---
name: Site Permissions Baseline
description: "Snapshot each SharePoint site's broad-access principals, primary admin and unique-permission counts as a least-privilege baseline; object detail is left to the audit."
lastReviewed: 2026-10-01
---

# Site Permissions Baseline

> **TL;DR:** This skill takes a site-level snapshot of SharePoint permissions: how many people can reach each site, who has broad access, who administers it, and how many items have unique permissions. It is a least-privilege baseline for Microsoft 365 Copilot; item-by-item listing is the audit's job.

## What does the site permissions baseline capture?

This skill builds a per-site permissions snapshot from the Data access governance "Site permissions for your organization" report in the SharePoint admin centre. For each site it records the unique number of users with access, guest and external participant permissions, Microsoft Entra group permissions, "Everyone except external users" (EEEU) and "Everyone" permission counts, sharing link counts, the primary admin, and the count of items with unique permissions. It does not list or rank those items; the [Broken Permission Inheritance Audit](/sharepoint/broken-permission-inheritance-audit) does that. Because Microsoft 365 Copilot respects existing permissions, sites with broad access are where unexpected content can surface. The baseline is a defensible starting point for ongoing governance. It reads permission data only and changes no permission.

## When should you run this skill?

- "Give me a permissions baseline for our SharePoint sites"
- "Who has excessive access across our sites?"
- "List site primary admins and broad-access groups"
- "Snapshot permissions before our least-privilege project"
- "Which sites have the most items with unique permissions?"

## How this skill works, step by step

1. Confirm licensing and roles (see below), then open Reports > Data access governance in the SharePoint admin centre, or use `Start-SPODataAccessGovernanceInsight` from SharePoint Online PowerShell.
2. Create the "Site permissions for your organization" report (SharePoint and OneDrive are reported separately), or download the latest one as CSV.
3. Flag sites with high user counts, EEEU, Everyone, guest or Anyone-link permissions.
4. Record the Primary admin column for each site and, as this skill's own check, note sites where it is blank or the account is disabled.
5. Record the "Items with unique permissions" count per site, as a count only; object-level listing is left to the audit.
6. Score each site by breadth of access, unique-permission count and ownership health (this scoring is the skill's own method, not a Microsoft metric).
7. Assemble the per-site snapshot.
8. Output the baseline without altering any permission.

## Output format

The skill returns a per-site permissions table, one row per site. Figures below are illustrative only.

| Site | Primary admin | Broad-access principals | Items with unique permissions | Risk | Recommended action |
| --- | --- | --- | --- | --- | --- |
| Finance Hub | Named | EEEU permissions present | 14 | High | Tighten access, run inheritance audit |
| HR Policies | Named | None | 1 | Low | Document exception |
| Legacy Archive | None recorded | Everyone permissions present | 31 | High | Assign owner, run inheritance audit |

Summary (illustrative):

- Total sites baselined
- Sites with EEEU, Everyone or guest permissions
- Sites with unique permissions (count only)
- Sites with no primary admin recorded (this skill's own check, not a report metric)
- High risk

## Scope and safety

This skill is read-only by default. The only thing it creates is the report itself in the SharePoint admin centre; it makes no changes to permissions, ownership or inheritance.

This skill does NOT:

- Add, remove or modify any permission assignment.
- Restore inheritance or break additional scopes.
- Reassign or add site owners.
- Change group membership or access levels.

Report coverage limits to state in the baseline:

- The first report takes up to 5 days; later reports complete within 24 hours, and you can run a report every 30 days.
- Data can be up to 48 hours old.
- Sites with a NoAccess lock status and archived sites are excluded.
- The reports are unavailable for Microsoft 365 operated by 21Vianet.

## Licensing and permissions

### Licences and add-ons

| Requirement | Detail |
| --- | --- |
| Base subscription | Office 365 E3, E5 or A5; Microsoft 365 E1, E3, E5 or A5; or Microsoft 365 GCC, GCC-High or DoD |
| SharePoint Advanced Management | At least one user assigned a Microsoft Copilot licence, or, where the subscription includes SharePoint K, P1 or P2, the SharePoint Advanced Management Plan 1 add-on, or Microsoft 365 E7 |
| Microsoft 365 E5 only | Gives access to Data access governance activity reports but not the snapshot reports or remedial actions, so E5 alone cannot run this skill |

### Least-privilege roles

- SharePoint Administrator
- SharePoint Advanced Management Administrator (includes all SharePoint Administrator capabilities plus advanced governance features)

### Microsoft Graph permissions (optional, read-only)

- `Sites.Read.All`: least-privileged permission for the Graph list and list-item permission reads (List permissions on a list). The site-level List permissions API lists only `Sites.FullControl.All`, so do not rely on Graph for site-level permissions; use the report

## When should I run this instead of the Broken Permission Inheritance Audit?

Run this baseline when you need a site-by-site picture of broad access, primary admins and a unique-permission count, for example before a least-privilege project. Run the [Broken Permission Inheritance Audit](/sharepoint/broken-permission-inheritance-audit) when you need every library, folder or item with unique permissions, ranked by scope and sensitivity. If you need both, run this baseline first to find the sites with high counts, then run the audit on those sites.

## Related skills

- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run first to flag sites with external or Anyone access.
- [Broken Permission Inheritance Audit](/sharepoint/broken-permission-inheritance-audit): run after, on sites with high unique-permission counts, to list each object and rank it by scope and sensitivity.
- [Everyone Except External Users (EEEU) Sweep](/sharepoint/everyone-except-external-users-sweep): run alongside to find broad-claim access.
- [Site Lifecycle Review](/sharepoint/site-lifecycle-review): run after to review inactive and ownerless sites.
- [SharePoint Copilot Readiness Guide](/sharepoint/copilot-readiness-guide): the pillar guide that maps each permission step to a read-only skill.

## Notes

- [Data access governance reports for SharePoint and OneDrive sites](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports)
- [Get your organization's site permissions baseline with the snapshot report](https://learn.microsoft.com/en-us/sharepoint/data-access-governance-site-permissions-report)
- [Prerequisites for SharePoint Advanced Management](https://learn.microsoft.com/en-us/sharepoint/sharepoint-advanced-management-prerequisites)
- [Manage Data access governance reports by using SharePoint Online PowerShell](https://learn.microsoft.com/en-us/sharepoint/powershell-for-data-access-governance)
- [List permissions on a list (Microsoft Graph)](https://learn.microsoft.com/en-us/graph/api/list-list-permissions?view=graph-rest-1.0)
