Skip to content
DocumentationContact
Protect

Explore permissions and sharing links

Interpret principals, access levels, capabilities, locations, and inheritance, then isolate entries that need a decision.

Each permission row keeps the content item, principal, access level, and location together. Review all four before deciding whether access is appropriate.

To check who actually opened a document, see See who viewed files in SharePoint. Permission assignments show who can access content; SharePoint Viewers and Microsoft Purview Audit show viewing activity.

Read a permission row

Column What it shows
Item The site, document library, folder, file, or list that was evaluated. Select a linked item to load that scope.
Shared with A person, guest, SharePoint group, Microsoft 365 group or Team, security group, distribution list, or sharing link.
Access level The assigned SharePoint role and icons for resulting capabilities.
Location The SharePoint path where the entry applies. Select it to open that location.

For SharePoint groups, Protect can show member pictures and names for the first visible members plus a count for the remainder. Group membership, not the permission row itself, controls which people receive that group access.

Interpret capability icons

Protect translates a returned access level into practical capabilities where possible:

Capability Meaning
View Open or read content.
Download Download a copy.
Upload Add content.
Edit Change existing content or properties.
Approve Participate in supported approval actions.
Share Create or manage sharing.
Delete Delete supported content.

Capability icons help compare custom roles, but the SharePoint permission-level definition remains authoritative. Select Access levels to open the current site's native role definitions.

Identify principal types

Use Shared with filters to separate:

  • Internal person and Guest direct assignments.
  • SharePoint group assignments managed at the site.
  • Microsoft 365 group or Team assignments that can affect other group-connected resources.
  • Security group and Distribution list entries managed outside the permission row.
  • People in your organization with the link, People you choose, and Anyone with the link sharing entries.

Anyone links can work without sign-in and normally warrant the most deliberate review. Organization links require an authenticated person in the tenant. Specific-people links are restricted to their named recipients.

Distinguish inherited and custom access

Inherited access comes from a parent scope. Custom access means the item has its own permission boundary.

  1. In Access source, select Items with inherited access or Items with custom access.
  2. For an inherited row, use the parent-source link to inspect where the assignment originates.
  3. For a custom item, review every entry required at that boundary.
  4. Don't remove an inherited row at a child location when the actual decision belongs at the parent.

Load nested entries

  1. Start with the current shallow scope.
  2. Narrow to the site, library, or folder that needs review.
  3. In Load, select Load nested sharing entries.
  4. Wait until detailed loading completes.
  5. Filter by item type, principal type, access level, location, or source.
  6. Clear the checkbox to return to shallow results.

Run a focused external-access review

  1. Select Guest, People you choose, and Anyone with the link under Shared with.
  2. Select the high-impact access levels relevant to your organization.
  3. Select Items with custom access.
  4. Use search to locate a known person, project, or path when needed.
  5. Review the principal, capability icons, permission source, and location.
  6. Export the loaded permission data or send an approved remediation decision to the site owner.
Was this page helpful?