Protect combines SharePoint-hosted commands with a permission-review app. Availability depends on where you open Protect, the selected content, your Protect plan, and your existing SharePoint authorization.
Platform requirements
- A Microsoft 365 work account.
- SharePoint Online and a modern SharePoint list or document library for command-bar features.
- A supported modern browser allowed by your organization's Microsoft 365 and conditional-access policies.
- The Protect SharePoint Framework package deployed to the target scope.
- A SharePoint page or Teams tab containing the Protect web part when you use those entry points.
Protect doesn't require custom script on a site.
Feature availability
| Feature | Where to open it | Plan | Additional requirement |
|---|---|---|---|
| Sites overview | Web part, Teams tab, or browser app | Free or Pro | Access to the sites that SharePoint returns |
| Review and filter permission entries | Manage permissions, web part, Teams tab, or browser app | Free or Pro | Read access to the target content and permission information |
| Export to Excel | Permission explorer | Free or Pro | Permission data must be loaded |
| Grant access | Manage permissions in SharePoint | Pro | A non-root site location and permission to manage access there |
| Change or remove access | Permission explorer | Pro | One or more eligible permission rows selected and permission to manage the affected locations |
| Import group access from Excel | Permission explorer | Pro | Exact paths, SharePoint group names, and access-level names |
| Manage metadata policy | Manage columns in a SharePoint library | Pro | Manage Lists permission and existing destination columns |
| Fill properties | Fill properties in a SharePoint document library | Pro | One or more files selected and a valid policy with a fill layout |
| Request, approve, or reject | View approvals in a SharePoint document library | Pro | One or more files selected and compatible approval state and settings |
| Enterprise governance template rollout | Protect rollout workflow | Pro | Approved template, target-site inventory, rollout owner, pilot scope, and exception process |
SharePoint authorization
Protect doesn't define a second permission model. SharePoint evaluates every read and write request under the signed-in user's identity.
| Task | SharePoint access to confirm |
|---|---|
| Open a site or file | The account can open the same content directly in SharePoint. |
| Read permission entries | The account can view the target content and its sharing or permission information. |
| Grant, change, or remove access | The account can manage permissions on every affected location. |
| Change a library policy | The account has Manage Lists for that library. |
| Fill document properties | The account can edit the selected items and every configured destination column. |
| Rename from a policy | The account can edit and rename the selected files. |
| Respond to an approval | The approval record allows the signed-in user to respond. |
Selection requirements
SharePoint shows or hides command-extension actions according to the current selection:
- Manage permissions is visible when fewer than two rows are selected. With no selection, it opens the current folder or library; with one selection, it still opens the current location.
- Manage columns is visible in the supported list or library view and manages the current library policy.
- Fill properties is visible only when every selected row is a file and at least one file is selected.
- View approvals follows the same file-only selection rule.
- Edit and Remove in the permission explorer require one or more non-placeholder permission entries.
Folders aren't accepted by Fill properties or View approvals.
Free and Pro behavior
Free supports discovery, permission review, filters, site signals, Excel export, native-setting shortcuts, metadata-policy previews, Fill properties previews, and approval-status review. Pro unlocks every Protect editing action: grant, bulk access-level changes, bulk removal, Excel-based group-access additions, metadata-policy publishing, Fill properties and policy-based renaming, and request, approve, or reject approval actions.
If a Pro-only action is selected without an active entitlement, Protect starts the subscription or licensing flow instead of writing to SharePoint.
Confirm readiness
- Open the target site directly in SharePoint with the account that will use Protect.
- Open Protect through the intended entry point.
- Load a known site and confirm that its permission entries appear.
- If the user will make changes, test one approved action on non-production content.
- Refresh the scope and verify the result in both Protect and SharePoint.
