SharePoint access control: see who has access to what
SharePoint access control becomes difficult when permissions change over time. Folders get unique permissions, files are shared directly, guests are invited and access is granted through groups. Binera SharePoint Explorer helps you see the actual access in one selected SharePoint site and find the deviations that need follow-up.
When a structure is too large to review manually, BSE can configure a recursive scan from a selected tree node. The completed report opens in BSE Analyzer, where access risk is prioritized for cleanup, audit and internal control.
SharePoint access control starts with knowing what access actually exists
It is difficult to control SharePoint access if you only know how the structure was intended to work. You also need to see where permissions have been changed, where inheritance is broken, which groups are involved and where external access or sharing links need review.
Actual permissions
Use BSE to see users, groups, roles and unique permissions directly from SharePoint for the selected site, folder or file.
Access deviations
Identify folders, files and objects where access deviates from the surrounding structure or needs closer follow-up.
Risk-based review
Use recursive scans and BSE Analyzer to turn larger permission structures into prioritized findings and risk areas.
Audit and cleanup basis
Export focused review lists and use the findings as a practical basis for owners, administrators, audits and internal control.
Customer value
BSE and BSE Analyzer help reduce manual work, make permission deviations visible, prioritize follow-up and create a clearer basis for cleanup, audit and governance.
A better foundation for SharePoint access control
For many organizations, SharePoint is not only about collaboration, but also about control over information, responsibility and access.
Access control becomes difficult when permissions are configured differently across folders, files and levels in the structure. Deviations are often located several levels down and are hard to detect without reviewing each level manually.
BSE makes these reviews more concrete by showing the selected SharePoint structure, the permissions that apply, and where unique permissions or access deviations require follow-up.
Make access review more practical
- Identify folders and documents with unique permissions
- Review areas with higher risk
- Support owners and administrators in cleanup
- Establish better routines over time
- Create a better basis for audit and documentation
BSE works site by site
BSE is designed to inspect permissions within one selected SharePoint site at a time. The navigation, access view and reports are tied to the site or tree node you are working with.
To review several SharePoint sites, open each site separately and configure separate recursive scans where needed.
Clearer boundaries make control easier
Site-by-site review gives a clearer relationship between the area being reviewed, the permissions being shown and the report that is generated.
This makes it easier to involve the correct site owners, document findings and follow up on cleanup in a controlled way.
Practical support for audit and documentation
During audits or internal reviews, it is often not enough to refer to the intended SharePoint structure.
You also need to understand how permissions are actually configured. BSE helps make these reviews more concrete by showing actual access, groups, users and unique permissions in the selected site.
The result is a better basis for documentation, follow-up and dialogue with the business.
Evidence for review
Use BSE to document what was reviewed and where permission deviations were found.
Better follow-up
Give site owners and administrators a clearer basis for deciding which permissions should be cleaned up.
Use recursive scans for deeper access-control reviews
Some permission deviations can be reviewed directly in BSE. For larger folder structures, BSE can configure a recursive scan from a selected site or folder. The scan collects permission data from the selected node and all items below it in the hierarchy.
Right-click the tree node
Use Configure Scan of folder tree from this tree node to configure a recursive scan from the selected site or folder.
Run after 17:00
Select the time of day for the scan. Jobs can only run after 17:00 to reduce impact during working hours.
Review the scheduled scan
The dialog shows scheduled scans with Site, Folder, Schedule and Last run.
Open Analyzer
If a completed report exists, use Open BSE Analyzer report to open the report.
Report availability and scheduled scans
The Open BSE Analyzer report menu option is shown only when a completed report exists for the selected tree node.
Use Delete scan for this site when an existing scheduled scan should be removed before configuring a different schedule.
From access control to prioritized findings
Control is not only about finding deviations. It is also about understanding which findings should be followed up first.
When a recursive scan has completed, the report can be opened from the right-click menu in BSE by selecting Open BSE Analyzer report. Analyzer shows the result from that selected BSE tree node and turns the scan data into a more structured access analysis.
Analyzer helps prioritize findings across paths, users, groups, object types, external access, sharing links and permission combinations.
Prioritized access review
- top risk paths
- findings by severity
- object types
- external and guest principals
- permission combinations
- groups and group access chains
A practical workflow for access control
Understand permissions
Start by understanding unique permissions, broken inheritance and why access deviations appear in SharePoint.
Inspect the selected site
Use BSE to review the structure, users, groups and permissions inside one selected SharePoint site.
Configure a recursive scan
Configure a recursive scan from the relevant tree node when the structure needs deeper review.
Analyze and follow up
Open the report in BSE Analyzer and use prioritized findings as the basis for cleanup, audit and internal control.
From uncertainty to better access control
Reduced risk
Better visibility into deviations and permission structures that require follow-up.
Less manual work
Faster identification of areas that would otherwise require manual review.
Better documentation
A more concrete foundation for internal control, audits and dialogue with the business.
Related BSE pages
SharePoint Explorer
See the full BSE workflow from permission visibility to recursive scan and analysis.
See the full workflowSharePoint permissions
Understand unique permissions, broken inheritance and why deviations are hard to detect.
Read about permissionsBSE Analyzer
See how scan results are turned into prioritized findings and risk areas.
Read about AnalyzerBSE demo
Try BSE in a prepared demo environment and see permission deviations in practice.
Try the demoWould you like to explore the control perspective of BSE?
Try the demo or book a walkthrough of how BSE and BSE Analyzer can support access control, cleanup and audit work.
