How to Create a SharePoint Online User Access Report
Question details
The user needs to generate a comprehensive quarterly SharePoint access report detailing sites, named owners, members, visitors, permissions, custom groups, broken inheritance, and dates.

- Product
- SharePoint Online
- Device & OS
- not provided
- Scenario
- Generating an in-depth quarterly access and permissions report for auditing or compliance purposes.
- Observed behavior
- SharePoint Online lacks a built-in, out-of-the-box reporting feature that captures all of these specific site details and permission parameters in a single view.
Ensure you have SharePoint Administrator or Global Administrator privileges and have the PnP PowerShell module installed on your system before attempting to extract permission data.
Generate a User Access Report Using PnP PowerShell
Since SharePoint does not offer a native comprehensive report, utilizing a PnP PowerShell script is the most effective way to extract complete permission details to a CSV file.
PowerShell allows administrators to iterate through site collections to pull precise data regarding named owners, members, visitors, custom groups, and files with broken inheritance.
Open PowerShell as an Administrator and install the PnP module by running the command `Install-Module -Name PnP.PowerShell`.
Authenticate and connect to your environment using the command `Connect-PnPOnline -Url https://yourdomain-admin.sharepoint.com -Interactive`.
Run a customized SharePoint permissions script designed to iterate through your site collections, checking the `HasUniqueRoleAssignments` property to document user access and broken inheritance.
Use the `Export-Csv` cmdlet at the end of your script to output the collected data into a CSV file format.
Because most scripts operate at the site-collection level, repeat this process for each site collection in your tenant, then combine the exported CSV files to create your final quarterly report.

Analyze Your SharePoint CSV Reports with WPS Office
After exporting your SharePoint user access data to a CSV file via PowerShell, you need a reliable spreadsheet tool to combine, format, and analyze the data. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office for managing all your reports.

Frequently Asked Questions
Can I generate a SharePoint access report without using PowerShell?
SharePoint Online does not currently provide a single out-of-the-box report that covers custom groups, broken inheritance, and complete site access all at once. You must rely on third-party SharePoint auditing tools or PowerShell scripts.
How do I find SharePoint sites or folders with broken permission inheritance?
You can identify broken inheritance by using PnP PowerShell scripts that evaluate the 'HasUniqueRoleAssignments' property. If this property returns 'True' for a list or site, it means the item does not inherit permissions from its parent.
What permissions do I need to run these PowerShell scripts?
You must have at least SharePoint Administrator credentials to connect via PnP PowerShell and retrieve complete site collection permission reports.
Can I schedule this SharePoint user access report to run automatically?
Yes. You can automate the execution of your PowerShell script using Azure Automation or Windows Task Scheduler to run the report on a quarterly basis and email the resulting CSV file.




