Fix OneDrive Access Denied for Returned Employees
Question details
A returned employee cannot access previously shared OneDrive files using their new account due to permission conflicts with their old user identity.

- Product
- Microsoft OneDrive
- Device & OS
- not provided
- Scenario
- A former employee is rehired and provisioned with a new account, but needs access to company files that were previously shared with their original account.
- Observed behavior
- When attempting to open shared OneDrive files, the user receives an 'Access Denied' error message because the file permissions are still associated with the unique ID of their previous account.
Ensure you have administrative access to the Microsoft Purview compliance portal to run audit logs, and confirm that audit logging was enabled prior to the employee's original departure.
Identify File Owners via Audit Logs and Re-share Files
Use Microsoft 365 audit logs to find which files were shared with the old account, export the list, and have the owners re-share the files with the new identity.
Microsoft 365 permissions are tied to a unique internal user ID, not just an email address. When an employee returns with a new account, the internal ID changes, causing Access Denied errors. You must manually remove the old permissions and grant access to the new ID.
Navigate to the Microsoft Purview compliance portal. Go to 'Audit' and run a search for shared files, folders, or sites associated with the old user account within the timeframe before it was deleted.
Once the search completes, click 'Export' to download the results as a CSV file. Open this file in Excel to easily identify the original owners who shared the files.
Instruct the identified file owners to open their OneDrive, right-click the affected shared files, select 'Manage Access', and remove the previous employee account from the permissions list.
Have the file owners click 'Share' on the same files and send a new invitation to the returned employee's current active account.

Clear Browser Cache to Prevent Credential Conflicts
Clear cached credentials to ensure the browser isn't silently attempting to authenticate using the old, disabled account session.
Experience Seamless File Sharing with WPS Office
Managing complex Microsoft 365 user identities and fixing permission mismatches can be time-consuming. If you are looking for a more straightforward, user-friendly approach to document collaboration, consider WPS Office. It provides robust cloud sharing features that integrate effortlessly with your workflow without complex backend identity conflicts.
- 1. Download WPS Office: Visit the official WPS website and download the free desktop application.
- 2. Sign In and Collaborate: Create a free account to unlock built-in cloud storage and start collaborating.
- 3. Share Documents Easily: Open any Office document and use the simplified 'Share' button to grant instant access without complex ID mismatches.

Frequently Asked Questions
Why does a rehired employee get Access Denied on previously shared files even if their email is the same?
Microsoft 365 associates file permissions with a unique internal user identifier (GUID), not the email address. Even if a returned employee is given the exact same email address, the newly created account generates a brand new internal ID. The files are still looking for the old ID, resulting in an Access Denied error.
Can I simply restore the old user account to fix the permission issue?
Yes, if the old account was deleted recently (usually within 30 days), an administrator can restore the original account from the Microsoft 365 admin center. Restoring the account recovers the original internal ID, immediately restoring access to all previously shared files.
What if audit logging wasn't enabled before the employee left?
If audit logging was disabled, you cannot run a centralized search to find all the files shared with the old account. You will need to manually identify the file owners (often department managers or close teammates) and ask them to check their shared files and manually grant access to the new account.
Does clearing the browser cache actually fix the OneDrive Access Denied error?
Clearing the cache only helps if the browser is incorrectly auto-authenticating with an old, cached session token. If the issue is a genuine internal user ID mismatch on the server, clearing the cache will not work, and the files must be explicitly re-shared by their owners.




