Skip to Content
SharePointBroken Permission Inheritance Audit (exceptions)

Broken Permission Inheritance Audit

TL;DR: This skill is an object-level exception audit: it finds every SharePoint Online library, folder or item where permission inheritance is broken and ranks each by access scope and content sensitivity, so owners can restore inheritance or formalise the exception. It is not a site-level snapshot.

What does the broken permission inheritance audit do?

The audit identifies every site, library, folder, or item in scope where SharePoint Online permission inheritance has been broken, evaluates the access scope of the resulting unique permissions, and ranks each finding by risk. Site-level breadth, owners and broad-access groups are out of scope here; the Site Permissions Baseline covers those. Site owners can then decide whether to restore inheritance or formally document the exception. The data is read through Microsoft Graph, and Microsoft Purview sensitivity labels are captured to weigh the exposure of each broken-inheritance object. Broken inheritance is the leading cause of oversharing surprises, so this audit is essential Copilot-readiness work: restoring least-privilege at the data layer is what keeps Microsoft 365 Copilot answers trustworthy and scoped to what each user should see.

When should you run this skill?

  • “Find broken permission inheritance in SharePoint”
  • “Audit unique permissions across our sites”
  • “Surface item-level permission drift”
  • “Review where inheritance was broken in the last review window”

How this skill works, step by step

  1. Enumerate sites in scope (or a named site).
  2. For each site walk the object hierarchy: site, lists / libraries, folders, items.
  3. Identify objects where inheritance is broken (unique permissions present).
  4. For each broken-inheritance object capture: object path, principals with access, permission level, sensitivity label of contents.
  5. Calculate access scope: count of users with effective access through the unique permissions.
  6. Compute risk score: High (external principals or Anyone with Restricted content), Medium (broad internal access), Low (single delegated owner).
  7. Produce the table below.

Output format

SiteObject PathObject TypePrincipalsPermission LevelScopeSensitivityRisk

Followed by a summary:

  • Sites scanned: N
  • Objects with broken inheritance: N
  • High risk: N (requires immediate review)
  • Recommended remediation order

Scope and safety

This skill is read-only by default and takes no destructive actions. It does NOT:

  • Restore inheritance or remove permissions (read-only)
  • Modify sharing links
  • Read file contents

Licensing and permissions

Licences and add-ons

Capability usedMinimum licence
Read SharePoint sites, libraries, items and unique permissions via Microsoft GraphMicrosoft 365 E3 (or Office 365 E3)
Read Microsoft Purview sensitivity labels on contentMicrosoft 365 E3
Site-level Data Access Governance and oversharing reports at scaleSharePoint Advanced Management (included in Microsoft 365 E5 or as an add-on)

Least-privilege roles

  • Global Reader — tenant-wide read-only visibility for the audit
  • SharePoint Administrator (read) — where site-level permission detail or SharePoint Advanced Management reports are needed

Microsoft Graph permissions (read-only)

  • Sites.Read.All — enumerate sites, lists, libraries and folders in scope
  • Files.Read.All — read item metadata and identify objects with unique permissions
  • Group.Read.All — resolve group principals granted access through broken inheritance
  • Directory.Read.All — resolve user and directory principals on unique permissions
  • InformationProtectionPolicy.Read.All — read the Purview sensitivity label definitions applied to content

When should I run this instead of the Site Permissions Baseline?

Run this audit when you need to know exactly which libraries, folders or items have unique permissions and how risky each one is. Run the Site Permissions Baseline when you need a per-site snapshot of broad access, owners and a broken-scope count. If you need both, run the baseline first to find the sites worth drilling into, then run this audit on those sites.

Sources and compliance

  • Pair with External Sharing Deep Audit and SharePoint Oversharing Audit for a complete access posture view
  • Re-run before any Microsoft 365 Copilot rollout — broken inheritance is the leading cause of oversharing surprises
  • Check permissions on a SharePoint site 

Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-06-02

Last updated on