Find files and folders with broken permission inheritance for security audit.
Related topics
unique permissions
broken inheritance
permission audit
sharepoint security
access control
About this tool
The Unique Permissions Audit identifies files and folders with broken permission inheritance in SharePoint. Find content where permissions differ from the parent, which often indicates oversharing or access creep.
Scan up to 5 levels deep in document libraries to find items with unique permissions. Risk-classify findings based on the scope of permission differences.
Essential for permission hygiene and identifying potential security issues from accumulated permission changes.
Key features
Broken inheritance detection
Configurable scan depth (1-5 levels)
Risk classification
Permission comparison
Inheritance break history
Remediation recommendations
Bulk reporting
Site-by-site analysis
Use cases
Permission hygiene. Identify and review unique permissions
Access control audit. Verify permission inheritance is maintained
Site cleanup. Restore inheritance where appropriate
Requires a paid edition (security). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Files.Read.All is read-only, and the configurable 1-5-level scan depth is a deliberate tradeoff — document libraries with permission breaks nested deeper than level 5 are not reported, because walking every level of every library in a large tenant would multiply Graph calls beyond a practical runtime. It flags broken inheritance; restoring inheritance is a manual SharePoint action this tool does not perform.