Find SharePoint permission deviations before they become risk
SharePoint access is often expected to follow the site and folder structure. Over time, inheritance can be broken, files can be shared directly, guests can be invited and group memberships can change. The real access picture may no longer match what owners believe.
Binera SharePoint Explorer helps you see actual permissions inside one selected SharePoint site and highlight where access deviates. When deeper review is needed, recursive scans and BSE Analyzer help turn the result into prioritized findings.
SharePoint permissions are manageable only when deviations are visible
A SharePoint site may look structured on the surface, but access can be different several levels down. To review permissions properly, you need to see where inheritance is broken, where access is assigned directly, which groups are involved and which files or folders should be checked first.
Inherited or unique permissions
See whether folders and files follow the structure above them, or whether they have their own permission setup.
Direct access and links
Find where access may have been granted directly to users, guests or through sharing links.
Users, groups and memberships
Understand which users and groups are involved before deciding whether access should be changed.
Know what to review first
Use recursive scans and BSE Analyzer when larger structures need risk-based prioritization.
Customer value
BSE helps make hidden permission exceptions visible. Analyzer helps prioritize the findings so cleanup, audit and internal control can focus on the areas that matter most.
What do unique permissions mean in SharePoint?
In SharePoint, folders and files normally inherit permissions from the level above. This makes the access model easier to maintain because the same permission setup follows the structure.
When inheritance is broken, the item receives unique permissions. That means access to a file, folder, page or library may differ from the surrounding SharePoint permissions structure.
Unique permissions are often necessary in specific cases, but over time these exceptions can make the environment difficult to understand, control and maintain.
Access becomes harder to trust
- Files become visible to people who should not have access according to the structure
- Folders get permission setups that are difficult to detect manually
- Old exceptions remain without follow-up
- Direct sharing creates access outside the expected model
- It becomes difficult to know who actually has access to what
Permission deviations grow over time
Broken inheritance
A folder or file can stop inheriting permissions from the level above. Once this happens, the item needs to be reviewed on its own.
Direct sharing
Access may be granted directly to users, guests or through sharing links. These exceptions can be hard to identify from the surrounding folder structure alone.
Group-based access
Access is often granted through groups. To understand actual access, you may also need to understand which users are members of those groups.
BSE works site by site
BSE is designed to inspect and document permissions within one selected SharePoint site at a time. The navigation, access view and reports are limited to the site or tree node you are working with.
To review several SharePoint sites, open each site separately and configure separate recursive scans where needed.
Clear expectation
BSE does not provide one combined tenant-wide view of all SharePoint sites. Analyzer also shows the result from the BSE scan that was opened, not a combined report for an entire tenant.
How BSE makes permission deviations visible
BSE shows the SharePoint structure for the selected site and highlights folders, files and other objects where permissions deviate from the surrounding structure.
When you select a site, folder or file, BSE shows the permissions that apply to that selected item. This makes it easier to understand both the structure and the actual access picture without moving between several Microsoft interfaces.
When permission deviations need deeper review
Some deviations can be reviewed directly in BSE. But when a folder structure contains many subfolders, files and exceptions, a deeper review may be needed. BSE can configure a recursive scan from a selected tree node and collect permission data from that node and all items below it in the hierarchy.
Right-click the tree node
Use Configure Scan of folder tree from this tree node to configure a recursive scan from the selected site or folder.
Run after 17:00
Select the time of day for the scan. Jobs can only run after 17:00 to reduce impact during working hours.
Review the scheduled scan
The dialog shows scheduled scans with Site, Folder, Schedule and Last run.
Open Analyzer
If a completed report exists, use Open BSE Analyzer report to open the report.
Report availability and scheduled scans
The Open BSE Analyzer report menu option is shown only when a completed report exists for the selected tree node.
Use Delete scan for this site when an existing scheduled scan should be removed before configuring a different schedule.
Once deviations are visible, decide what to review first
BSE helps you find where permissions deviate from the surrounding structure. When there are many findings, the next step is to understand which deviations should be reviewed first.
When a recursive scan has completed, the report can be opened from the right-click menu in BSE by selecting Open BSE Analyzer report. Analyzer shows the result from that selected BSE tree node and turns the scan data into a more structured access analysis.
Analyzer helps prioritize findings across paths, users, groups, external access, sharing links, object types, group access chains and permission combinations. This gives you a better basis for cleanup, governance, audits and dialogue with the owners of the SharePoint areas.
Why SharePoint permissions are difficult to review manually
In Microsoft’s interface, access information is often spread across several views. You may need to inspect the object, review group-based access, check membership and understand how sharing has been applied.
When this has to be repeated across many folders, files and pages, the work quickly becomes time-consuming. It is also easy to miss exceptions that exist several levels down in the structure.
BSE is designed to provide this insight in a more practical way for the selected SharePoint site, and Analyzer helps turn the scan result into prioritized findings.
What to look for
- Where inheritance is broken
- Which items have unique permissions
- Who has direct access
- Which groups provide access
- Where external users or guests appear
- Where sharing links are involved
- Which object types are affected
- Which findings should be prioritized
Learn more about permissions, control and analysis
This page explains why SharePoint permissions become difficult to understand. Continue with the full Explorer workflow, access-control perspective, Analyzer or demo flow.
SharePoint Explorer
See the full BSE workflow from permission visibility to recursive scan and analysis.
See the full workflowSharePoint access control
See how permission deviations become part of internal control, cleanup, audit work and governance follow-up.
Read about access controlBSE Analyzer
See how scan results are turned into prioritized findings, object types, risk areas and cleanup basis.
Read about AnalyzerBSE demo
Try BSE in a prepared demo environment and see how SharePoint permission deviations become visible.
Try the demoWould you like to see how this works in practice?
Try the demo environment or book a short walkthrough of Binera SharePoint Explorer and BSE Analyzer.
