# Permissions Cleanup & Governance Prep Checklist

> Audit and fix an on-premises SharePoint permission model (broken inheritance, orphaned accounts, oversharing) before you migrate, so you move a clean model once and lay the groundwork for Copilot.

1.  [Home](https://tenantcraft.ca/)
2.   [Insights](https://tenantcraft.ca/insights)
3.   Permissions Cleanup & Governance Prep Checklist

Plan Permissions 45 checkpoints

Last reviewed May 16, 2026 · 7 pages in print

Before you start

## Clean the model before you move it

A migration copies your permission model exactly as it is: every broken inheritance, every account that left three years ago, every “share with Everyone” nobody remembers making. Fix it on the source first and you move a clean model once. Skip this and you rebuild it under pressure in SharePoint Online, where Copilot will read every loose grant straight back to your staff. Work the stages in order; the audit stages come first because you cannot fix what you have not found.

The limits that decide what is clean
| Item | What it means |
| --- | --- |
| 5,000 scopes | Recommended ceiling of unique permission scopes per list or library. Past it, migration slows and degrades. |
| 50,000 scopes | The hard limit per list. A library past this will not migrate cleanly. It must be restructured first. |
| 100,000 items | Above this you can no longer break or restore permission inheritance on a list or folder. Decide its model before it grows. |
| Inherited rights | Not migrated. Target content re-inherits from its new parent, so fix inheritance before you move, not after. |
| “Deny” rights | Dropped entirely by the migration tool. A Deny-based block becomes open access in SharePoint Online. |
| Orphaned accounts | An account with no match in Microsoft Entra ID is dropped; the item falls back to its parent’s permissions. |

The eight stages

1.  1Scope, inventory, and tooling baseline5 checkpoints
2.  2Map broken inheritance and scope sprawl6 checkpoints
3.  3Hunt oversharing and broad grants5 checkpoints
4.  4Hunt orphaned and over-privileged accounts6 checkpoints
5.  5Prepare identity, Active Directory to Entra ID6 checkpoints
6.  6Design the clean permission model5 checkpoints
7.  7Remediate permissions6 checkpoints
8.  8Validate and set governance6 checkpoints

Stage one · Audit

## Scope, inventory, and tooling baseline

5 checkpoints

-   Define exactly which **site collections are in migration scope**. The permission work follows the scope, not the whole farm.
-   Enumerate every **web, list, and library** with its item count. This is the structure you will audit against.
-   Run the **SPMT scan** and export its assessment report. It flags large lists and unique-permission risk codes.
-   Run a **PowerShell pass** for permission scopes and role assignments: the detail the scan does not surface.
-   Confirm whether **Active Directory already syncs to Microsoft Entra ID**. This decides whether any permission can survive the move.

Stage two · Audit

## Map broken inheritance and scope sprawl

6 checkpoints

-   Flag every **web with broken inheritance** from its parent site.
-   Flag every **list and library with unique permissions**. Count the unique scopes on each.
-   Flag libraries over **5,000 unique scopes** (slow, degraded) and over **50,000** (will not migrate cleanly).
-   Flag any list or library over **100,000 items**. Inheritance can no longer be broken or restored on it.
-   Identify **item-level permission sprawl**: individual files and folders carrying their own permissions.
-   Note **“Limited Access” build-up**: the silent grants SharePoint adds whenever someone is given a single item.

Stage three · Audit

## Hunt oversharing and broad grants

5 checkpoints

-   Find every grant to **“Everyone”** or **“Everyone except external users”**. In SharePoint Online these reach the whole organization.
-   Find every grant to **“All Authenticated Users”** or **NT AUTHORITY\\authenticated users**.
-   Flag any site or web application with **anonymous access** enabled.
-   Flag **direct user grants** made instead of using a group. Flag permission levels that let members re-share.
-   Treat every broad grant as a finding to **justify or remove**. Copilot will surface whatever it can reach.

Stage four · Audit

## Hunt orphaned and over-privileged accounts

6 checkpoints

-   Identify **orphaned permissions**: disabled or deleted accounts still on permission lists.
-   Identify **AD security groups** that are empty, deleted, or no longer resolve.
-   Flag **service, farm, and system accounts** that appear on content permissions.
-   Inventory every **site collection administrator** and confirm each is current. Admins bypass all other permissions.
-   Inventory **external and guest users** with their last activity. Retire access left over from finished projects.
-   Flag every **custom permission level** and every **“Deny” permission**. Both need manual handling before the move.

Stage five · Prepare

## Prepare identity, Active Directory to Entra ID

6 checkpoints

-   Stand up **Entra Connect** (or Cloud Sync) so every account and group used in SharePoint has a cloud identity.
-   Reconcile **every principal on a permission list** against the directory. A missing match means a dropped grant.
-   Clean up **orphaned and disabled accounts in Active Directory** so they never sync to the cloud.
-   Decide per AD security group: **keep it synced** or rebuild it as a Microsoft 365 or Entra group.
-   Build an **SPMT user-mapping file** for any account whose name or sign-in has changed.
-   Confirm **no sensitive item** is protected only by a “Deny” or only by an orphaned account.

Stage six · Design

## Design the clean permission model

5 checkpoints

-   Grant access **through groups**, never to individual users named directly on content.
-   **Maximize inheritance**. Every unique scope you keep must earn its place.
-   Standardize on the **three default SharePoint groups** per site: Owners, Members, Visitors.
-   Use a **separate site** for each genuine access boundary instead of uniquely-permissioned folders inside a shared site.
-   Cap **site collection administrators** at two named, current people.

Stage seven · Remediate

## Remediate permissions

6 checkpoints

-   **Restore inheritance** everywhere a unique scope is not deliberate.
-   **Consolidate scattered item-level grants**: move the files into one folder and set the permission once.
-   Replace every **“Everyone” and broad grant** with a scoped group sized to who actually needs the content.
-   **Redesign every “Deny”** as an explicit allow-list before the migration silently drops it.
-   Remove **orphaned accounts, stale guests, and over-privileged admins** from every permission list.
-   Merge **duplicate and empty groups** (AD and SharePoint) down to the documented model.

Stage eight · Validate

## Validate and set governance

6 checkpoints

-   Confirm **no library still exceeds 5,000 unique scopes**, and that none needs unique permissions it can no longer be given.
-   **Pilot-migrate one cleaned site** and verify the permissions land exactly as designed.
-   Plan a **multi-phase security import** for any site with more than 100,000 child items.
-   Set the **tenant and per-site external sharing levels** before users arrive.
-   Set the **default sharing link** to a restrictive type. Decide who can create sites.
-   Record that a **clean, group-based model** is the prerequisite for safely turning on Microsoft 365 Copilot.

If the cleanup outgrows the calendar

## Permission messes are deep, and the deadline is not moving.

The audit stages have a way of turning up more than anyone expected: thousands of item-level grants, “Everyone” on a folder of contracts, admin accounts belonging to people who left in 2021. If the findings outrun the time you have before July 14, 2026, that is the work TenantCraft does: untangling permission models and landing them clean in SharePoint Online. A discovery call is free, 25 minutes, and ends with a written scope, not a sales pitch.

Web

tenantcraft.ca

Email

hello@tenantcraft.ca

Discovery call

Free · 25 minutes

Checklist last reviewed May 16, 2026. SharePoint Server 2016 and 2019 reach end of support on July 14, 2026. Clean the permission model before you migrate, while the cleanup is still cheap and the deadline is still ahead of you.

In this guide

1.  01 [Scope, inventory, and tooling baseline](#scope-inventory-and-tooling-baseline)
2.  02 [Map broken inheritance and scope sprawl](#map-broken-inheritance-and-scope-sprawl)
3.  03 [Hunt oversharing and broad grants](#hunt-oversharing-and-broad-grants)
4.  04 [Hunt orphaned and over-privileged accounts](#hunt-orphaned-and-over-privileged-accounts)
5.  05 [Prepare identity, Active Directory to Entra ID](#prepare-identity-active-directory-to-entra-id)
6.  06 [Design the clean permission model](#design-the-clean-permission-model)
7.  07 [Remediate permissions](#remediate-permissions)
8.  08 [Validate and set governance](#validate-and-set-governance)

Printable copy

The whole guide is on this page already. If you'd rather work from paper, or hand it to someone who will, the PDF is the same document laid out for printing.

Email me the PDF

One email with the link. No drip sequence, no upsell. Unsubscribe any time.

Thanks, the PDF is on its way to your inbox.

Sneak peek, read it now [Download the PDF](https://tenantcraft.ca/downloads/permissions-cleanup-prep.pdf)

Something went wrong. Email [hello@tenantcraft.ca](mailto:hello@tenantcraft.ca) and I'll send it manually.

The background reading

-   [EWSAllowedAppIDs before October 10: find and test every EWS app](https://tenantcraft.ca/insights/ewsallowedappids-find-test-ews-apps)

    On October 10, 2026, turning EWS on stops being enough. Exchange Online will want a list of the exact apps allowed to use it, and any app missing from that list can lose access. Here is how to find every app still calling EWS, build the list without wiping it, and prove it works before the date.

-   [How to find every SharePoint site with broken permission inheritance](https://tenantcraft.ca/insights/find-broken-permission-inheritance)

    The admin center will not tell you, unless you pay for SharePoint Advanced Management, and even then the report you want does not exist. Here is the check that works by hand, and the script that covers a whole tenant in two logins.

-   [Run a permissions audit before you migrate SharePoint](https://tenantcraft.ca/insights/permissions-cleanup-before-migration)

    A pre-migration permissions audit is cheap insurance. Skip it, or rush it, and you discover broken inheritance, orphaned access, and dropped grants one mystery support ticket at a time after cutover.

-   [Power Pages vs SharePoint sites: who the audience is decides it](https://tenantcraft.ca/insights/power-pages-vs-sharepoint-sites)

    SharePoint sites are for people inside your tenant. Power Pages is for everyone outside it. One question, who needs to use this, settles almost every case. Here's the honest split.

-   [Why your SharePoint search shows too much, and the one line that fixes it](https://tenantcraft.ca/insights/scope-sharepoint-search-box-to-one-site)

    Someone searches from your intranet and gets files from half the company. It looks like a permissions leak. It usually isn't. Here is what actually changed, the one command that puts it back, and the part most people are never told: this makes search tidier, not safer.

Next in the sequence

-   [InfoPath Forms Decision Tree](https://tenantcraft.ca/resources/guides/infopath-forms-decision-tree)

    Plan · InfoPath

-   [SharePoint Workflow Rebuild Playbook](https://tenantcraft.ca/resources/guides/sp2013-workflow-rebuild-playbook)

    Plan · Workflows

-   [SharePoint Server → SPO Migration Checklist](https://tenantcraft.ca/resources/guides/sp2016-eol-checklist)

    Plan · Migration

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/resources/guides/permissions-cleanup-prep · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
