Are you storing your essential data on SharePoint? If yes, then you will need to proactively audit any permission changes in SharePoint. In many cases, employees are given excessive privileges and inadvertently leak, delete or distribute confidential files that they should never have had access to in the first place. To ensure the security of your SharePoint data, it is essential to detect permission changes the moment they occur. In this article, the steps to audit SharePoint permission changes for both SharePoint Server and SharePoint Online are explained; first by using the native method and then an alternative, more straightforward method, using Lepide Auditor for SharePoint.
Audit Permissions and Access Changes in SharePoint Server
Step 1- Enable Auditing
The following are the steps for enabling native auditing:
- Open SharePoint Central Administration, Go to Settings, Site Settings
- Navigate to Site Collection Administration, Site collection, audit settings
- Next, select Editing users and permissions, and click OK
Figure 1: Enabling permission change auditing - Navigate to Settings, Site Settings, Site Collection Administration, Site collection audit settings, Features, Activate Reporting.
NOTE: This step is required if “Reporting” has not been activated earlier. If you have already activated reporting, you can skip this step.
Figure 2: Activating reporting NOTE: To find out whether reporting has been enabled or not, go to “Site Collection Administration” and check whether the “Audit log reports” is visible or not.
Step 2- View the Permission Changes Report
Perform the following steps:
- Go to Settings, Site settings, Site Collection Administration, Audit Log Reports
- The View Auditing Reports page appears. In this case, since we want to see permission changes report, you will have to click Security Settings

- Click “Browse” button to the folder where you want to save the report and click “OK”
- The Operation Completed Successfully page appears, click the click here to view the report link to save the report on the disk.
Figure 4: Report saved on local disk - The following screenshot shows the native permission change report opened in Microsoft Excel.
Figure 5: Permission change report
Audit Permissions and Access Changes in SharePoint Online
The following are the options available to enable native auditing in SharePoint Online:
1. Using Microsoft Purview Audit Logs
Permission changes in SharePoint Online are recorded within the Microsoft 365 audit log.
- Open the Microsoft 365 Compliance Portal through Microsoft Purview
- Navigate to Solutions, Audit
- Search for activities such as:
- Added member to SharePoint group
- Removed user from SharePoint group
- Changed site permissions
- Sharing invitation created
- Anonymous link created
- Site collection administrator changes

2. Using PowerShell
- Administrators can retrieve audit records using Exchange Online PowerShell using the following cmdlet:
Search-UnifiedAuditLog - This allows the filtering of permission-related activities over specific date ranges.
3. Review Site Permissions Directly
-
- Open the SharePoint site
- Go to Site Permissions
- Review the following:
- SharePoint groups
- Direct user permissions
- External sharing permissions
- Site collection administrators
This shows the current state but not historical changes.
Issues with Native Auditing for SharePoint
The following are drawbacks of the native auditing:
- Keeping track of the configuration and content can be complicated.
- Lacks the facility to store data from multiple SharePoint Servers in one centralized and secure database.
- Predefined reports lack flexibility as it is difficult to search for changes based on object path, users and resource. Filtering and sorting the reports is also not easy.
How Lepide Helps
Managing SharePoint permissions and monitoring access changes can become challenging as environments grow in size and complexity. While native auditing provides basic visibility, investigating permission changes across multiple site collections and generating meaningful reports can be time-consuming.
Lepide Auditor for SharePoint simplifies the process of auditing SharePoint permissions and access changes by providing real-time visibility into who changed permissions, what action was performed, when the change occurred, and where the activity originated. From a single console, administrators can audit both SharePoint Online and SharePoint Server, with all audit data stored in a centralized, secure repository for long-term analysis, compliance reporting, and security investigations.
The solution includes a comprehensive library of predefined reports that help administrators track permission changes, monitor user activity, investigate suspicious behavior, and demonstrate compliance. One such report, SharePoint Online Site Collection Permission Changes, is shown below.

The report provides a detailed audit trail of permission-related activities across SharePoint site collections. It shows the affected site collection, the user who performed the action, the date and time of the change, the permission operation (such as Permission Level Granted), and the source IP address. These insights enable administrators to quickly investigate unauthorized permission changes, verify administrative actions, and simplify compliance reporting.