logo
search
Permission & Access Issues

How to Remove a User from All OneDrive and SharePoint Sites via PowerShell

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 869 views

Question details

An administrator needs to remove a specific user's access across all personal OneDrive and SharePoint sites, including revoking their Site Collection Administrator role, but encounters an access error.

How to Remove a User from All OneDrive and SharePoint Sites
Product
Microsoft SharePoint and OneDrive
Device & OS
not provided
Scenario
Offboarding a user or auditing permissions across an organization's Microsoft 365 tenant.
Observed behavior
Running the PowerShell script to remove the user's role fails and returns an 'Access is denied' (HRESULT: 0x80070005) error.
Before you start

Ensure you have the SharePoint Online Management Shell installed and that you possess Global Administrator or SharePoint Administrator privileges in your Microsoft 365 tenant before running these scripts.

Solution 1Recommended

Use SharePoint Online PowerShell to Remove the User Role

Connect to your SharePoint admin center and run the Set-SPOUser command to iterate through sites and revoke Site Collection Administrator rights.

To perform bulk administrative actions across an entire tenant, the SharePoint Online Management Shell is required. This script will identify the target user and strip their administrative access from the specified site collections.

1
Connect to SharePoint Admin Center

Open PowerShell as an administrator and run the command 'Connect-SPOService -Url https://yourdomain-admin.sharepoint.com' to authenticate your admin session.

2
Retrieve All Sites

Execute 'Get-SPOSite -IncludePersonalSite $true -Limit All' to fetch the complete list of all SharePoint and personal OneDrive sites within the tenant.

3
Remove Site Collection Administrator Role

Loop through the sites and run 'Set-SPOUser -Site $site.Url -LoginName user@yourdomain.com -IsSiteCollectionAdmin $false' to securely remove the user's access.

Use SharePoint Online PowerShell to Remove the User Role
Processing Time: Running this script across a large tenant with thousands of OneDrive sites may take a significant amount of time to complete.
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft Office?

While managing SharePoint and OneDrive permissions requires specialized Microsoft admin tools, WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for your everyday document creation and editing needs.

  1. 1. Download WPS Office: Visit the official WPS website and click the download button for your preferred operating system.
  2. 2. Install the Software: Run the downloaded installer file and follow the simple on-screen instructions to complete the setup.
  3. 3. Open and Edit Documents: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office files without any formatting loss.
Highly compatible with Microsoft Word, Excel, and PowerPoint formatsLightweight installation with remarkably fast loading timesFamiliar, intuitive user interface for a seamless migrationBuilt-in PDF editing, merging, and document conversion tools
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get an Access Denied error when running Set-SPOUser?

This error typically occurs if your administrator account lacks Global or SharePoint Administrator privileges, or if your PowerShell session was connected to a standard SharePoint site instead of the dedicated admin center URL.

Can I remove a user from all SharePoint sites without using PowerShell?

While you can manually remove users from individual sites via the SharePoint Admin Center GUI, removing a user from all sites across an entire organization is highly impractical manually and is significantly faster and more reliable when automated using a PowerShell script.

Do I need a specific PowerShell module for these commands to work?

Yes, you must download and install the SharePoint Online Management Shell from Microsoft to utilize administrative commands like Connect-SPOService, Get-SPOSite, and Set-SPOUser.