Skip to content
Plan Permissions 45 checkpoints

Permissions Cleanup & Governance Prep Checklist

Audit and fix an on-premises SharePoint permission model (broken inheritance, orphaned accounts, oversharing) before you migrate, so you move a clean model once and lay the groundwork for Copilot.

Last reviewed May 16, 2026 · 7 pages in print

Before you start

Clean the model before you move it

A migration copies your permission model exactly as it is: every broken inheritance, every account that left three years ago, every “share with Everyone” nobody remembers making. Fix it on the source first and you move a clean model once. Skip this and you rebuild it under pressure in SharePoint Online, where Copilot will read every loose grant straight back to your staff. Work the stages in order; the audit stages come first because you cannot fix what you have not found.

The limits that decide what is clean
ItemWhat it means
5,000 scopes Recommended ceiling of unique permission scopes per list or library. Past it, migration slows and degrades.
50,000 scopes The hard limit per list. A library past this will not migrate cleanly. It must be restructured first.
100,000 items Above this you can no longer break or restore permission inheritance on a list or folder. Decide its model before it grows.
Inherited rights Not migrated. Target content re-inherits from its new parent, so fix inheritance before you move, not after.
“Deny” rights Dropped entirely by the migration tool. A Deny-based block becomes open access in SharePoint Online.
Orphaned accounts An account with no match in Microsoft Entra ID is dropped; the item falls back to its parent’s permissions.

The eight stages

  1. 1Scope, inventory, and tooling baseline5 checkpoints
  2. 2Map broken inheritance and scope sprawl6 checkpoints
  3. 3Hunt oversharing and broad grants5 checkpoints
  4. 4Hunt orphaned and over-privileged accounts6 checkpoints
  5. 5Prepare identity, Active Directory to Entra ID6 checkpoints
  6. 6Design the clean permission model5 checkpoints
  7. 7Remediate permissions6 checkpoints
  8. 8Validate and set governance6 checkpoints

Stage one · Audit

Scope, inventory, and tooling baseline

5 checkpoints

  • Define exactly which site collections are in migration scope. The permission work follows the scope, not the whole farm.
  • Enumerate every web, list, and library with its item count. This is the structure you will audit against.
  • Run the SPMT scan and export its assessment report. It flags large lists and unique-permission risk codes.
  • Run a PowerShell pass for permission scopes and role assignments: the detail the scan does not surface.
  • Confirm whether Active Directory already syncs to Microsoft Entra ID. This decides whether any permission can survive the move.

Stage two · Audit

Map broken inheritance and scope sprawl

6 checkpoints

  • Flag every web with broken inheritance from its parent site.
  • Flag every list and library with unique permissions. Count the unique scopes on each.
  • Flag libraries over 5,000 unique scopes (slow, degraded) and over 50,000 (will not migrate cleanly).
  • Flag any list or library over 100,000 items. Inheritance can no longer be broken or restored on it.
  • Identify item-level permission sprawl: individual files and folders carrying their own permissions.
  • Note “Limited Access” build-up: the silent grants SharePoint adds whenever someone is given a single item.

Stage three · Audit

Hunt oversharing and broad grants

5 checkpoints

  • Find every grant to “Everyone” or “Everyone except external users”. In SharePoint Online these reach the whole organization.
  • Find every grant to “All Authenticated Users” or NT AUTHORITY\authenticated users.
  • Flag any site or web application with anonymous access enabled.
  • Flag direct user grants made instead of using a group. Flag permission levels that let members re-share.
  • Treat every broad grant as a finding to justify or remove. Copilot will surface whatever it can reach.

Stage four · Audit

Hunt orphaned and over-privileged accounts

6 checkpoints

  • Identify orphaned permissions: disabled or deleted accounts still on permission lists.
  • Identify AD security groups that are empty, deleted, or no longer resolve.
  • Flag service, farm, and system accounts that appear on content permissions.
  • Inventory every site collection administrator and confirm each is current. Admins bypass all other permissions.
  • Inventory external and guest users with their last activity. Retire access left over from finished projects.
  • Flag every custom permission level and every “Deny” permission. Both need manual handling before the move.

Stage five · Prepare

Prepare identity, Active Directory to Entra ID

6 checkpoints

  • Stand up Entra Connect (or Cloud Sync) so every account and group used in SharePoint has a cloud identity.
  • Reconcile every principal on a permission list against the directory. A missing match means a dropped grant.
  • Clean up orphaned and disabled accounts in Active Directory so they never sync to the cloud.
  • Decide per AD security group: keep it synced or rebuild it as a Microsoft 365 or Entra group.
  • Build an SPMT user-mapping file for any account whose name or sign-in has changed.
  • Confirm no sensitive item is protected only by a “Deny” or only by an orphaned account.

Stage six · Design

Design the clean permission model

5 checkpoints

  • Grant access through groups, never to individual users named directly on content.
  • Maximize inheritance. Every unique scope you keep must earn its place.
  • Standardize on the three default SharePoint groups per site: Owners, Members, Visitors.
  • Use a separate site for each genuine access boundary instead of uniquely-permissioned folders inside a shared site.
  • Cap site collection administrators at two named, current people.

Stage seven · Remediate

Remediate permissions

6 checkpoints

  • Restore inheritance everywhere a unique scope is not deliberate.
  • Consolidate scattered item-level grants: move the files into one folder and set the permission once.
  • Replace every “Everyone” and broad grant with a scoped group sized to who actually needs the content.
  • Redesign every “Deny” as an explicit allow-list before the migration silently drops it.
  • Remove orphaned accounts, stale guests, and over-privileged admins from every permission list.
  • Merge duplicate and empty groups (AD and SharePoint) down to the documented model.

Stage eight · Validate

Validate and set governance

6 checkpoints

  • Confirm no library still exceeds 5,000 unique scopes, and that none needs unique permissions it can no longer be given.
  • Pilot-migrate one cleaned site and verify the permissions land exactly as designed.
  • Plan a multi-phase security import for any site with more than 100,000 child items.
  • Set the tenant and per-site external sharing levels before users arrive.
  • Set the default sharing link to a restrictive type. Decide who can create sites.
  • Record that a clean, group-based model is the prerequisite for safely turning on Microsoft 365 Copilot.

If the cleanup outgrows the calendar

Permission messes are deep, and the deadline is not moving.

The audit stages have a way of turning up more than anyone expected: thousands of item-level grants, “Everyone” on a folder of contracts, admin accounts belonging to people who left in 2021. If the findings outrun the time you have before July 14, 2026, that is the work TenantCraft does: untangling permission models and landing them clean in SharePoint Online. A discovery call is free, 25 minutes, and ends with a written scope, not a sales pitch.

Web
tenantcraft.ca
Email
hello@tenantcraft.ca
Discovery call
Free · 25 minutes

Checklist last reviewed May 16, 2026. SharePoint Server 2016 and 2019 reach end of support on July 14, 2026. Clean the permission model before you migrate, while the cleanup is still cheap and the deadline is still ahead of you.

The background reading

Next in the sequence

TWENTY MINUTES, NO PITCH

Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

Sneak peek

Document preview

100%

Loading the document…