Skip to content
DocumentationContact
Protect

Grant, change, or remove access

Apply Protect Pro permission changes with exact scope, selection, inheritance, and verification steps.

Protect Pro can write permission assignments to SharePoint under the signed-in user's identity. The user must also have permission to manage access at every affected location.

Before you change access

Confirm all of the following:

  • The approved person or group.
  • The exact site, library, list, folder, or file.
  • The least SharePoint access level that supports the work.
  • Whether the current access is inherited or custom.
  • Whether the decision should be implemented through group membership instead.
  • Whether a remaining owner or administrator is in place.

Grant access

The in-app Add command is available in the SharePoint-hosted permission explorer at a non-root location.

  1. Open the target list, library, or folder in SharePoint.
  2. Select Manage permissions.
  3. Verify the target path in the breadcrumb.
  4. Select Add.
  5. In the principal picker, select one user, SharePoint group, security group, or distribution list returned by SharePoint.
  6. In Access level, select one existing SharePoint permission level.
  7. Choose whether to notify the recipient.
  8. Select Grant access.
  9. Wait for the saved confirmation, then select Refresh.
  10. Confirm the principal, access level, location, and access source.

If Add is disabled, confirm that you aren't at the site root and that you opened Protect from its SharePoint-hosted experience.

Change access for selected entries

Use Edit when every selected entry should receive the same new access level.

  1. Filter the permission table until the intended entries are visible.
  2. Select each entry to change.
  3. Confirm the selected count in the command bar.
  4. Recheck every selected location and principal.
  5. Select Edit.
  6. In Choose access level, select the new SharePoint role.
  7. Select Change access level.
  8. Wait for the saved confirmation, then select Refresh.
  9. Confirm that the old role is gone and the new role appears.

Protect adds the selected role and removes the previous role when a change is required. A bulk selection can span different locations, so review each row before applying one role to all of them.

Remove selected entries

  1. Filter and select only the assignments approved for removal.
  2. Confirm whether each assignment is direct, group-based, link-based, inherited, or custom.
  3. Select Remove.
  4. Read the confirmation and select Remove access.
  5. Wait for the saved confirmation, then select Refresh.
  6. Confirm the resulting access and inheritance state.

When removal leaves no custom assignments at a supported boundary, Protect can restore inheritance from the parent. The resulting inherited entries might therefore differ from the removed custom entries.

Choose the correct remediation

Finding Preferred action
A person receives access through a SharePoint group Change group membership on the native group page when the group assignment itself is still correct.
A Microsoft 365 group or Team is too broad Review the connected group's membership and broader resource impact before changing site access.
A direct assignment duplicates group access Remove the direct assignment after verifying the person retains the required group access.
A sharing link is no longer justified Remove the link assignment only after confirming no active workflow depends on it.
A custom boundary is no longer needed Remove approved custom entries and verify whether parent inheritance is restored.

Verify and document the result

  1. Refresh the affected scope in Protect.
  2. Open the location directly in SharePoint.
  3. Test with a representative account for sensitive changes.
  4. Export the reviewed permission data when evidence is required.
  5. Record the approver, business reason, date, affected paths, and review reference in your organization's system of record.
Was this page helpful?