Access Requests
Common Use Cases
- Locked-out visitors: a user opens a site link they were never granted
- Restricted document access: someone needs a single file in a protected library
- New team members: a joiner requests access before owners add them to a group
- External collaboration: a guest asks for access to shared content
- Fewer admin tickets: users self-serve the request instead of emailing IT
- Controlled onboarding: owners grant the right level rather than over-sharing
Benefits
- No dead ends: users get a request path instead of an error page
- Owner control: permissions stay with site owners, not end users
- One-click decisions: approve or decline from the email or settings
- Right-sized access: choose the exact permission level on approval
- Visible queue: pending and handled requests are listed for owners
- Out-of-the-box: nothing to build, it ships with every modern site
Details
- Feature Category: Sharing & Permissions
How It Works
- Triggered on denial: appears when a user lacks permission to content
- Request message: the user adds context for the approver
- Email to approvers: the request routes to the owners or a chosen mailbox
- Approve or decline: owners act from the email or Access Request Settings
- Permission on grant: the approver sets the level the requester receives
- Pending until resolved: outstanding requests stay listed until handled
Settings
- Allow access requests: a toggle in Site Permissions, Access Request Settings
- Request destination: send to site owners or a specific email address
- Sharing requests: governs requests to share with people who lack access
- Owner-managed: only owners or full-control users see the settings
- Per-site scope: each site controls its own access request behavior
- Works with groups: approvals add users to Owners, Members, or Visitors
Limits and Nuances
- Owners must respond: requests sit until an owner acts on them
- Email dependency: approvers need to see the notification to act
- Not a substitute for planning: heavy volume signals a permissions gap
- Unique permissions grow: each approval can create item-level permissions
- External requests vary: guest requests depend on external sharing settings
- No built-in SLA: there is no automatic escalation or reminder
Common Questions About Access Requests
What are access requests in SharePoint?
Access requests are SharePoint’s built-in flow for when someone tries to open a site, library, or file they do not have permission to see. Rather than hitting a dead end, the user can submit a short request, which SharePoint emails to the site owners. An owner then approves or declines it and chooses the permission level to grant. It keeps access decisions with owners while giving users a clear way to ask.
Who receives and approves an access request?
By default the request goes to the site owners, but in Access Request Settings an owner can route requests to a specific email address or mailbox instead. Whoever receives it can approve or decline directly from the notification or from the settings page, and on approval they pick the permission level the requester gets. Only owners or users with full control can manage these settings.
Where do I turn access requests on or off?
Access requests are controlled per site under Site Permissions, in the Access Request Settings panel. There you can allow or block requests entirely, decide who receives them, and govern requests to share content with people who do not already have access. Because the setting is per site, each site owner manages their own behavior rather than relying on a single tenant-wide switch.
What is the difference between an access request and external sharing?
An access request is an internal user asking an owner for permission to existing content. External sharing is the separate capability that controls whether content can be shared with guests outside your organization at all. The two interact: a guest can submit an access or sharing request, but whether that is even possible depends on your external sharing settings at the tenant and site level.
Why do too many access requests signal a problem?
A steady stream of requests usually means the site’s permission structure does not match how people actually work. When the right groups are not set up, users repeatedly hit walls and ask for one-off access, and each approval can create unique, item-level permissions that are harder to manage over time. The requests are a useful signal that the underlying permission design needs a rethink.
When should I get help structuring permissions?
Access requests work best on a site whose permissions were designed deliberately in the first place. Greg Zelfond, the consultant behind LookBook 365, structures sites around clear Owners, Members, and Visitors groups so most people already have the access they need, and requests become the exception rather than the norm. When access requests become routine, it is usually a sign the permission model needs the attention he provides.