Protect Pro can write permission assignments to SharePoint under the signed-in user's identity. The user must also have permission to manage access at every affected location.
Before you change access
Confirm all of the following:
- The approved person or group.
- The exact site, library, list, folder, or file.
- The least SharePoint access level that supports the work.
- Whether the current access is inherited or custom.
- Whether the decision should be implemented through group membership instead.
- Whether a remaining owner or administrator is in place.
Grant access
The in-app Add command is available in the SharePoint-hosted permission explorer at a non-root location.
- Open the target list, library, or folder in SharePoint.
- Select Manage permissions.
- Verify the target path in the breadcrumb.
- Select Add.
- In the principal picker, select one user, SharePoint group, security group, or distribution list returned by SharePoint.
- In Access level, select one existing SharePoint permission level.
- Choose whether to notify the recipient.
- Select Grant access.
- Wait for the saved confirmation, then select Refresh.
- Confirm the principal, access level, location, and access source.
If Add is disabled, confirm that you aren't at the site root and that you opened Protect from its SharePoint-hosted experience.
Change access for selected entries
Use Edit when every selected entry should receive the same new access level.
- Filter the permission table until the intended entries are visible.
- Select each entry to change.
- Confirm the selected count in the command bar.
- Recheck every selected location and principal.
- Select Edit.
- In Choose access level, select the new SharePoint role.
- Select Change access level.
- Wait for the saved confirmation, then select Refresh.
- Confirm that the old role is gone and the new role appears.
Protect adds the selected role and removes the previous role when a change is required. A bulk selection can span different locations, so review each row before applying one role to all of them.
Remove selected entries
- Filter and select only the assignments approved for removal.
- Confirm whether each assignment is direct, group-based, link-based, inherited, or custom.
- Select Remove.
- Read the confirmation and select Remove access.
- Wait for the saved confirmation, then select Refresh.
- Confirm the resulting access and inheritance state.
When removal leaves no custom assignments at a supported boundary, Protect can restore inheritance from the parent. The resulting inherited entries might therefore differ from the removed custom entries.
Choose the correct remediation
| Finding | Preferred action |
|---|---|
| A person receives access through a SharePoint group | Change group membership on the native group page when the group assignment itself is still correct. |
| A Microsoft 365 group or Team is too broad | Review the connected group's membership and broader resource impact before changing site access. |
| A direct assignment duplicates group access | Remove the direct assignment after verifying the person retains the required group access. |
| A sharing link is no longer justified | Remove the link assignment only after confirming no active workflow depends on it. |
| A custom boundary is no longer needed | Remove approved custom entries and verify whether parent inheritance is restored. |
Verify and document the result
- Refresh the affected scope in Protect.
- Open the location directly in SharePoint.
- Test with a representative account for sensitive changes.
- Export the reviewed permission data when evidence is required.
- Record the approver, business reason, date, affected paths, and review reference in your organization's system of record.
