Find files and folders with broken permission inheritance for security audit.
Related topics
unique permissions
broken inheritance
permission audit
sharepoint security
access control
About this tool
The Unique Permissions Audit identifies files and folders with broken permission inheritance in SharePoint. Find content where permissions differ from the parent, which often indicates oversharing or access creep.
Scan up to 5 levels deep in document libraries to find items with unique permissions. Risk-classify findings based on the scope of permission differences.
Essential for permission hygiene and identifying potential security issues from accumulated permission changes.
Key features
Broken inheritance detection
Configurable scan depth (1-5 levels)
Risk classification
Permission comparison
Inheritance break history
Remediation recommendations
Bulk reporting
Site-by-site analysis
Use cases
.
.
.
Graph scopes
undefined (application), undefined (application).
Tool identity
Slug: unique-permissions.
Category: audit.
Plan tier: pro.
Editions: cloud, desktop.
SKUs: security, suite.
Documented scenarios: 3.
Declared features: 8.
Graph permissions requested: 2.
Licensing & access
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Unique Permissions Audit: Detective control only: findings are reported, never auto-remediated. Severity rankings use the documented heuristic and may diverge from Microsoft Secure Score. Detection coverage stops at the Graph permission surface declared above — workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate.