Binera SharePoint Explorer Administrator user manual
This guide explains how to use Binera SharePoint Explorer (BSE) to navigate SharePoint, inspect users, groups and permissions, work with scan reports, and manage scheduled site scans when you have BSE administrator permissions.
Version 1.3 · Administrator edition · Last updated: August 31, 2026
Find the part of BSE you want to understand
Overview
What BSE helps you doInterface
Main screen and layoutTop bar and appearance
Administration, analysis, help, theme and tree viewNavigation panel
Sites, folders, pages and filesInformation and export
Search, filtering and exportsRecursive scan
View scan configurations and open reportsAdministration
Find sites and manage scheduled scansAccess panel
Groups, users and permissionsIcon legend
Object and access iconsOpening the correct user manual
Select the blue question-mark icon in BSE to open the user manual. BSE checks whether the signed-in user belongs to the administrator group. Users with BSE administrator permissions are directed to this Administrator user manual; other users are directed to the standard BSE user manual.
What BSE helps you do
BSE gives you a practical way to inspect permissions in SharePoint. You can navigate the site structure, select a site, document library, folder, file, page or channel site, and see the permissions that apply to the selected item.
Work site by site
Review permissions within one selected SharePoint site at a time.
Find permission breaks
Identify where inheritance is broken and where folders have unique permissions.
See access deviations
See which documents deviate from the surrounding folder structure.
Analyze deeper structures
Open existing scan reports for selected tree nodes when deeper review is needed.
Interface in Binera SharePoint Explorer
The main screen in BSE is divided into four marked parts: the top bar and appearance controls, the navigation panel, selected item information with search and export, and the access panel.
The selected item controls what is shown in the work area. When you select another item in the navigation panel, BSE updates the information and access view for that item.
Top bar and appearance settings
Part 1 contains the administrator actions and the controls that apply to the overall BSE interface.
- select Manage scans to open the Scheduled site scans administration page
- select Analyze all scanned sites to open BSE Analyzer with data from all sites scanned during the last 24 hours
- use the blue question-mark icon to open this Administrator user manual after BSE has checked the user's administrator access
- switch between a light and dark background
- select Hide Tree to hide the navigation tree and Show Tree to display it again
Tree view makes it easier to navigate the hierarchy of sites, folders and files, especially in larger SharePoint environments.
Navigation panel
The navigation panel shows the SharePoint structure and makes it possible to move between the different levels in the selected site. It allows you to navigate in a way that resembles a traditional file structure.
The panel can display SharePoint sites, Teams-connected sites, document libraries, folders, files, pages and channel sites. You can also filter which object types are shown.
Current limitation
Site assets and list are currently not supported in this version.
- Hide SharePoint sites hides standard SharePoint sites
- Hide Teams sites hides Teams-connected sites
- Hide files with inherited permissions only hides files that only inherit permissions
- Show only scanned sites filters the site tree so that only scanned sites are shown
- Search sites searches the site tree while you type
- see objects with unique permissions highlighted in the tree
When you select a site, folder or file, the item is highlighted in the structure. At the same time, the permissions that apply to the selected item are shown in the access panel.
Scan status and hover text
A status indicator may appear to the right of a scanned site. Hold the pointer over the indicator to read the full status message.
Blue: A scan is in progress.
Green: The latest scan is less than one day old.
Yellow: The latest scan is between one and three days old.
Red: The latest scan is more than three days old.
Grey: A scheduled scan exists but has not started yet.
No indicator: No corresponding scan status is available for the site.
For both yellow and red indicators, the hover text shows the date and time of the last completed scan. It also explains that a newer scheduled scan has not completed yet, that Microsoft may throttle SharePoint and Microsoft Graph requests to protect Microsoft 365, and that BSE automatically waits and continues when capacity becomes available. The hover text also shows how many other sites have active scan schedules and explains that, in large environments, completing all scheduled scans can take several days.
Analyze all scanned sites
This button opens BSE Analyzer with data from all sites scanned during the last 24 hours. The same explanation is shown when you hold the pointer over the button.
The report opens in a separate browser tab. This user manual only describes how to open the report from BSE. BSE Analyzer will be documented separately when the new version is ready.
Right-click actions in the tree
You can right-click a site or folder in the navigation tree to work with its recursive scan configuration and open an available BSE Analyzer report. The scan configuration action depends on whether the user has BSE administrator permissions.
Learn more about how scan results are reviewed on the SharePoint access analysis with BSE Analyzer page.
This Administrator user manual also explains how to manage scheduled site scans. See Administration.
Information, search and export
This part of the solution shows information about the selected item and provides access to search, filtering and export of results.
Information about the selected item
The panel shows details about the selected item, including its name, associated group and a link to the item in SharePoint if available.
Sensitivity information
When sensitivity metadata is available for a selected file, BSE shows the label name, colour and how the label was applied, for example Applied manually. Hold the pointer over the information to read the full explanation.
BSE displays metadata received from Microsoft 365. BSE does not classify the file or change the sensitivity label.
Search and filtering
You can search by name, email address and role. The role filter shows the roles available for the selected item. Select All Roles to display all roles again.
Export
Results can be exported as JSON or flat CSV. JSON retains structured data, while flat CSV is suitable for further work in Excel and other table-based tools.
Recursive scan and BSE Analyzer
A recursive scan collects permission data from a selected tree node and everything below it in the hierarchy. This makes it possible to analyze larger SharePoint structures without manually navigating through every level.
Creating, changing and deleting recursive scan configurations requires BSE administrator permissions. Other BSE users can view existing scan configurations and open available BSE Analyzer reports.
Configuring a recursive scan
Right-click the relevant site or folder and select Configure Scan of folder tree from this tree node. The scan includes the selected tree node and everything below it in the hierarchy.
The Scan configuration dialog identifies the selected tree node. Large scans may take longer because of Microsoft throttling and the amount of permission data collected.
When a scheduled scan already exists, the dialog shows its status and the columns Site, Folder, Schedule and Last run. An existing schedule must be deleted before a different schedule can be configured for the same site.
Select Open Analyzer report to open the available report. Select Delete scheduled scan only when the displayed schedule is to be removed.
Check before deleting
Verify the selected tree node, site, folder, schedule and last run before selecting Delete scheduled scan. This removes the scheduled scan configuration; it does not delete the SharePoint site, folder or content.
Opening a BSE Analyzer report
When a completed report exists for the selected tree node, Open BSE Analyzer report is available from the right-click menu.
The report can also be opened from the Scan configuration dialog by selecting Open Analyzer report.
Opening an Analyzer report does not require BSE administrator permissions. BSE administrator permissions are required only for creating, changing or deleting recursive scan configurations.
Managing scheduled site scans
Users with BSE administrator permissions can open Manage scans from the top bar. This opens the Scheduled site scans administration page, where several SharePoint sites can be selected, assigned a common daily start time, or have existing schedules deleted.
Manage scans
Select Manage scans in the BSE top bar. The administration page opens with the heading Scheduled site scans.
Use Back to BSE in the top bar or Back to explorer on the page to return to the main BSE interface.
Other available actions
Analyze all scanned sites opens BSE Analyzer with data from all sites scanned during the last 24 hours. The blue question-mark icon opens the appropriate user manual after BSE checks the user's administrator access.
The theme control and Hide Tree remain available in the top bar.
Daily scanning pause
SharePoint scans are paused daily from 08:00–16:00 (Europe/Oslo). Active scans wait during this period and resume automatically afterwards. The notice is displayed near the top of the administration page.
Find and filter sites
Use Search site name or URL to narrow the list. Under Show sites by scan status, select Not configured or Configured. The number displayed with each choice shows how many sites currently belong to that category.
Use Site type to filter by site type. The list distinguishes SharePoint sites from Teams sites. Select all results selects the sites currently returned by the search and filters. The summary above the table shows how many sites are displayed out of the total and how many are selected.
Read the current scan information
Each row begins with a checkbox used to select that site. The table then shows:
- Site: the site name and URL.
- Type: whether the site is a SharePoint site or a Teams site.
- Scheduled scan: the daily start time, or Not scheduled when no schedule is shown.
- Last completed: the date and time of the latest completed scan, or a dash when no completion time is shown.
Select the intended sites
Select individual sites with the checkboxes in the table, or use Select all results after narrowing the list. The selected counter shows how many sites are included. For configured sites, the number in Delete schedules shows how many schedules are included in that action.
Check the scope before continuing
Before assigning or deleting schedules, verify the selected status category, the filtered list, the selected count and the selected sites. When assigning schedules, also verify the daily start time. These actions change the scheduled scan configuration for the selected sites.
Not configured
- Select Not configured under Show sites by scan status.
- Find and select the sites that need a daily scan schedule.
- Use the scheduling controls displayed for the selected sites to assign a common daily start time.
- Verify the selected sites and start time before applying the schedule.
Delete schedules
- Select Configured under Show sites by scan status.
- Find and select the sites whose existing schedules are to be removed.
- Verify the selected count shown in Delete schedules.
- Select Delete schedules to remove the schedules from the selected sites.
This action removes scheduled scan configurations; it is not described here as deleting SharePoint sites or content.
Recursive scan configurations
In the navigation tree, right-click the relevant site or folder and select Configure Scan of folder tree from this tree node. With BSE administrator permissions, the scan configuration can be reviewed and an existing scheduled scan can be deleted. The report is opened with Open BSE Analyzer report from the right-click menu or Open Analyzer report in the Scan configuration dialog.
Access panel
The access panel shows how access is configured for the item you have selected. Here you can see which groups have access, which users belong to those groups and how the access has been assigned.
- which groups have access
- which users are members of those groups
- how the access has been assigned
- whether access is direct or inherited through group membership
Groups can be expanded directly in the view by clicking the arrow in front of the group name. This makes it easier to see which users actually have access through group membership.
Select Show Users Only to display the users who ultimately have access without the expanded group structure. The button then changes to Show Full Structure, which displays the complete group hierarchy again.
The Name, Roles, Email/Principal, Direct Group and Root Group columns show which identity the row represents, the assigned role and the groups that provide access.
The permissions shown always apply to the item that is selected. Changes in the selected item will therefore affect what is displayed in the panel.
Log Analytics
Log Analytics is available only when Log Analytics is installed in the customer's tenant. When it is installed, a dedicated button becomes available in BSE.
The function makes it possible to analyze recorded activity related to files and folders, including when they were accessed and by whom. Select Start Date and End Date, and then search within the required period.
- search log data
- see who has accessed documents and folders
- analyze usage over a selected period
- export results to CSV
If Log Analytics is not installed in the customer's tenant, the button and function are not available in BSE.
Icons used in BSE
BSE uses different icons to show object types, users and how access has been assigned.
SharePoint site
Standard SharePoint area or group.
Teams site
Indicates that the site is Teams-enabled.
Entra group
Indicates that the object is a group in Entra ID.
Document library
Shows a SharePoint document library.
Channel site
Indicates a channel site or channel-related SharePoint area.
Folder inherits permissions
The folder inherits permissions from the level above.
Folder unique permissions
The folder has permissions that differ from the level above.
Document inherits permissions
The document inherits permissions from its folder.
Document unique permissions
The document has permissions that differ from the folder.
Pages
Area pages in the SharePoint structure.
Organization
Indicates access that applies to the organization.
Internal user
Indicates an internal user in the organization.
External user
Indicates a guest user or external identity.
Access via link
Indicates access granted through a sharing link.
System account
Indicates a system account or technical user.
Device
Indicates a physical device or client.
Need help using BSE?
Request demo access or book a walkthrough if you want help understanding the workflow from SharePoint navigation to recursive scan and analysis.
