Skip to content
BSE Analyzer – Full analysis of SharePoint access Skip to main content

Binera

Menu
  • Home
  • Services
  • Products
    • Binera Sharepoint Explorer
  • About us
  • Contact us
  • Book a meeting
Binera

Binera

Binera

🇳🇴 NO 🇬🇧 EN
BSE Analyzer

Turn SharePoint permission scans into prioritized access findings

BSE Analyzer helps IT, security and site owners understand what a completed recursive BSE scan actually means. Instead of reviewing raw permission rows manually, Analyzer highlights risk paths, external access, sharing links, object types, groups and permission combinations that should be reviewed first.

Use Analyzer after BSE has collected permission data from a selected SharePoint site, document library, folder or tree node. Each report is scoped to the scan that was opened, giving you a focused basis for cleanup, audit and internal control.

Book a walkthrough See what Analyzer does Read the user manual
In plain terms

BSE collects the access data. Analyzer shows what needs attention.

A recursive scan can contain many paths, users, groups, roles and permission combinations. Analyzer turns that data into a practical review surface so you can understand where risk exists and what should be followed up first.

Open

Open the completed report

Open a completed BSE Analyzer report from the BSE right-click menu for the selected site, folder or tree node.

Understand

See the access picture

Review users, groups, object types, external access, guests, sharing links and permission combinations in one structured view.

Prioritize

Find what to review first

Use dashboard KPIs, Findings and Top Risk paths to focus on the items that are most important to review.

Follow up

Export review lists

Export focused views for cleanup, audit evidence, owner dialogue and internal control follow-up.

Customer value

Analyzer helps reduce manual review work, make high-risk access visible, separate external users and guests, and create a practical basis for deciding which SharePoint permissions should be reviewed or cleaned up first.

From BSE to Analyzer

How BSE and Analyzer work together

BSE is where you select the SharePoint area, inspect permissions and configure recursive scans. Analyzer is where the completed scan result is opened, prioritized and reviewed.

Select node

Find the area in BSE

Right-click the relevant site or folder in the BSE navigation tree.

Configure scan

Run a recursive scan

Use Configure Scan of folder tree from this tree node when a deeper review is needed.

Open report

Open Analyzer

If a completed report exists, use Open BSE Analyzer report.

Analyze

Review findings

Analyzer opens the scan result and shows dashboard, findings, users, groups, risk paths and raw data.

Report availability

The Open BSE Analyzer report menu option is shown only when a completed report exists for the selected tree node.

Why Analyzer

From raw permission data to concrete findings

Large SharePoint structures can contain many folders, files, groups, users, guests and sharing mechanisms. Even when permission data has been collected, it can be difficult to see what should be reviewed first.

BSE Analyzer makes the scan result more actionable. Instead of reviewing raw rows manually, you get a structured view of paths, identities, groups, object types and risk indicators.

The result is a better basis for cleanup, internal control, audit preparation and dialogue with owners of the SharePoint areas.

Prioritized findings Top Risk paths Object types External / guests Group access chains Permission combinations
BSE Analyzer v19.30 dashboard. Click the image to view it larger.
Dashboard v19.30

Start with the dashboard, then drill into detail

The dashboard gives a high-level view of the loaded scan result before you open detailed views. It combines scan metadata, KPI cards, Access Risk Snapshot, object types and top risk paths.

Split KPI values

External/guest and Critical/high split

The top KPI area separates values that are often reviewed differently:

External / guestsShows external identity count and guest identity count as separate values.
Critical / high pathsShows Critical path count and High path count as separate values.
Dashboard drilldowns

Open details directly from tiles

Some dashboard tiles can be used as shortcuts into more detailed views.

External and guest principalsOpens Users/principals.
Keyword rulesOpens the Keyword rules dialog.

Drilldowns support mouse click and keyboard activation with Enter or Space.

Header
Shows file name, file scan date, document library, full path and source data rows when available in the scan result.
Status chips
Show active rule set, configured internal domains and number of keyword rules.
Access Risk Snapshot
Summarizes risk distribution, findings by severity, permission combinations, object types, external/guest principals, keyword rules and top risk paths.
Left navigation
Moves between Dashboard, Findings, access risk views, users and groups, Group access chains and Raw data.
Analysis areas

What BSE Analyzer helps you see

Prioritize

Prioritized findings

Get a practical list of findings that should be reviewed, documented or followed up.

Risk

Top Risk paths

Identify folders, files and other objects with the strongest risk indicators in the loaded scan result.

Object types

Site, Subsite, Channel and Pages

Use Object Type to separate different SharePoint object classes when reviewing, filtering or exporting data.

Identities

Users and principals

Review identities that appear in the scan result, including users, groups, guests and sharing-link identities.

Groups

Groups and access chains

Understand group-based access and use group access chains when chain information is available in the scan result.

External access

External users and guests

Separate external identities from guest identities and prioritize where they require review.

Sharing

Sharing links

See where access appears to come from sharing links and use this as a basis for cleanup and risk review.

Patterns

Permission combinations

Find repeating permission patterns and compare similar access setups across the loaded report.

Rules

Keyword rules

Use keyword-rule signals to understand which path names match configured review rules.

Roles in the solution

BSE and Analyzer have different roles

BSE is where you navigate SharePoint, inspect permissions and configure recursive scans. Analyzer is where the completed scan result is analyzed and prioritized.

Together, they provide a connected workflow from SharePoint insight to recursive scan, analysis and follow-up.

Explorer

BSE

  • Browse one selected SharePoint site
  • See permissions retrieved from SharePoint
  • Find objects with unique permissions
  • Configure recursive scans from selected tree nodes
  • Open available BSE Analyzer reports
Analysis

BSE Analyzer

  • Open the completed report for the selected tree node
  • Analyze paths, users, groups and object types
  • Surface external access and sharing links
  • Prioritize findings and risk areas
  • Provide a basis for cleanup, control and audit
Scope and safety

Analyzer is read-only and scoped to the opened scan result

BSE Analyzer is a reporting and review tool. It does not change SharePoint permissions, group memberships or sharing settings.

Analyzer shows the result that has been opened. It does not provide a combined view of an entire SharePoint installation, tenant or all sites.

Practical for access review

Treat each report as a point-in-time view of the selected BSE scan scope. Use Analyzer to understand what should be reviewed before making changes in SharePoint or Microsoft 365 administration tools.

Use cases

When is BSE Analyzer useful?

Control

Internal control

Create a more practical basis for reviewing and documenting SharePoint access.

Cleanup

Permission cleanup

Find unique permissions, external access, sharing links and old exceptions that need follow-up.

Audit

Audit preparation

Use prioritized findings and exports as support for audit, evidence collection and owner review.

Sharing

External sharing

Identify guests, external identities and sharing-link access that should be reviewed.

Product value

This is more than an export

The scan result may have a technical file format underneath, but the value for the user is the analysis. BSE Analyzer makes the result understandable, prioritizes findings and gives a better decision basis than manual review of raw rows.

That is why Analyzer should be understood as part of the BSE workflow: first SharePoint insight in BSE, then recursive scan, then analysis and follow-up in BSE Analyzer.

Continue through the BSE workflow

Related BSE pages

SharePoint Explorer

See the full BSE workflow from permission visibility to recursive scan and analysis.

See the full workflow

SharePoint access control

See how BSE and Analyzer support internal control, cleanup and audit work.

Read about access control

SharePoint permissions

Understand unique permissions, broken inheritance and why deviations are hard to detect.

Read about permissions

Analyzer user manual

Learn how to use Dashboard, Findings, Top Risk paths, Object Type, Groups and exports.

Read the manual

Would you like to see a scan analyzed in Analyzer?

Book a short walkthrough, or test the BSE demo to see how SharePoint permissions become visible before analysis.

Book a walkthrough Try demo
Built with BoldGrid