如何使用CSOM PowerShell检查用户SharePoint站点权限的归属方式
Let's break this down into manual verification steps first, then jump into the CSOM PowerShell script to automate the check—including detecting if a user has both direct and group-based permissions.
Manual Check: Direct Permissions vs. Group Membership
Checking Direct Site Permissions
- Navigate to your SharePoint site, click the gear icon (Settings) > Site permissions
- Click Advanced permissions settings at the bottom of the permissions pane
- Look for the user in the main list: users with direct permissions will appear as individual entries (not nested under any SharePoint group)
Checking Group-Based Permissions
- From the same Advanced permissions page, you can either:
- Click into each SharePoint group (like "Site Members" or "Site Owners") to review its member list
- Use the Check Permissions tool at the top: enter the user's email/username, click Check Now, and the results will explicitly show which groups grant them access (look for lines starting with "Granted via [Group Name]")
CSOM PowerShell Implementation
First, make sure you have the SharePoint Online CSOM module installed (skip if you already have it):
Install-Module -Name Microsoft.Online.SharePoint.PowerShell -Force
This script will check both direct permissions and group membership, and flag if the user has both types of access:
# Configuration - Update these values $siteUrl = "https://yourtenant.sharepoint.com/sites/yoursite" $targetUser = "user@yourtenant.com" $adminUsername = "admin@yourtenant.com" $adminPassword = Read-Host -Prompt "Enter admin password" -AsSecureString # Initialize CSOM context Connect-SPOService -Url "https://yourtenant-admin.sharepoint.com" -Credential (New-Object System.Management.Automation.PSCredential($adminUsername, $adminPassword)) $ctx = New-Object Microsoft.SharePoint.Client.ClientContext($siteUrl) $ctx.Credentials = New-Object Microsoft.SharePoint.Client.SharePointOnlineCredentials($adminUsername, $adminPassword) # Load site web and role assignments $web = $ctx.Web $ctx.Load($web) $ctx.Load($web.RoleAssignments) $ctx.ExecuteQuery() # Ensure the target user exists in the site $user = $web.EnsureUser($targetUser) $ctx.Load($user) $ctx.ExecuteQuery() # Initialize flags and group list $hasDirectAccess = $false $hasGroupAccess = $false $accessGroups = @() # Check for direct permissions foreach ($roleAssignment in $web.RoleAssignments) { $ctx.Load($roleAssignment.Member) $ctx.ExecuteQuery() if ($roleAssignment.Member.PrincipalType -eq [Microsoft.SharePoint.Client.PrincipalType]::User -and $roleAssignment.Member.LoginName -eq $user.LoginName) { $hasDirectAccess = $true break } } # Check for group membership-based permissions $siteGroups = $web.SiteGroups $ctx.Load($siteGroups) $ctx.ExecuteQuery() foreach ($group in $siteGroups) { $ctx.Load($group.Users) $ctx.ExecuteQuery() if ($group.Users | Where-Object { $_.LoginName -eq $user.LoginName }) { $hasGroupAccess = $true $accessGroups += $group.Title } } # Output the results Write-Host "`n=== Permission Check Results for $targetUser ===" Write-Host "Direct site permissions: $hasDirectAccess" Write-Host "Permissions via SharePoint groups: $hasGroupAccess" if ($hasGroupAccess) { Write-Host "Groups providing access: $($accessGroups -join ', ')" } if ($hasDirectAccess -and $hasGroupAccess) { Write-Host "⚠️ Alert: This user has BOTH direct permissions AND group-based access to the site!" }
How the Script Works
- Direct Permissions Check: It loops through the site's role assignments and checks if any assignment is directly linked to the target user (not a group)
- Group Permissions Check: It iterates through all site groups, loads their members, and checks if the user is part of any group that has site access
- Dual Permissions Detection: The script explicitly checks if both flags (
$hasDirectAccessand$hasGroupAccess) are$true, so it will clearly alert you if the user has both types of permissions
内容的提问来源于stack exchange,提问作者Mayank Surana
相关产品推荐
相关产品推荐

