How to Fix Microsoft Lists Permissions Removed Without Changes
Question details
Users need to investigate and resolve issues where Microsoft Lists permissions are unexpectedly modified or removed without direct manual intervention.

- Product
- Microsoft Lists
- Device & OS
- not provided
- Scenario
- A user or team discovers that co-owner or read-only access to specific Microsoft Lists has been removed unexpectedly.
- Observed behavior
- Access permissions for Microsoft Lists are automatically revoked or altered, preventing authorized users from viewing or editing the list, despite no admin or owner manually making these changes.
Ensure you have Global Administrator, Compliance Administrator, or SharePoint Administrator privileges in Microsoft 365, as you will need these rights to access the Purview audit logs and review organization-wide policies.
Review Microsoft Purview Audit Logs
Use the Microsoft Purview compliance portal to track down exactly who or what modified the list permissions.
The Microsoft Purview audit log records all user and system activities within your tenant. By filtering for SharePoint and Lists activities, you can identify the exact timestamp and source of the permission change.
Log in to the Microsoft 365 admin center and navigate to the Microsoft Purview compliance portal.
In the left-hand navigation menu, click on 'Audit' to open the audit log search interface.
Set the Date and time range to cover when the permissions were lost. Under 'Activities', search for and select SharePoint list activities, specifically looking for 'Modified list permissions' or 'Removed user or group from SharePoint group'.
In the 'File, folder, or site' field, paste the exact URL of the affected Microsoft List to narrow down the results, then click 'Search'.
Once the search completes, click 'Export' to download the results as a CSV file. Review the 'User' and 'Item' columns to determine if an automated system account or an administrator triggered the change.

Check Power Automate Flows and Organizational Policies
Verify if automated workflows, custom scripts, or updated sharing policies are inadvertently revoking list access.
Contact Microsoft 365 Support
Escalate the issue to Microsoft Support if audit logs and policy checks yield no explanation.
Try WPS Office for Seamless Data and Document Management
If you are struggling with complex administrative permission issues in Microsoft 365, WPS Office offers a free, lightweight, and highly compatible alternative. You can manage your tracking data seamlessly using WPS Spreadsheet with simple file-sharing capabilities and native compatibility with Microsoft Office formats.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install and Launch: Run the installer and follow the on-screen prompts. Once installed, open WPS Office.
- 3. Manage Data with Spreadsheets: Use WPS Spreadsheet to import your existing list data or create new tracking sheets without worrying about unexpected backend permission changes.

Frequently Asked Questions
Can external sharing settings cause list permissions to drop unexpectedly?
Yes. If an administrator changes the organization's or site's external sharing settings to be more restrictive (e.g., changing from 'Anyone' to 'Only people in your organization'), existing external guests will immediately lose their access to the list.
How long does Microsoft Purview retain audit logs for permission changes?
By default, standard audit logs in Microsoft 365 are retained for 90 days. If your organization has premium licensing (like E5) and has configured extended retention, logs can be kept for up to one year or longer.
Can a Power Automate flow change Microsoft Lists permissions in the background?
Yes. Power Automate flows have specific actions, such as 'Stop sharing an item or a file' or 'Grant access to an item or a folder', which can alter list permissions without manual user interaction. This is a common cause for unexpected permission changes.
Why does a user still get an 'Access Denied' error when they are in a SharePoint group?
This can happen if the site collection's permission inheritance is broken at the list level, or if the user's specific account has an active Conditional Access policy blocking their login session due to network or device non-compliance.




