How to Resolve SharePoint and OneDrive User ID Mismatch Errors
Question details
A returning user experiences access-denied errors when attempting to open files shared across multiple SharePoint sites and OneDrive due to a user identity mismatch.

- Product
- Microsoft SharePoint and OneDrive
- Device & OS
- not provided
- Scenario
- A user left the organization and later returned with a newly created identity. Colleagues are trying to share files with the returning employee, but the user is blocked from accessing them.
- Observed behavior
- Access-denied errors are triggered because the user's obsolete, previous identity is still active in the site's access list, causing a conflict with their new active credentials.
Ensure you have SharePoint Administrator or Global Administrator privileges in Microsoft 365, as well as access to the SharePoint Online Management Shell to execute tenant-wide identity audits.
Remove the Obsolete Identity using a PowerShell Script
The most effective tenant-wide approach to audit and safely delete the mismatched account from all SharePoint and OneDrive sites.
Because the user has a new identity, their old profile remains cached in the hidden UserInfo list of various site collections. A PowerShell script is required to scan all site collections and remove these obsolete entries effectively.
Open the SharePoint Online Management Shell and run the command `Connect-SPOService -Url https://yourtenant-admin.sharepoint.com` to connect to your admin center.
Prepare a PowerShell script designed to iterate through all site collections and locate the user's old identity using their old User Principal Name (UPN).
Target a single, specific SharePoint test site collection where the issue is confirmed. Run the script to verify that it correctly identifies and deletes the obsolete account without affecting other permissions.
Once the script is thoroughly tested, execute it across all affected SharePoint sites and OneDrive instances to completely clear the old identity from your tenant's access lists.

Manually Remove the User from Individual Site Access Lists
A quick, manual workaround for individual sites if you prefer not to use PowerShell or only have one affected site.
Discover WPS Office: A Lightweight and Free Alternative
While resolving administrative permissions and identity mismatches in Microsoft 365 can be highly complex, managing documents doesn't have to be. WPS Office offers a streamlined, standalone experience for creating and editing documents, free from complicated tenant permission issues. Enjoy a lightweight, highly compatible alternative for your team's daily productivity needs.
- 1. Download and Install: Visit the official WPS Office website to download the free, lightweight installer for Windows, Mac, or Linux systems.
- 2. Open Your Documents: Launch WPS Office and directly open your existing Microsoft Office files without worrying about format conversion or data loss.
- 3. Collaborate Freely: Use built-in tools or standard local network sharing to work together seamlessly without complex enterprise permission hurdles.

Frequently Asked Questions
Why do returning employees get access-denied errors in SharePoint?
When an employee leaves and returns with a new user account, SharePoint often caches their old identity in the site's hidden UserInfo list. This identity mismatch prevents their new, active credentials from accessing files that were shared with the old account.
Can I resolve a user ID mismatch without using PowerShell?
Yes, but only on a site-by-site basis. Site administrators can manually access the advanced permissions page of individual SharePoint sites to remove the old user identity, after which the files must be re-shared.
How do I find the hidden user access list in a SharePoint site?
You can view the hidden UserInfo list by navigating to your SharePoint site and appending `/_layouts/15/people.aspx?MembershipGroupId=0` to the end of the site URL.
Will deleting the old user account from a site delete their previously authored files?
No. Removing an obsolete user identity from a site's access list only removes their access permissions; it does not delete or alter any documents they created or modified during their previous employment.




