Audit privileged SharePoint access including Site Collection Admins, owners, and Full Control.
Related topics
privileged access
admin audit
permission review
access certification
least privilege
About this tool
The Privileged Access Report audits all users with elevated SharePoint permissions. Find Site Collection Administrators, site owners, and users with Full Control access across your environment.
Identify excessive privileged access that may indicate permission creep over time. Compare against role requirements to ensure least-privilege principles are maintained.
Export results to Excel for access certification workflows and remediation tracking.
Key features
Site Collection Admin audit
Owner role identification
Full Control access scan
Admin role mapping
Permission level analysis
Department-level reporting
Historical comparison
Certification workflow support
Use cases
.
.
.
Graph scopes
undefined (application), undefined (application).
Tool identity
Slug: privileged-access.
Category: audit.
Plan tier: pro.
Editions: cloud, desktop.
SKUs: security, suite.
Documented scenarios: 3.
Declared features: 8.
Graph permissions requested: 2.
Licensing & access
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Privileged Access Report: Detective control only: findings are reported, never auto-remediated. Severity rankings use the documented heuristic and may diverge from Microsoft Secure Score. Detection coverage stops at the Graph permission surface declared above — workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate.