Skip to content
DocumentationContact
Protect

See who viewed files in SharePoint

Learn how to see who viewed a file in SharePoint using SharePoint Viewers for quick checks and Microsoft Purview Audit for compliance-grade tracking.

Track document access in SharePoint and Teams

If you need a quick answer, use SharePoint Viewers on the file card.

If you need audit evidence for compliance or investigations, use Microsoft Purview Audit.

If you're checking a sensitive document, the next question is who can still access it. Protect Free brings people, groups, sharing links, and access levels into one permission view, with an Excel export you can share with the owner.

Get Protect Free to review current SharePoint access, or jump to the access-review workflow below.

Microsoft provides two primary options:

  • SharePoint Viewers on the file card (user-facing)
  • Microsoft Purview Audit (admin/compliance-grade auditing)

You can also use file activity in a document library for recent changes.

Option 1: Enable and use SharePoint Viewers

Microsoft’s official feature is called SharePoint Viewers. After activation, users can see viewers and view counts on the file card.

Enable SharePoint Viewers

  1. Open your SharePoint site.
  2. Select Settings (top-right) > Site information.
  3. Select View all site settings.
  4. Under Site Actions, select Manage site features.
  5. Find SharePoint Viewers and select Activate.

If you don’t see Site information, you don’t have permission to manage this setting.

See who viewed a file/page

  1. Go to the document or pages library.
  2. Point to a file/page to open the file card.
  3. Check Viewers and Views (names/photos and totals).

Microsoft states that when this feature is enabled, historical viewer data can appear, including views collected while the feature was previously off.

The file card is only visible to people who already have access to the file, and content in the card is personalized to the viewer.

Option 2: Check file activity in the document library

Use this for quick, recent activity directly in a library.

  1. Open the document library.
  2. Select Open the details pane.
  3. Select More details at the bottom of the pane to open Activity.
  4. Review the latest file/library activities.

Microsoft documents this activity as recent changes such as created/edited/deleted and says activity is available for the last 60 days.

Site usage reports are useful for trends (for example, popular content, unique viewers, and total visits), not for detailed compliance investigations. Microsoft notes individual names are shown in the library hover card when SharePoint Viewers is enabled, not on the Site Usage page.

Option 4: Use Microsoft Purview Audit for full auditing

For exact forensic/compliance tracking (who, when, IP, operation), use Microsoft Purview Audit.

Official prerequisites

  • You need the Audit Logs or View-Only Audit Logs role.
  • Audit log search is on by default for Microsoft 365/Office 365 enterprise organizations.
  • Retention depends on licensing:
    • Audit (Standard): typically 180 days
    • E5 / Audit Premium-related licensing: up to 1 year by default for key workloads (including SharePoint)

How to search SharePoint file access events

  1. Open the Microsoft Purview portal.
  2. Open Audit.
  3. Configure search criteria:
    • Date/time range (UTC)
    • Activities
    • Users (optional)
    • File, folder, or site (file name/path/URL)
    • Workloads (include SharePoint)
  4. Run search and inspect results for user, activity, IP, and item details.

Recommended search approach for larger environments:

  • Start with a narrow UTC date range and one site path.
  • Use File, folder, or site with a full or partial URL/path.
  • Add Users only if needed after the first result set.
  • Use export after filtering to keep reports focused.

Microsoft notes audit records for core services are typically available within 60–90 minutes, but this isn't guaranteed.

In Purview Audit search UI, the maximum date range per search is 180 days.

Review current access with Protect

After checking a file's viewing history, review the permissions that could allow the next person to open it. A project owner might recognize a viewer but still need to check whether a former contractor, a broad group, or a sharing link retains access.

Protect keeps the content location, principal, access level, and permission source together, so you can move from a concern to a specific access decision.

Your next task How Protect helps Plan
Understand current exposure Review people, groups, and sharing links; distinguish inherited and custom access. Free
Give the owner a review record Export the loaded permission matrix to Excel. Free
Apply an approved decision Change or remove eligible selected permission entries, then refresh and verify the result. Pro

Once your administrator has deployed Protect, start with the affected folder or library:

  1. Open the location in SharePoint and select Manage permissions.
  2. Confirm the site and folder in the breadcrumb.
  3. Select Load nested sharing entries if the review includes files or subfolders.
  4. Review Item, Shared with, Access level, and Location together. Use Access source to separate inherited and custom entries.
  5. Select Export to Excel to give the owner a record of the loaded permissions.
  6. If a change is approved, use Protect Pro's permission actions and verify the resulting access.

Protect reviews current permissions. It does not provide file-view history or replace Microsoft Purview Audit. Every review and change uses your existing SharePoint permissions.

Optional: Custom logging with Power Automate

Power Automate can capture and store events based on available triggers/actions, but it is not a replacement for Purview audit in compliance scenarios.

Troubleshooting: why viewer data may be missing

If names or counts don’t appear as expected:

  1. Confirm SharePoint Viewers is activated on the site feature page.
  2. Wait a few minutes after activation before testing.
  3. Validate permissions: users without access won’t see file card insights.
  4. Check where you’re looking: individual names appear in the library hover card, not Site Usage.
  5. For audit searches, allow for ingestion delay (commonly 60–90 minutes) and verify role assignments.

Known limits

  • Site Usage is aggregate analytics and does not show per-viewer identity on the Site Usage page.
  • Site Usage can exclude the most recent 60 minutes of activity.
  • Purview audit record availability is not guaranteed at an exact time.
  • If a third-party tool renders PDFs from SPO libraries, those views may not be recorded in file view statistics or reflected in audit log file view stats.

FAQ

Why don’t I see viewer names on a file?

Check whether SharePoint Viewers is activated for the site, then wait a few minutes and test again from the library hover card.

Do PDF views always appear in SharePoint usage or audit data?

Not always. Microsoft notes that if a third-party tool renders PDFs from SharePoint Online libraries, those views may not be recorded in file view statistics and may not be reflected in audit log file view stats.

What do I need to search who accessed a file in Purview?

You need the Audit Logs or View-Only Audit Logs role and enough retention coverage for your selected date range.

Which option should I use first?

Use SharePoint Viewers for a quick check. Use Microsoft Purview Audit when you need traceable audit evidence.

Next steps

Make the investigation useful beyond a single file: review the containing library, give its owner an access report, and identify assignments that need a decision.

Start your access review with Protect Free. Permission visibility and Excel export are included. Start with one library using the first-review guide.

Need to apply the decisions? Compare Protect Free and Pro. For an organization-wide review, discuss your SharePoint access-review workflow with our team.

Protect requires SharePoint Online, a Microsoft 365 work account, and administrator deployment. See deployment steps and security and data boundaries.

Microsoft official references

Last verified: 2026-02-20

Was this page helpful?