Site Permissions for Users Report
Common Use Cases
- Pre-Copilot license check: seeing what a user’s Copilot could surface before assigning a license
- Department changes: reviewing access when someone moves teams
- Offboarding: confirming what a departing user can reach
- Access right-sizing: trimming excessive access a user has accumulated
- Direct vs. group access: seeing exactly how access is granted
- Multi-user review: including several users in one report
Benefits
- Per-user access map: every site a user can reach, point in time
- Shows how access is granted: whole-site vs. specific files, direct vs. through a group
- Rich site context: admin, external sharing, privacy, label, and file count
- Copilot-relevant: shows exactly what a user’s Copilot can surface
- Multi-user reports: review several users at once
- Tenant-scale download: per-user CSV up to 1 million sites, or a ZIP for all users
Details
- Feature Category: Governance & Compliance
How It Works
- Lives in the SharePoint Admin Center: App Launcher, Admin, SharePoint admin center, Data access governance under Reports, Site permissions for users, View reports, Create report
- Add users and scope: pick the users, choose the SharePoint or OneDrive scope, name the report, and run it
- Snapshot per user: lists every site each user can access and the extent of that access
- Admin only: only SharePoint administrators can create and view it; site owners and regular users have no access
- Licensing plus a prerequisite: Advanced Management licensing, and the organization-wide site permissions report must have been generated at least once first
- Output: an on-screen users-and-sites view, plus a per-user CSV (up to 1 million sites) or a ZIP of CSVs covering all users
Limits and Nuances
- Created per user and scope: add one or more users, choose the SharePoint or OneDrive scope, and name the report
- Prerequisite: the organization-wide site permissions report must have been generated at least once before this report can run
- Freshness: data can be up to 48 hours old, so this is a snapshot, not a live view
- Caps: you can keep a maximum of 5 reports, and each report can only be re-run every 30 days
- Downloads: export a per-user CSV covering up to 1 million sites, or a ZIP of CSVs covering all users
Common Questions About the Site Permissions for Users Report
What does the Site Permissions for Users report show?
For each user you select, it lists every SharePoint or OneDrive site the user can access and how that access is granted – whole site versus specific files, direct versus through a group. Each site row includes the primary administrator, external sharing status, privacy setting, sensitivity label, and approximate file count.
What license is required to run this report?
You need either the SharePoint Advanced Management add-on license or a Microsoft 365 Copilot license, which includes Advanced Management. Licensing packages change often, so check Microsoft’s official requirements before planning around it.
Who can create and view the report?
Only SharePoint administrators. The report lives in the Data Access Governance section of the SharePoint Admin Center, which is not accessible to site owners or regular users.
Are there any prerequisites before running it?
Yes – the organization-wide site permissions report must have been generated at least once first. The user-level report builds on that snapshot, so if you have never run the organization-wide report, start there.
How fresh is the data, and how often can I re-run it?
The data can be up to 48 hours old, so treat it as a recent snapshot rather than a live view. You can keep up to 5 reports at a time, and each individual report can only be re-run once every 30 days.
How does this report help with Microsoft 365 Copilot readiness?
Copilot answers using whatever access a user already has. Running this report before assigning someone a Copilot license shows exactly what content their Copilot will be able to surface – and gives you the chance to trim excessive access first. It is equally useful when a person changes departments or leaves.