Skip to Content
SharePointSite Permissions Baseline (snapshot)

Site Permissions Baseline

TL;DR: This skill takes a site-level snapshot of SharePoint permissions: how many people can reach each site, who has broad access, who administers it, and how many items have unique permissions. It is a least-privilege baseline for Microsoft 365 Copilot; item-by-item listing is the audit’s job.

What does the site permissions baseline capture?

This skill builds a per-site permissions snapshot from the Data access governance “Site permissions for your organization” report in the SharePoint admin centre. For each site it records the unique number of users with access, guest and external participant permissions, Microsoft Entra group permissions, “Everyone except external users” (EEEU) and “Everyone” permission counts, sharing link counts, the primary admin, and the count of items with unique permissions. It does not list or rank those items; the Broken Permission Inheritance Audit does that. Because Microsoft 365 Copilot respects existing permissions, sites with broad access are where unexpected content can surface. The baseline is a defensible starting point for ongoing governance. It reads permission data only and changes no permission.

When should you run this skill?

  • “Give me a permissions baseline for our SharePoint sites”
  • “Who has excessive access across our sites?”
  • “List site primary admins and broad-access groups”
  • “Snapshot permissions before our least-privilege project”
  • “Which sites have the most items with unique permissions?”

How this skill works, step by step

  1. Confirm licensing and roles (see below), then open Reports > Data access governance in the SharePoint admin centre, or use Start-SPODataAccessGovernanceInsight from SharePoint Online PowerShell.
  2. Create the “Site permissions for your organization” report (SharePoint and OneDrive are reported separately), or download the latest one as CSV.
  3. Flag sites with high user counts, EEEU, Everyone, guest or Anyone-link permissions.
  4. Record the Primary admin column for each site and, as this skill’s own check, note sites where it is blank or the account is disabled.
  5. Record the “Items with unique permissions” count per site, as a count only; object-level listing is left to the audit.
  6. Score each site by breadth of access, unique-permission count and ownership health (this scoring is the skill’s own method, not a Microsoft metric).
  7. Assemble the per-site snapshot.
  8. Output the baseline without altering any permission.

Output format

The skill returns a per-site permissions table, one row per site. Figures below are illustrative only.

SitePrimary adminBroad-access principalsItems with unique permissionsRiskRecommended action
Finance HubNamedEEEU permissions present14HighTighten access, run inheritance audit
HR PoliciesNamedNone1LowDocument exception
Legacy ArchiveNone recordedEveryone permissions present31HighAssign owner, run inheritance audit

Summary (illustrative):

  • Total sites baselined
  • Sites with EEEU, Everyone or guest permissions
  • Sites with unique permissions (count only)
  • Sites with no primary admin recorded (this skill’s own check, not a report metric)
  • High risk

Scope and safety

This skill is read-only by default. The only thing it creates is the report itself in the SharePoint admin centre; it makes no changes to permissions, ownership or inheritance.

This skill does NOT:

  • Add, remove or modify any permission assignment.
  • Restore inheritance or break additional scopes.
  • Reassign or add site owners.
  • Change group membership or access levels.

Report coverage limits to state in the baseline:

  • The first report takes up to 5 days; later reports complete within 24 hours, and you can run a report every 30 days.
  • Data can be up to 48 hours old.
  • Sites with a NoAccess lock status and archived sites are excluded.
  • The reports are unavailable for Microsoft 365 operated by 21Vianet.

Licensing and permissions

Licences and add-ons

RequirementDetail
Base subscriptionOffice 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD
SharePoint Advanced ManagementAt least one user assigned a Microsoft Copilot licence, or, where the subscription includes SharePoint K, P1 or P2, the SharePoint Advanced Management Plan 1 add-on, or Microsoft 365 E7
Microsoft 365 E5 onlyGives access to Data access governance activity reports but not the snapshot reports or remedial actions, so E5 alone cannot run this skill

Least-privilege roles

  • SharePoint Administrator
  • SharePoint Advanced Management Administrator (includes all SharePoint Administrator capabilities plus advanced governance features)

Microsoft Graph permissions (optional, read-only)

  • Sites.Read.All: least-privileged permission for the Graph list and list-item permission reads (List permissions on a list). The site-level List permissions API lists only Sites.FullControl.All, so do not rely on Graph for site-level permissions; use the report

When should I run this instead of the Broken Permission Inheritance Audit?

Run this baseline when you need a site-by-site picture of broad access, primary admins and a unique-permission count, for example before a least-privilege project. Run the Broken Permission Inheritance Audit when you need every library, folder or item with unique permissions, ranked by scope and sensitivity. If you need both, run this baseline first to find the sites with high counts, then run the audit on those sites.

Notes


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-10-01 · Published 2026-06-02

Last updated on