Turn SharePoint permission scans into prioritized access findings
BSE Analyzer helps IT, security and site owners understand what a completed recursive BSE scan actually means. Instead of reviewing raw permission rows manually, Analyzer highlights risk paths, external access, sharing links, object types, groups and permission combinations that should be reviewed first.
Use Analyzer after BSE has collected permission data from a selected SharePoint site, document library, folder or tree node. Each report is scoped to the scan that was opened, giving you a focused basis for cleanup, audit and internal control.
BSE collects the access data. Analyzer shows what needs attention.
A recursive scan can contain many paths, users, groups, roles and permission combinations. Analyzer turns that data into a practical review surface so you can understand where risk exists and what should be followed up first.
Open the completed report
Open a completed BSE Analyzer report from the BSE right-click menu for the selected site, folder or tree node.
See the access picture
Review users, groups, object types, external access, guests, sharing links and permission combinations in one structured view.
Find what to review first
Use dashboard KPIs, Findings and Top Risk paths to focus on the items that are most important to review.
Export review lists
Export focused views for cleanup, audit evidence, owner dialogue and internal control follow-up.
Customer value
Analyzer helps reduce manual review work, make high-risk access visible, separate external users and guests, and create a practical basis for deciding which SharePoint permissions should be reviewed or cleaned up first.
How BSE and Analyzer work together
BSE is where you select the SharePoint area, inspect permissions and configure recursive scans. Analyzer is where the completed scan result is opened, prioritized and reviewed.
Find the area in BSE
Right-click the relevant site or folder in the BSE navigation tree.
Run a recursive scan
Use Configure Scan of folder tree from this tree node when a deeper review is needed.
Open Analyzer
If a completed report exists, use Open BSE Analyzer report.
Review findings
Analyzer opens the scan result and shows dashboard, findings, users, groups, risk paths and raw data.
Report availability
The Open BSE Analyzer report menu option is shown only when a completed report exists for the selected tree node.
From raw permission data to concrete findings
Large SharePoint structures can contain many folders, files, groups, users, guests and sharing mechanisms. Even when permission data has been collected, it can be difficult to see what should be reviewed first.
BSE Analyzer makes the scan result more actionable. Instead of reviewing raw rows manually, you get a structured view of paths, identities, groups, object types and risk indicators.
The result is a better basis for cleanup, internal control, audit preparation and dialogue with owners of the SharePoint areas.
Start with the dashboard, then drill into detail
The dashboard gives a high-level view of the loaded scan result before you open detailed views. It combines scan metadata, KPI cards, Access Risk Snapshot, object types and top risk paths.
External/guest and Critical/high split
The top KPI area separates values that are often reviewed differently:
Open details directly from tiles
Some dashboard tiles can be used as shortcuts into more detailed views.
Drilldowns support mouse click and keyboard activation with Enter or Space.
What BSE Analyzer helps you see
Prioritized findings
Get a practical list of findings that should be reviewed, documented or followed up.
Top Risk paths
Identify folders, files and other objects with the strongest risk indicators in the loaded scan result.
Site, Subsite, Channel and Pages
Use Object Type to separate different SharePoint object classes when reviewing, filtering or exporting data.
Users and principals
Review identities that appear in the scan result, including users, groups, guests and sharing-link identities.
Groups and access chains
Understand group-based access and use group access chains when chain information is available in the scan result.
External users and guests
Separate external identities from guest identities and prioritize where they require review.
Sharing links
See where access appears to come from sharing links and use this as a basis for cleanup and risk review.
Permission combinations
Find repeating permission patterns and compare similar access setups across the loaded report.
Keyword rules
Use keyword-rule signals to understand which path names match configured review rules.
BSE and Analyzer have different roles
BSE is where you navigate SharePoint, inspect permissions and configure recursive scans. Analyzer is where the completed scan result is analyzed and prioritized.
Together, they provide a connected workflow from SharePoint insight to recursive scan, analysis and follow-up.
BSE
- Browse one selected SharePoint site
- See permissions retrieved from SharePoint
- Find objects with unique permissions
- Configure recursive scans from selected tree nodes
- Open available BSE Analyzer reports
BSE Analyzer
- Open the completed report for the selected tree node
- Analyze paths, users, groups and object types
- Surface external access and sharing links
- Prioritize findings and risk areas
- Provide a basis for cleanup, control and audit
Analyzer is read-only and scoped to the opened scan result
BSE Analyzer is a reporting and review tool. It does not change SharePoint permissions, group memberships or sharing settings.
Analyzer shows the result that has been opened. It does not provide a combined view of an entire SharePoint installation, tenant or all sites.
Practical for access review
Treat each report as a point-in-time view of the selected BSE scan scope. Use Analyzer to understand what should be reviewed before making changes in SharePoint or Microsoft 365 administration tools.
When is BSE Analyzer useful?
Internal control
Create a more practical basis for reviewing and documenting SharePoint access.
Permission cleanup
Find unique permissions, external access, sharing links and old exceptions that need follow-up.
Audit preparation
Use prioritized findings and exports as support for audit, evidence collection and owner review.
External sharing
Identify guests, external identities and sharing-link access that should be reviewed.
This is more than an export
The scan result may have a technical file format underneath, but the value for the user is the analysis. BSE Analyzer makes the result understandable, prioritizes findings and gives a better decision basis than manual review of raw rows.
That is why Analyzer should be understood as part of the BSE workflow: first SharePoint insight in BSE, then recursive scan, then analysis and follow-up in BSE Analyzer.
Related BSE pages
SharePoint Explorer
See the full BSE workflow from permission visibility to recursive scan and analysis.
See the full workflowSharePoint access control
See how BSE and Analyzer support internal control, cleanup and audit work.
Read about access controlSharePoint permissions
Understand unique permissions, broken inheritance and why deviations are hard to detect.
Read about permissionsAnalyzer user manual
Learn how to use Dashboard, Findings, Top Risk paths, Object Type, Groups and exports.
Read the manualWould you like to see a scan analyzed in Analyzer?
Book a short walkthrough, or test the BSE demo to see how SharePoint permissions become visible before analysis.
