See who can access content across your SharePoint sites and OneDrive accounts.
The Permissions matrix report (PMR) reveals a content hierarchy for the sites you select and surfaces every permission at each level, so you can spot oversharing and identify broken permission inheritance.
You can find the Permissions matrix report in the Reporting section of ShareGate Protect.
Do you want to talk about the Permissions matrix report with our product manager?
Before you start
The PMR uses data from your tenant's permissions crawl, which refreshes approximately every 24 hours. The data you see is not real-time.
If your tenant's initial permissions crawl is still in progress, results appear progressively as sites are processed.
The PMR shows the direct members of SharePoint groups. Nested memberships of Microsoft 365 groups and security groups are not yet displayed.
The PMR is a read-only report. Remediation actions are not yet available.
Run the Permissions matrix report
Select Reports from the sidebar menu.
Click the Permissions matrix report card.
Use filtering to find the SharePoint sites and OneDrives you want to report on:
Select All, OneDrives, or SharePoint sites at the top.
If you select SharePoint sites, filters will appear to filter by whether a SharePoint site has a Microsoft 365 group and team, a Microsoft 365 group only, or no Microsoft group associated with it.
Click Filters to use the filters available for SharePoint sites.
Select the sites you want to report on with checkmarks.
Click on the checkmark in the header row to select all the sites on the page.
A Select all sites prompt will appear when your sites span multiple pages in the report.
Select View report.
Read the report results
The PMR displays your content as a hierarchy:
Sites and subsites
Document libraries and lists
Folders and documents are shown after you expand their library, only when they have unique permissions (broken permission inheritance from their parent)
List items are not included in this version of the PMR.
For each item in the hierarchy, the report lists all users and groups with access, with one row per permission.
A user who has access through multiple paths appears on multiple rows, so you can see exactly how each access was granted.
When you run a report, each site is expanded by default down to the document library and list level.
You can expand document libraries further to view any folders and documents with unique permissions (you can only expand them when they contain items with unique permissions).
You can also collapse individual sites to show less detail. Site-level permissions remain visible when a site is collapsed.
Permission levels
The PMR uses simplified permission buckets instead of SharePoint's full list of permission levels:
Bucket | What it means | SharePoint permission levels included |
Full control | Can read, edit, delete, and manage permissions for others | Full control |
Write | Can create and edit content | Contribute, Edit, Design |
Read | Can view content only | Read |
Partial access | Can only access content explicitly shared with them | Restricted view, Review |
Custom | A permission level that does not map to a standard bucket. Behavior differs by object type: for files and folders, custom permission levels are mapped to Full control, Write, or Read if they match those categories. For site collections, subsites, lists, and document libraries, custom permission levels always display as Custom. | Any permission level |
Who appears in the report
The PMR lists all users and groups with access to your content.
User types:
Internal user: a member of your organization
External user: anyone outside your organization, including guests added to your Microsoft 365 tenant via Azure Active Directory B2B and people who access content without a guest account in Entra ID. Both appear as "External user" in the report.
Group types:
Microsoft 365 group
Security group
SharePoint group: includes default groups (Owners, Members, Visitors) and custom groups.
Built-in principals: Everyone except external users (EEEU), Everyone, and All users.
The PMR also shows sharing links. For "Specific people" links, the report lists the individual users the link grants access to.
What's not yet available
This version of the PMR is focused on visibility. The following capabilities are planned for future updates:
Nested group memberships: The direct members of SharePoint groups are shown, but nested memberships of Microsoft 365 groups and security groups are not yet expanded.
Site collection administrators: Visibility into site collection admin roles is not included in this first version.
Remediation actions: You cannot take action on permissions from within the report yet.
Export: We are considering adding an option to export the report as an Excel document, along with other options that allow an admin to share it with other stakeholders while preserving its structure and format.
Saved scope: You cannot save or bookmark a scoped view to return to later.
How this compares to the Permissions Matrix Report in ShareGate Migrate
The Protect PMR and the Permissions Matrix Report in ShareGate Migrate serve different needs. Migrate's PMR remains the go-to tool for migration validation.
Both reports cover SharePoint and OneDrive using a content-centric approach. The key differences:
| Protect PMR | Migrate PMR |
How data is collected | Continuous tenant crawl, refreshed every ~24 hours | On-demand scan |
Report speed | Results appear in seconds | It can take hours for large tenants |
Permissions required | Managed via ShareGate Home access controls. No site collection admin role needed. | Site collection admin permissions required on targeted sites |
Permission levels shown | Simplified buckets (Full control, Write, Read, Partial access, Custom) | Granular SharePoint permission levels |
Access paths | One row per user per permission, accurately reflecting access paths | One row per user with all permissions. Access paths not fully reflected. |
Export | Not available in this version | Excel export available |
