Office 365 permissions report software

Who can open what? A permissions report that is right today, not last quarter.

A permissions export shows declared permissions and goes stale the moment it finishes - and it rarely shows that an ordinary account can reach 400,000 files through three nested groups and a link from 2022. 1Security keeps effective access resolved continuously across sites, files, mailboxes, groups, apps and sharing links, so your Office 365 permissions report is whatever view you are looking at, exported.

The problem

Declared permissions are not the answer to the question.

The question behind every permissions report is "who can actually open this?", and a declared-permissions export does not answer it. Site permissions, group memberships, mailbox delegates and sharing links are four different lists, and the answer only appears once they are resolved together.

Real access is assembled: a user reaches a file through a group nested inside another group, through a site permission inherited three levels up, or through an "anyone" link somebody created years ago and that never expires. Stitching that together with scripts is days of work per report - it is common to see 40+ hours per quarter on a mid-size tenant - and the result is out of date before anyone reads it.

The numbers a live report shows are usually the surprise: hundreds of thousands of files reachable by a single non-admin account, thousands of anyone links, dozens of guests still holding access after a year without a sign-in, and shared mailboxes with delegates nobody has reviewed. A quarterly export hides all of it between exports.

In practice

From question to exported report in four clicks.

How a permissions report works when the graph does the resolving and you only pick the view.

  1. 01

    Ask from either side

    Open Users and pick a person: every site, file, mailbox and group they can reach, with a count on top - typically 50,000-500,000 files for a long-tenured employee. Or open Files and pick a document: every user, group, app and sharing link that opens it. Both directions read the same resolved graph.

  2. 02

    See why, not just that

    Every entry shows its path: the nested group, the inherited site permission, the sharing link, the app grant. Each hop is clickable, and the explanation is plain language a data owner can follow - "through Finance-All, member of Finance-Leads, inherited from the Budget site".

  3. 03

    Filter to the cut the report needs, then save it

    External users on finance sites, files reachable by a departing employee, admin-role holders without MFA, groups that unlock more than 100,000 files - each is a filter set. Save the view and share it tenant-wide so the next reviewer opens the same live report, not a copy.

  4. 04

    Export on demand

    Every list exports in full, with the filter state that produced it. The report you hand to the auditor is the screen you verified at 9:00, describing the tenant at 9:00 - and if they ask again in June, you export it again in June.

What makes it work

Three parts of the platform, one permissions report.

Permissions reporting runs on capabilities you can read about in depth.

  • Access management

    The permission graph: effective access resolved through nesting, links, inheritance and app grants, readable from a person or from a resource.

    Explore the feature
  • Reporting

    Saved views, tenant-wide sharing, full exports and scheduled digests built on the same live data.

    Explore the feature
  • Inventory

    Every site, OneDrive, group, guest, app and AI agent on one graph, so the report covers the resources the directory forgot.

    Explore the feature

FAQ

Common questions.

How is this different from a scripted permissions export?

An export lists declared permissions, one service at a time. 1Security reports effective access: what an identity can actually open once nested groups, site inheritance, sharing links, mailbox delegation and app grants are resolved together - and it reads in both directions, from a person to their reach or from a file to its audience.

How fresh is the data behind a report?

The report is the live screen. After the initial scan, permission changes and new sharing links surface within minutes at any tenant size, so an export made at 9:00 reflects the tenant at 9:00. Up to three years of activity history sits behind it if the question is "who actually opened it".

Can non-technical stakeholders use it?

Yes. Access paths are written in plain language - who, through which group or link, to what - and saved views can be shared so an auditor or a data owner opens the exact cut you prepared, live, without learning the product.

What does it need from our tenant?

A read-only app consent on standard Microsoft 365 licenses. No premium license, no agent, no scripts. First reports appear the same day; the largest tenants with tens of millions of files take longer to map completely.

Stop exporting. Start answering.

Connect read-only and pull your first effective-access report the same day - who can open what, and why - on standard Microsoft licenses.

Or stitch next quarter's report by hand again.