Permissions in Microsoft 365 rarely get set up wrong on day one - they drift wrong over years, as staff change roles, contractors come and go, and files get shared "just to be quick." Most businesses have no clear picture of who can actually access what until they go looking.
Why Permissions Creep Happens
Every "can you just share that folder with me" request is reasonable in isolation. The problem is cumulative - nobody circles back to remove access once it's no longer needed, and over a few years, a small business can end up with dozens of stale permissions nobody remembers granting.
Where to Look: The Four Key Areas
1. Admin Roles
Check the Microsoft 365 admin centre for who holds Global Administrator and other elevated roles. This should be a small, deliberate list, not a default that's grown by accident. Anyone who no longer needs admin access should be reduced to a standard user role. See our guide on Microsoft Entra ID explained for how role-based access actually works.
2. SharePoint and OneDrive Sharing
Use the sharing reports available in the SharePoint admin centre to find files and folders shared externally, or shared with "anyone with the link" rather than specific people. This is consistently one of the most common findings in a permissions audit - convenient sharing settings left far broader than intended.
3. Group and Distribution List Membership
Review who belongs to each security group and distribution list, particularly ones tied to sensitive data access (finance, HR, client records). Membership tends to grow through requests but rarely shrinks without a deliberate review.
4. Former Staff and Contractor Accounts
Confirm every account belongs to a current staff member or active contractor. This should already be handled by a proper offboarding process - see our Microsoft 365 offboarding checklist - but an audit is the safety net that catches anything missed.
How to Run the Audit Practically
- Export a current user list from the admin centre and confirm each account is still active staff
- Run SharePoint and OneDrive sharing reports and review any external or "anyone" links
- Review admin role assignments against an updated list of who should genuinely hold them
- Check group memberships against current staff roles, removing anyone who's changed positions
What to Do With What You Find
Remove access that's no longer needed rather than leaving it "just in case" - unused access is pure risk with no corresponding benefit. For sensitive data, consider whether Conditional Access policies or Microsoft Purview DLP could reduce reliance on manual permission management going forward. See our guides on Conditional Access and Microsoft Purview DLP.
Frequently Asked Questions
How often should a permissions audit be done?
At least annually for most small businesses, with a lighter check whenever a staff member changes role or leaves. Businesses in regulated industries, or those handling particularly sensitive data, often benefit from a more frequent cadence, such as quarterly.
Is this something I can do myself, or does it need IT expertise?
The concepts are accessible to a non-technical business owner, but the tools involved (the Microsoft 365 admin centre, Entra ID, SharePoint's sharing reports) have a learning curve, and misconfiguring a permission while trying to fix another can create new problems. Many businesses have their IT provider run this as part of a periodic review.
What's the most common finding in a permissions audit?
Former staff or contractors retaining access after they've left, and shared links set to 'anyone with the link' rather than restricted to specific people - both are extremely common and both represent genuine, avoidable risk once identified.
Does Microsoft 365 have a built-in tool for this, or do I need third-party software?
Microsoft 365 and Entra ID include built-in reporting - access reviews, sharing reports, and sign-in logs - sufficient for most small businesses. Third-party tools add convenience and automation but aren't strictly necessary to get a genuine picture of your permissions.
We run periodic permissions and access reviews across Microsoft 365 for Perth businesses, so stale access gets caught before it becomes a real risk.
Microsoft 365 Services →Not sure who actually has access to what in your tenant?
Call 0433 087 091 - we'll run a permissions review across your Microsoft 365 environment, no obligation.
Get a Free Permissions ReviewFor related reading, see our guides to the Microsoft 365 offboarding checklist and auditing Microsoft 365 licences.