Last Updated on October 7, 2026 by Satyendra
- Granular permissions are only effective when organizations can understand, review, and govern the access they create.
- Lepide’s 2026 research found that 79% of organizations assessed had users with excessive permissions, up to 83% of privileged accounts inherited administrative rights through nested group membership, and 90% had enabled inactive Active Directory accounts
- Access risks depend on more than permissions alone. They should be evaluated in the context of identity, effective access, data sensitivity, actual usage, and business need.
- AI tools such as Microsoft 365 Copilot do not inherently grant users new permissions to Microsoft 365 content. However, they can make information that users are already authorized to access easier to discover and use.
- Governing granular access controls is continuous: discover, resolve, understand, compare, remediate, monitor.
Organizations are investing heavily in granular permissions, and the market reflects it. The Business Research Company’s Granular Permissions Global Market Report 2026 names Lepide among the companies profiled in the market and forecasts growth from $3.96 billion in 2026 to $7.9 billion by 2030.
Granular permissions aren’t primarily a problem of creating more detailed access controls. The tough part is understanding what access users actually end up with once direct permissions, inherited permissions, nested groups, stale access, and changing business requirements are combined. Lepide’s own assessment data suggests many organizations still struggle to answer a basic question: who can reach our sensitive data and how?
What are Granular Permissions?
Granular permissions control precisely which users can access resources and what actions they can perform on them. Rather than granting broad access to a whole system or file share, granular access rights let administrators decide who can read, edit, share**, or** delete a specific folder, file, site**, or** application.
However, the security challenge isn’t whether granular access controls exist. It is about whether businesses are able to determine what kind of access each of their users actually receives through the combination of permissions granted directly, membership in groups, inherited permissions, and file sharing.
Effective Access Matters More Than Assigned Access
Most permission reviews start from the access control list (ACL) that shows what is assigned to the resource. Effective access refers to the access a user ultimately receives after the applicable authorization mechanisms for a resource are evaluated. Depending on the platform, these can include direct and inherited permissions, group membership, nested group membership, share permissions, and sharing mechanisms.
- Direct Permissions
- Inherited Permissions
- Security Group Membership
- Nested Group Membership
- SharePoint site, library, folder, and item permissions
- Sharing links and other sharing mechanisms
- Access granted for an old role or project
Each route can look reasonable on its own. When combined, they yield access that was never intended. This shows that granular access is not a guarantee of least privilege. Lepide provides visibility into effective permissions and the access paths behind them, along with context about data sensitivity and user activity. While an ACL shows permissions configured on a resource, effective access helps determine the access a user ultimately receives. Whether that access is appropriate must then be evaluated against factors such as business need, data sensitivity, and usage
Lepide in Real Environments When Assessing Granular Access Controls
As part of Lepide’s 2026 identity and data security research, we analyze real-world Identity and Data Risk Assessments across organizations in sectors including government, education, manufacturing, utilities, and commercial services. The findings stand out:
- 79% had users with excessive permissions. Excessive permissions occur when users retain or receive access beyond what is required for their legitimate business responsibilities.
- Up to 83% of privileged accounts inherited administrative rights through nested groups. This emphasizes why it is important to analyze accounts in greater detail rather than looking only at direct access rights. The administrative access came through various group relationships that are easy to overlook when examining a single account.
- 90% had enabled inactive Active Directory accounts. Although certain accounts may not be currently used, their group memberships and access rights can still be important with regard to potential access.
These figures come from Lepide’s assessments and should not be interpreted as representative statistics for every enterprise globally. Even so, they point to a consistent pattern the intended design of granular permissions and the reality of effective access frequently diverge.
How Do Granular Access Controls Become Excessive Access?
There are five ways well-designed granular permissions can drift into excessive access.
- Permission Inheritance: A sensitive Payroll folder inherits permissions from a broader Finance folder. If those inherited permissions give users access to Payroll data they don’t need, the inherited access becomes excessive even though no one explicitly assigned those users permission to the Payroll folder.
- Nested Group Membership: A user may receive privileged access through multiple layers of group membership. Because the access is inherited through nested groups rather than assigned directly to the user’s account, a review of the user’s direct permissions may not reveal the full access path.
- Access That Outlives Its Business Purpose: Someone legitimately received access for a project, an acquisition, or a previous role. The access was correct when granted. Later, it wasn’t. Access granted for a project or previous role may remain in place if the organization does not have effective lifecycle or expiration controls to remove it.
- Inactive Identities Retaining Access: An account may not have been used for an extended period but can remain enabled and retain group memberships, permissions, and other access entitlements.
- Sensitive Data Moving Underneath Existing Permissions: The permissions may not change at all. Someone places a sensitive document in an already broadly accessible location, and the risk changes even though the ACL doesn’t.
Why Don’t Permissions Alone Tell You Whether Access Is Risky?
Knowing that someone has access to a resource doesn’t tell you whether that access is a problem. Risk depends on context, and a simple model captures it:
A practical way to assess access risk is to consider: Identity + Effective Access + Data Sensitivity + Usage + Business Need
| Access Factor | What to Evaluate |
|---|---|
| Identity | Who is the user, and is the account active and legitimate? |
| Effective Access | What resources and actions are available to the user after the applicable access-control mechanisms are evaluated? |
| Data Sensitivity | How sensitive is the data they can reach? |
| Usage | Access that is unused and cannot be justified by a current business need is a strong candidate for review or removal, particularly when it involves sensitive information. |
| Business Need | Do they still have a reason to have it? |
Granting access rights to sensitive information poses very different challenges than using those rights in a justified manner. Lepide’s Data Access Governance combines sensitive-data discovery, effective permissions, and user activity rather than treating granular access controls as an isolated dataset. That’s what turns granular access control from a configuration exercise into a risk-management one.
Granular Access Governance Must Answer “Should They Have Access?” Not Just “Can They Access It?”
Traditional permission reviews often focus on one question: Who has access? Effective access governance should also ask: How did they obtain that access? What can they do with it? Are they using it? What data can they reach? And do they still need that access?
This matters because generating tons of permission statistics doesn’t address the issue. A report that shows all the permissions of every user is accurate but impractical. Reviewers can’t judge what they can’t put in context.
This connects to the central finding of our research. The organizations we assessed weren’t necessarily lacking security controls. They lacked context across identities, permissions, sensitive data, and activity. We refer to this phenomenon as Identity-Data Disconnect, where the understanding of the users is not in sync with their accessibility of data and the data itself. Granular permissions are one of the places where that disconnect does the most damage, because the more finely access is defined, the more it depends on understanding how those definitions combine.
Why Does AI Make Permissions Granularity More Consequential?
AI hasn’t created the underlying permission problem. It has changed the consequences of leaving it unresolved.
Microsoft states that Microsoft 365 Copilot operates within existing permissions and access controls and that overshared or poorly governed content can affect Copilot results and increase risk. If your granular access controls have drifted, Copilot will work faithfully within that drift. Consider the difference between:
- Before AI: An employee may have had access to a large volume of content without knowing what information was available or where it was stored.
- With Microsoft 365 Copilot: The employee can use natural-language prompts to find, summarize, and reason over relevant organizational content that Copilot can access on their behalf within applicable Microsoft 365 permissions and security boundaries.
Same Permissions. Different Level of Discoverability.
Each of the scenarios above becomes more significant. Inherited payroll access, a nested administrative right, a forgotten project permission, an enabled dormant account, a sensitive file dropped into an open location: discovering that information might have required users to know where to look or manually search across multiple repositories. Microsoft 365 Copilot can make information within a user’s authorized access boundary easier to discover and use through natural-language interaction.
Lepide’s Copilot security capabilities provide visibility into sensitive data accessed through Copilot, including the user, file, sensitivity information, search query, and associated Copilot conversation context. The adoption of AI tools that can retrieve and reason over organizational data makes accurate access governance increasingly important because existing access determines what information those tools may be able to surface to a user.
What Good Granular Permissions Governance Actually Looks Like?
Governing granular permissions doesn’t need to be a sprawling program. The goal is to create an easy-to-follow procedure that allows organizations to understand who has access to sensitive information, why they have that access, and whether they should still have that access. The approach can consist of five simple steps.
- Discover Sensitive Data: Start by identifying where any sensitive, regulated, or critical business data is located, including information stored on file servers, in cloud systems, in applications, and on collaborative platforms. Classifying data helps organizations understand what categories of restrictions should be applied to authorization processes.
- Resolve Effective Access: Determine each user’s effective access by evaluating the authorization mechanisms applicable to the resource. These may include direct and inherited permissions, group and nested-group membership, NTFS and SMB share permissions, SharePoint permissions, and applicable sharing mechanisms. There is one question you should be able to answer: What can a specific user access?
- Understand How the Access Was Obtained: Knowing that someone has access is only half the picture. It is also necessary to understand how the user received this access and through which access path it was granted. If the access was provided explicitly, inherited from a parent folder, received via a nested group, or given through an external sharing method, different remedial actions may be required.
- Compare Permissions with Actual Usage and Business Need: Not all access represents a real business requirement. By comparing granted permissions with actual data usage, role, and business justification, organizations can identify access that is excessive, dormant, or no longer necessary. Unused access that no longer has a valid business justification is a strong candidate for removal or reduction, particularly when it provides access to sensitive information. Remediation should be validated to avoid disrupting legitimate business processes.
- Remove Unnecessary Access and Monitor for Regression: Once excessive access has been identified, remove or reduce it in a controlled way and verify that legitimate business processes continue to work. Access rights tend to drift over time as personnel change, groups are changed and new sharing options are established. Therefore, access rights should be monitored continuously to prevent excessive access from being granted again.
The key principle is that granular permissions governance is not only about making permissions tighter. It’s about maintaining sustainable relationships between sensitive data, an individual’s identity, access paths, and actual business needs, as well as keeping those relationships correct over time.
Where Lepide Fits
Lepide connects identity, sensitive data, effective permissions, and user activity, so organisations can move from asking “who has access?” to determining “who has access they don’t need?”
In practice, that means four capabilities:
- Discover sensitive data across your environment.
- Understand effective access to it, including inherited and nested permissions.
- Identify excessive permissions using access and usage context.
- Remediate excessive access and continuously monitor for permission and access drift to support least privilege.
Schedule a demo to see how Lepide can help you identify and reduce excessive access across your environment.
Frequently Asked Questions
Microsoft 365 Copilot operates within existing permissions, so excessive or poorly governed access can become easier to discover when users retrieve information through natural-language queries.
Assigned permissions are what’s configured on a resource. Effective permissions describe the resultant permissions a user has after the applicable access-control mechanisms are evaluated. Depending on the platform, these can include direct and inherited permissions, group membership, nested groups, share permissions, and sharing mechanisms.
Detailed permissions can accumulate and interact through inheritance, nested groups, sharing, and old role or project access, while access may not be regularly reviewed against usage and business need.