frequency.

For an MSP or adviser, keep one client scope and approval owner per record. Agree who supplies evidence, who evaluates it and who can authorize action. A completed review for Client A says nothing about Client B's access. If a client's source is unavailable, name that gap in its report without holding up an independent, adequately evidenced client review.

Where GovernSafe fits

GovernSafe's Microsoft 365 governance guide describes supported tenant data, client-scoped analytics, findings and recommendations with evidence for human review. Coverage depends on the configured connector, data and workflow. Discuss the evidence your team needs and verify that the supported workflow fits that scope. This is not a promise of exhaustive SharePoint permissions coverage or automatic revocation.

Source notes

Sources checked on 8 September 2026. Documentation can change; recheck the relevant source before conducting a review. These sources explain Microsoft behavior and GovernSafe's public scope. The synthetic example reports no customer assessment or tenant action.

Tags:Microsoft 365SharePointPermissionsHuman review

Talk to GovernSafe

Ready to see it on your stack?

Show us the cloud problem. We will walk through the GovernSafe workflow that fits it.