How to Audit SharePoint Access Requests and File Permissions
Question details
The user needs to know how to review and audit access requests, requesters, sharing activities, and specific file or folder permissions within Microsoft SharePoint.
- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Auditing site security, monitoring sharing activities, and generating permissions reports for SharePoint files and folders.
- Observed behavior
- Administrators need actionable methods to track access logs, review current permissions, and efficiently generate comprehensive security reports.
Ensure you have Site Collection Administrator or Global Administrator privileges in SharePoint, and verify that Microsoft Purview audit logging is enabled for your organization.
Review Sharing and Access Requests via Microsoft Purview Audit Logs
Use the Microsoft Purview compliance portal to track who requested access, who shared files, and how sharing invitations were handled across your SharePoint environment.
Microsoft Purview provides centralized audit logging for Office 365 services. By searching the audit logs, administrators can pinpoint exact timestamps and user details for sharing invitations, access requests, and permission changes.
Sign in to the Microsoft Purview compliance portal using your administrator credentials.
On the left navigation pane, scroll down and click on 'Audit'.
Set your desired date range. In the 'Activities' dropdown, search for and select activities related to 'Sharing and access request activities' (such as 'Created an access request' or 'Shared file, folder, or site').
Click 'Search' to generate the logs. Once the search completes, you can review the results directly or click 'Export' to download a CSV file for detailed analysis.
Inspect File and Folder Permissions Using Manage Access
Manually check and modify who has access to specific files, folders, or document libraries using SharePoint's built-in interface.
Generate Complete Permissions Reports Using PowerShell
Create automated custom scripts using PowerShell or PnP PowerShell to extract a full, site-wide report of all user permissions and access levels.
Looking for a Lightweight Office Solution? Try WPS Office
While auditing SharePoint server permissions requires Microsoft administrative tools, WPS Office provides an excellent, lightweight, and free alternative for creating, editing, and managing your everyday documents with seamless Microsoft Office format compatibility.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Software: Run the downloaded installer file and follow the quick on-screen instructions to set up the suite.
- 3. Open and Edit Documents: Launch WPS Office to immediately start creating new files or opening your existing Microsoft Office documents seamlessly.

Frequently Asked Questions
How do I turn off access requests for a restricted SharePoint site?
To disable access requests, navigate to your site's 'Settings' (gear icon), select 'Site permissions', and click on 'Site sharing settings' or 'Advanced permissions settings'. Find the 'Access Request Settings' and uncheck the 'Allow access requests' option, then click OK.
Where can I view pending access requests in SharePoint?
Site owners can view and manage pending access requests by clicking the gear icon, selecting 'Site contents', and then clicking on 'Access requests and invitations'. If there are no pending requests, this button may not be visible.
Can I export SharePoint permission reports without using PowerShell?
Natively, SharePoint does not offer a one-click button to export a full site permission report without PowerShell. However, you can manually check individual permissions using 'Manage Access' or utilize third-party SharePoint administration tools that offer built-in reporting features.
Who can approve SharePoint access requests?
By default, access requests are sent to the site owners group. Any user who is a member of the site owners group, or the specific email address configured in the Access Request Settings, can approve or decline these requests.




