Start with the smallest affected scope and preserve the complete message. Many failures come from selection state, delegated SharePoint access, or a mismatch between configuration and the current site.
Collect diagnostic context
Before retrying, record:
- Date, time, and time zone.
- Signed-in account and tenant.
- Entry point: SharePoint command, web part, Teams tab, or browser app.
- Site URL, library, and affected path.
- Selected files or permission entries.
- Action attempted and complete error text.
- Any SharePoint request or support code.
- Whether the same account can complete the equivalent task directly in SharePoint.
Don't include passwords, tokens, or confidential file contents.
Commands are missing in SharePoint
| Symptom | Check |
|---|---|
| All Protect commands are missing | Confirm the solution is deployed tenant-wide or added to this site, then reload the modern library view. |
| Manage permissions disappears | Clear the selection or select no more than one row. The command is hidden for two or more selected rows. |
| Fill properties is missing | Select at least one file and remove every folder from the selection. |
| View approvals is missing | Select at least one file and remove every folder from the selection. |
| The web part isn't in the picker | Confirm the app is added to the site and search for both Protect and the package's configured title. |
Browser sign-in fails
- Confirm that you are using a Microsoft 365 work account.
- Open the tenant's SharePoint root directly with the same account.
- Select Try again in Protect.
- If sign-in loops, sign out of Protect, close duplicate sign-in tabs, and start again.
- Check whether conditional access, consent, browser storage, or tenant policy blocks the Microsoft identity flow.
- Expand Technical details and retain the complete message.
The browser app derives the SharePoint tenant root from the signed-in profile. If it can't determine or open that root, ask the Microsoft 365 administrator to confirm the user's SharePoint profile and access.
Sites are missing or fields keep loading
- Select Reset filters in the Sites view.
- Open the missing site directly in SharePoint.
- Return to Protect and reload the Sites view.
- Wait for background report fields to complete.
- Compare results with a representative account that should have access.
SharePoint can return partial site discovery or deny individual report fields. Unknown sharing or lock values mean that Protect didn't receive a definitive value; they don't prove a safe or unsafe configuration.
Permission rows are missing
- Confirm the breadcrumb points to the intended site and path.
- Clear search and select Reset filters.
- Select Refresh.
- Enable Load nested sharing entries if the missing assignment is on child content.
- Use the parent-source link when the expected assignment is inherited.
- Open the location directly in SharePoint and confirm the signed-in user can view its permissions.
Add is unavailable
Add is disabled at the site root and isn't shown in the browser app.
- Open Protect through Manage permissions in SharePoint.
- Navigate to a list, library, or folder below the site root.
- Confirm Protect Pro is active.
- Confirm the account can manage permissions at that path.
Edit or Remove is unavailable
- Select at least one actual permission entry, not an Add access placeholder.
- Confirm that the app shows the expected selected count.
- Confirm Protect Pro entitlement.
- Confirm the account can manage every selected location.
- Split a mixed bulk selection into one path at a time to identify the failing boundary.
After a successful write, select Refresh. A saved message doesn't automatically replace the currently loaded permission rows.
A permission write fails
- Retry the action on one entry.
- Verify whether the access comes from a group or inherited parent rather than a direct assignment.
- Open the affected location's native SharePoint permissions.
- Confirm the selected access level still exists.
- Confirm another owner remains when changing owner-level access.
- Record the exact path and SharePoint response.
Excel export isn't complete
Export contains the permission data loaded by Protect. Return to the intended site or folder, enable nested loading if required, wait for it to finish, and export again. Verify paths and principals in the workbook before using it as evidence.
Excel import contains invalid rows
| Status | Resolution |
|---|---|
| Checking path | Wait for cross-site validation to finish. |
| Path missing or Path not found | Use an existing site-relative path accessible to the signed-in account. |
| Member missing or Member not found | Use the exact title of a SharePoint group available in the target site. |
| Role missing or Role not found | Use the exact name of an existing SharePoint access level. |
| No rows after selection | Remove individual emails, guests, sharing links, system groups, and malformed paths; import supports group additions. |
Grant access stays disabled until every preview row is Ready. Blank workbook cells don't remove existing permissions.
Manage columns can't save
- Confirm Protect Pro entitlement.
- Confirm Manage Lists permission.
- Validate the JSON syntax in the JSON tab.
- Confirm every property uses an existing writable column's internal name.
- Use only the rules listed in Reference.
- Review existing list validation before saving.
- Check whether a target column has unmanaged validation that Protect refuses to replace.
If the generated list formula exceeds SharePoint's 1,024-character limit, simplify cross-column relationships. Protect can move independent value rules together to column validation, but it won't publish a weaker partial relationship.
Fill properties can't run
| Message or symptom | Resolution |
|---|---|
| A license message appears | Confirm Protect Pro entitlement. |
| Policy isn't configured | Create and save a policy with Manage columns. |
| No configured layout | Add a supported named-capture source pattern and destinations. |
| Validation is out of sync | Review any manual formula change, then save the policy again through Manage columns. |
| A row needs attention | Correct every required, choice, format, structure, and rename error. |
| The button stays disabled | Every selected row must be ready; process valid files separately if needed. |
| Some files fail during write | Confirm edit rights, checkout or lock state, column writability, and rename safety for each named file. |
Approval actions are disabled
| State or message | Resolution |
|---|---|
| A license message appears | Confirm Protect Pro entitlement. |
| Mixed approval states | Select files that all have one state. |
| Default approvers aren't configured | Configure the library's predefined approval settings. |
| Approve or Reject is disabled | Confirm the signed-in user can respond to every selected active approval. |
| Active approval ID couldn't load | Retry the affected file separately and record its support code. |
| Files are Approved or Rejected | Completed selections have no further bulk action. |
Contact support
Use the contact page and include the diagnostic context from the first section. State whether the issue affects all users, one user, one site, one library, or one item so support can isolate the authorization and configuration boundary.
