logo
search
Permission & Access Issues

How to Fix SharePoint Folder Permissions After Adding Azure AD Group

Emma BrownEmma Brown Oct 10, 2026 868 views

Question details

Users are unable to access specific SharePoint folders after their individual permissions were replaced with an Azure AD security group.

How to Fix SharePoint Folder Permissions Changed After Replacing Users with an Azure AD Group
Product
Microsoft SharePoint
Device & OS
not provided
Scenario
An administrator replaces individual members of a SharePoint Members group with a broader Azure AD security group to streamline management.
Observed behavior
Folder access inheritance and group membership evaluations change, causing folders with unique permissions to become unexpectedly inaccessible to authorized users.
Before you start

Ensure you have Site Administrator privileges in SharePoint and access to the Microsoft 365 admin center to successfully check permissions and audit logs.

Solution 1Recommended

Verify and Repair Folder-Level Permissions

Use the Check Permissions tool in SharePoint to diagnose access differences between affected and unaffected folders.

Because SharePoint folders can have unique permissions assigned at multiple levels, adding an Azure AD group might not automatically propagate to folders that have broken inheritance. You must manually check the access logic of the inaccessible folders.

1
Access Folder Settings

Navigate to the affected SharePoint folder, click the ellipsis (three dots) next to the folder name, and select Manage access.

2
Open Advanced Settings

Scroll to the bottom of the Manage Access panel and click on Advanced settings to open the classic permission management page.

3
Run Permission Check

Click Check Permissions in the site permissions ribbon. Enter the affected user's name or email to evaluate their direct, SharePoint group, and Azure AD group permissions.

4
Compare and Restore Inheritance

Compare these permission results with a known unaffected folder. If the affected folder is missing the new Azure AD group permissions, consider clicking 'Delete unique permissions' to restore inheritance from the parent site.

Verify and Repair Folder-Level Permissions
Testing Access Properly: Always ask the affected user to test their folder access using an InPrivate or Incognito browser window. This prevents old, cached login tokens from interfering with the new group permissions.
Free Microsoft Office alternative

Try WPS Office for Seamless Document Management

While troubleshooting complex SharePoint and Azure AD permission issues, you might need a reliable, lightweight suite for your offline and cloud documents. WPS Office is a highly compatible, free alternative to Microsoft Office that makes document creation and collaboration hassle-free.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install and Sign In: Run the installer and sign in with your email or social account to activate your free cloud storage.
  3. 3. Open Your Office Documents: Drag and drop your existing Microsoft Office files into WPS Office to continue working seamlessly with zero formatting loss.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Built-in secure cloud collaboration and file sharing without complex Active Directory setups.Lightweight installation and incredibly fast loading times across Windows, Mac, Linux, iOS, and Android.
microsoft office alternative - wps office

Frequently Asked Questions

Why does replacing individual users with an Azure AD group break SharePoint inheritance?

When individual users are removed and replaced by an Azure AD security group, folders that previously had unique permissions (broken inheritance) tied directly to those specific user accounts lose those links. Only folders inheriting directly from the parent site where the new AD group was applied will grant access automatically.

Is there a delay when syncing Azure AD groups to SharePoint Online?

Yes, there can be a synchronization delay between Azure AD and SharePoint Online. Background group membership evaluations and security token updates might take a few hours to propagate fully across all site collections.

How can I verify if an Azure AD group has been properly recognized by a SharePoint folder?

Use the 'Check Permissions' tool found in the SharePoint Advanced Settings. Enter the name of a user inside that Azure AD group. The tool will break down exactly how the user is receiving access, specifying if it comes from a direct assignment or via the Azure AD group membership.