Site Permissions Baseline
TL;DR: This skill takes a site-level snapshot of SharePoint permissions: how many people can reach each site, who has broad access, who administers it, and how many items have unique permissions. It is a least-privilege baseline for Microsoft 365 Copilot; item-by-item listing is the audit’s job.
What does the site permissions baseline capture?
This skill builds a per-site permissions snapshot from the Data access governance “Site permissions for your organization” report in the SharePoint admin centre. For each site it records the unique number of users with access, guest and external participant permissions, Microsoft Entra group permissions, “Everyone except external users” (EEEU) and “Everyone” permission counts, sharing link counts, the primary admin, and the count of items with unique permissions. It does not list or rank those items; the Broken Permission Inheritance Audit does that. Because Microsoft 365 Copilot respects existing permissions, sites with broad access are where unexpected content can surface. The baseline is a defensible starting point for ongoing governance. It reads permission data only and changes no permission.
When should you run this skill?
- “Give me a permissions baseline for our SharePoint sites”
- “Who has excessive access across our sites?”
- “List site primary admins and broad-access groups”
- “Snapshot permissions before our least-privilege project”
- “Which sites have the most items with unique permissions?”
How this skill works, step by step
- Confirm licensing and roles (see below), then open Reports > Data access governance in the SharePoint admin centre, or use
Start-SPODataAccessGovernanceInsightfrom SharePoint Online PowerShell. - Create the “Site permissions for your organization” report (SharePoint and OneDrive are reported separately), or download the latest one as CSV.
- Flag sites with high user counts, EEEU, Everyone, guest or Anyone-link permissions.
- Record the Primary admin column for each site and, as this skill’s own check, note sites where it is blank or the account is disabled.
- Record the “Items with unique permissions” count per site, as a count only; object-level listing is left to the audit.
- Score each site by breadth of access, unique-permission count and ownership health (this scoring is the skill’s own method, not a Microsoft metric).
- Assemble the per-site snapshot.
- Output the baseline without altering any permission.
Output format
The skill returns a per-site permissions table, one row per site. Figures below are illustrative only.
| Site | Primary admin | Broad-access principals | Items with unique permissions | Risk | Recommended action |
|---|---|---|---|---|---|
| Finance Hub | Named | EEEU permissions present | 14 | High | Tighten access, run inheritance audit |
| HR Policies | Named | None | 1 | Low | Document exception |
| Legacy Archive | None recorded | Everyone permissions present | 31 | High | Assign owner, run inheritance audit |
Summary (illustrative):
- Total sites baselined
- Sites with EEEU, Everyone or guest permissions
- Sites with unique permissions (count only)
- Sites with no primary admin recorded (this skill’s own check, not a report metric)
- High risk
Scope and safety
This skill is read-only by default. The only thing it creates is the report itself in the SharePoint admin centre; it makes no changes to permissions, ownership or inheritance.
This skill does NOT:
- Add, remove or modify any permission assignment.
- Restore inheritance or break additional scopes.
- Reassign or add site owners.
- Change group membership or access levels.
Report coverage limits to state in the baseline:
- The first report takes up to 5 days; later reports complete within 24 hours, and you can run a report every 30 days.
- Data can be up to 48 hours old.
- Sites with a NoAccess lock status and archived sites are excluded.
- The reports are unavailable for Microsoft 365 operated by 21Vianet.
Licensing and permissions
Licences and add-ons
| Requirement | Detail |
|---|---|
| Base subscription | Office 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD |
| SharePoint Advanced Management | At least one user assigned a Microsoft Copilot licence, or, where the subscription includes SharePoint K, P1 or P2, the SharePoint Advanced Management Plan 1 add-on, or Microsoft 365 E7 |
| Microsoft 365 E5 only | Gives access to Data access governance activity reports but not the snapshot reports or remedial actions, so E5 alone cannot run this skill |
Least-privilege roles
- SharePoint Administrator
- SharePoint Advanced Management Administrator (includes all SharePoint Administrator capabilities plus advanced governance features)
Microsoft Graph permissions (optional, read-only)
Sites.Read.All: least-privileged permission for the Graph list and list-item permission reads (List permissions on a list). The site-level List permissions API lists onlySites.FullControl.All, so do not rely on Graph for site-level permissions; use the report
When should I run this instead of the Broken Permission Inheritance Audit?
Run this baseline when you need a site-by-site picture of broad access, primary admins and a unique-permission count, for example before a least-privilege project. Run the Broken Permission Inheritance Audit when you need every library, folder or item with unique permissions, ranked by scope and sensitivity. If you need both, run this baseline first to find the sites with high counts, then run the audit on those sites.
Related skills
- SharePoint Oversharing Audit: run first to flag sites with external or Anyone access.
- Broken Permission Inheritance Audit: run after, on sites with high unique-permission counts, to list each object and rank it by scope and sensitivity.
- Everyone Except External Users (EEEU) Sweep: run alongside to find broad-claim access.
- Site Lifecycle Review: run after to review inactive and ownerless sites.
- SharePoint Copilot Readiness Guide: the pillar guide that maps each permission step to a read-only skill.
Notes
- Data access governance reports for SharePoint and OneDrive sites
- Get your organization’s site permissions baseline with the snapshot report
- Prerequisites for SharePoint Advanced Management
- Manage Data access governance reports by using SharePoint Online PowerShell
- List permissions on a list (Microsoft Graph)
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-10-01 · Published 2026-06-02