🇳🇴 NO 🇬🇧 EN
Documentation

Binera SharePoint Explorer Administrator user manual

This guide explains how to use Binera SharePoint Explorer (BSE) to navigate SharePoint, inspect users, groups and permissions, work with scan reports, and manage scheduled site scans when you have BSE administrator permissions.

Version 1.3 · Administrator edition · Last updated: August 31, 2026

Contents

Find the part of BSE you want to understand

Opening the correct user manual

Select the blue question-mark icon in BSE to open the user manual. BSE checks whether the signed-in user belongs to the administrator group. Users with BSE administrator permissions are directed to this Administrator user manual; other users are directed to the standard BSE user manual.

Overview

What BSE helps you do

BSE gives you a practical way to inspect permissions in SharePoint. You can navigate the site structure, select a site, document library, folder, file, page or channel site, and see the permissions that apply to the selected item.

Sites

Work site by site

Review permissions within one selected SharePoint site at a time.

Folders

Find permission breaks

Identify where inheritance is broken and where folders have unique permissions.

Documents

See access deviations

See which documents deviate from the surrounding folder structure.

Reports

Analyze deeper structures

Open existing scan reports for selected tree nodes when deeper review is needed.

Interface

Interface in Binera SharePoint Explorer

The main screen in BSE is divided into four marked parts: the top bar and appearance controls, the navigation panel, selected item information with search and export, and the access panel.

The selected item controls what is shown in the work area. When you select another item in the navigation panel, BSE updates the information and access view for that item.

Administrator interface in BSE, marked as Parts 1 to 4. Click the image to view it larger.
Part 1

Top bar and appearance settings

Part 1 contains the administrator actions and the controls that apply to the overall BSE interface.

  • select Manage scans to open the Scheduled site scans administration page
  • select Analyze all scanned sites to open BSE Analyzer with data from all sites scanned during the last 24 hours
  • use the blue question-mark icon to open this Administrator user manual after BSE has checked the user's administrator access
  • switch between a light and dark background
  • select Hide Tree to hide the navigation tree and Show Tree to display it again

Tree view makes it easier to navigate the hierarchy of sites, folders and files, especially in larger SharePoint environments.

Part 1: administrator top bar and appearance settings. Click the image to view it larger.
Part 3

Information, search and export

This part of the solution shows information about the selected item and provides access to search, filtering and export of results.

The information, search and export panel in BSE. Click the image to view it larger.
Selected item

Information about the selected item

The panel shows details about the selected item, including its name, associated group and a link to the item in SharePoint if available.

Sensitivity

Sensitivity information

When sensitivity metadata is available for a selected file, BSE shows the label name, colour and how the label was applied, for example Applied manually. Hold the pointer over the information to read the full explanation.

BSE displays metadata received from Microsoft 365. BSE does not classify the file or change the sensitivity label.

Search

Search and filtering

You can search by name, email address and role. The role filter shows the roles available for the selected item. Select All Roles to display all roles again.

Export

Export

Results can be exported as JSON or flat CSV. JSON retains structured data, while flat CSV is suitable for further work in Excel and other table-based tools.

Information about the selected item.
Search and filtering.
Export function.
Recursive scan

Recursive scan and BSE Analyzer

A recursive scan collects permission data from a selected tree node and everything below it in the hierarchy. This makes it possible to analyze larger SharePoint structures without manually navigating through every level.

Creating, changing and deleting recursive scan configurations requires BSE administrator permissions. Other BSE users can view existing scan configurations and open available BSE Analyzer reports.

Selected tree node Recursive permissions Scheduled scan BSE administrator permissions BSE Analyzer
Administrator

Configuring a recursive scan

Right-click the relevant site or folder and select Configure Scan of folder tree from this tree node. The scan includes the selected tree node and everything below it in the hierarchy.

The Scan configuration dialog identifies the selected tree node. Large scans may take longer because of Microsoft throttling and the amount of permission data collected.

When a scheduled scan already exists, the dialog shows its status and the columns Site, Folder, Schedule and Last run. An existing schedule must be deleted before a different schedule can be configured for the same site.

Select Open Analyzer report to open the available report. Select Delete scheduled scan only when the displayed schedule is to be removed.

Check before deleting

Verify the selected tree node, site, folder, schedule and last run before selecting Delete scheduled scan. This removes the scheduled scan configuration; it does not delete the SharePoint site, folder or content.

Recursive scan configuration for a user with BSE administrator permissions. Click the image to view it larger.

Opening a BSE Analyzer report

When a completed report exists for the selected tree node, Open BSE Analyzer report is available from the right-click menu.

The report can also be opened from the Scan configuration dialog by selecting Open Analyzer report.

Opening an Analyzer report does not require BSE administrator permissions. BSE administrator permissions are required only for creating, changing or deleting recursive scan configurations.

Administration

Managing scheduled site scans

Users with BSE administrator permissions can open Manage scans from the top bar. This opens the Scheduled site scans administration page, where several SharePoint sites can be selected, assigned a common daily start time, or have existing schedules deleted.

Manage scans Scheduled site scans Daily scanning pause Configured and Not configured SharePoint and Teams sites
Scheduled site scans administration page. Click the image to view it larger.
Open administration

Manage scans

Select Manage scans in the BSE top bar. The administration page opens with the heading Scheduled site scans.

Use Back to BSE in the top bar or Back to explorer on the page to return to the main BSE interface.

Top bar

Other available actions

Analyze all scanned sites opens BSE Analyzer with data from all sites scanned during the last 24 hours. The blue question-mark icon opens the appropriate user manual after BSE checks the user's administrator access.

The theme control and Hide Tree remain available in the top bar.

Daily scanning pause

SharePoint scans are paused daily from 08:00–16:00 (Europe/Oslo). Active scans wait during this period and resume automatically afterwards. The notice is displayed near the top of the administration page.

Find and filter sites

Use Search site name or URL to narrow the list. Under Show sites by scan status, select Not configured or Configured. The number displayed with each choice shows how many sites currently belong to that category.

Use Site type to filter by site type. The list distinguishes SharePoint sites from Teams sites. Select all results selects the sites currently returned by the search and filters. The summary above the table shows how many sites are displayed out of the total and how many are selected.

Site list

Read the current scan information

Each row begins with a checkbox used to select that site. The table then shows:

  • Site: the site name and URL.
  • Type: whether the site is a SharePoint site or a Teams site.
  • Scheduled scan: the daily start time, or Not scheduled when no schedule is shown.
  • Last completed: the date and time of the latest completed scan, or a dash when no completion time is shown.
Selection

Select the intended sites

Select individual sites with the checkboxes in the table, or use Select all results after narrowing the list. The selected counter shows how many sites are included. For configured sites, the number in Delete schedules shows how many schedules are included in that action.

Check the scope before continuing

Before assigning or deleting schedules, verify the selected status category, the filtered list, the selected count and the selected sites. When assigning schedules, also verify the daily start time. These actions change the scheduled scan configuration for the selected sites.

Sites without schedules

Not configured

  1. Select Not configured under Show sites by scan status.
  2. Find and select the sites that need a daily scan schedule.
  3. Use the scheduling controls displayed for the selected sites to assign a common daily start time.
  4. Verify the selected sites and start time before applying the schedule.
Remove schedules

Delete schedules

  1. Select Configured under Show sites by scan status.
  2. Find and select the sites whose existing schedules are to be removed.
  3. Verify the selected count shown in Delete schedules.
  4. Select Delete schedules to remove the schedules from the selected sites.

This action removes scheduled scan configurations; it is not described here as deleting SharePoint sites or content.

Recursive scan configurations

In the navigation tree, right-click the relevant site or folder and select Configure Scan of folder tree from this tree node. With BSE administrator permissions, the scan configuration can be reviewed and an existing scheduled scan can be deleted. The report is opened with Open BSE Analyzer report from the right-click menu or Open Analyzer report in the Scan configuration dialog.

Part 4

Access panel

The access panel shows how access is configured for the item you have selected. Here you can see which groups have access, which users belong to those groups and how the access has been assigned.

  • which groups have access
  • which users are members of those groups
  • how the access has been assigned
  • whether access is direct or inherited through group membership

Groups can be expanded directly in the view by clicking the arrow in front of the group name. This makes it easier to see which users actually have access through group membership.

Select Show Users Only to display the users who ultimately have access without the expanded group structure. The button then changes to Show Full Structure, which displays the complete group hierarchy again.

The Name, Roles, Email/Principal, Direct Group and Root Group columns show which identity the row represents, the assigned role and the groups that provide access.

The permissions shown always apply to the item that is selected. Changes in the selected item will therefore affect what is displayed in the panel.

The access panel in BSE. Click the image to view it larger.
Log Analytics

Log Analytics

Log Analytics is available only when Log Analytics is installed in the customer's tenant. When it is installed, a dedicated button becomes available in BSE.

The function makes it possible to analyze recorded activity related to files and folders, including when they were accessed and by whom. Select Start Date and End Date, and then search within the required period.

  • search log data
  • see who has accessed documents and folders
  • analyze usage over a selected period
  • export results to CSV

If Log Analytics is not installed in the customer's tenant, the button and function are not available in BSE.

Log Analytics in BSE. Click the image to view it larger.
Icon legend

Icons used in BSE

BSE uses different icons to show object types, users and how access has been assigned.

SharePoint site icon

SharePoint site

Standard SharePoint area or group.

Teams site icon

Teams site

Indicates that the site is Teams-enabled.

Entra group icon

Entra group

Indicates that the object is a group in Entra ID.

Document library icon

Document library

Shows a SharePoint document library.

Channel site

Indicates a channel site or channel-related SharePoint area.

Folder with inherited permissions icon

Folder inherits permissions

The folder inherits permissions from the level above.

Folder with unique permissions icon

Folder unique permissions

The folder has permissions that differ from the level above.

Document with inherited permissions icon

Document inherits permissions

The document inherits permissions from its folder.

Document with unique permissions icon

Document unique permissions

The document has permissions that differ from the folder.

Pages icon

Pages

Area pages in the SharePoint structure.

Organization icon

Organization

Indicates access that applies to the organization.

Internal user icon

Internal user

Indicates an internal user in the organization.

External user icon

External user

Indicates a guest user or external identity.

Access via link icon

Access via link

Indicates access granted through a sharing link.

System account icon

System account

Indicates a system account or technical user.

Device icon

Device

Indicates a physical device or client.

Need help using BSE?

Request demo access or book a walkthrough if you want help understanding the workflow from SharePoint navigation to recursive scan and analysis.