You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用CSOM PowerShell检查用户SharePoint站点权限的归属方式

How to Check if a User is Added Directly to a SharePoint Site or via a Group (Plus CSOM PowerShell Implementation)

Let's break this down into manual verification steps first, then jump into the CSOM PowerShell script to automate the check—including detecting if a user has both direct and group-based permissions.

Manual Check: Direct Permissions vs. Group Membership

Checking Direct Site Permissions

  • Navigate to your SharePoint site, click the gear icon (Settings) > Site permissions
  • Click Advanced permissions settings at the bottom of the permissions pane
  • Look for the user in the main list: users with direct permissions will appear as individual entries (not nested under any SharePoint group)

Checking Group-Based Permissions

  • From the same Advanced permissions page, you can either:
    1. Click into each SharePoint group (like "Site Members" or "Site Owners") to review its member list
    2. Use the Check Permissions tool at the top: enter the user's email/username, click Check Now, and the results will explicitly show which groups grant them access (look for lines starting with "Granted via [Group Name]")

CSOM PowerShell Implementation

First, make sure you have the SharePoint Online CSOM module installed (skip if you already have it):

Install-Module -Name Microsoft.Online.SharePoint.PowerShell -Force

This script will check both direct permissions and group membership, and flag if the user has both types of access:

# Configuration - Update these values
$siteUrl = "https://yourtenant.sharepoint.com/sites/yoursite"
$targetUser = "user@yourtenant.com"
$adminUsername = "admin@yourtenant.com"
$adminPassword = Read-Host -Prompt "Enter admin password" -AsSecureString

# Initialize CSOM context
Connect-SPOService -Url "https://yourtenant-admin.sharepoint.com" -Credential (New-Object System.Management.Automation.PSCredential($adminUsername, $adminPassword))
$ctx = New-Object Microsoft.SharePoint.Client.ClientContext($siteUrl)
$ctx.Credentials = New-Object Microsoft.SharePoint.Client.SharePointOnlineCredentials($adminUsername, $adminPassword)

# Load site web and role assignments
$web = $ctx.Web
$ctx.Load($web)
$ctx.Load($web.RoleAssignments)
$ctx.ExecuteQuery()

# Ensure the target user exists in the site
$user = $web.EnsureUser($targetUser)
$ctx.Load($user)
$ctx.ExecuteQuery()

# Initialize flags and group list
$hasDirectAccess = $false
$hasGroupAccess = $false
$accessGroups = @()

# Check for direct permissions
foreach ($roleAssignment in $web.RoleAssignments) {
    $ctx.Load($roleAssignment.Member)
    $ctx.ExecuteQuery()
    if ($roleAssignment.Member.PrincipalType -eq [Microsoft.SharePoint.Client.PrincipalType]::User -and $roleAssignment.Member.LoginName -eq $user.LoginName) {
        $hasDirectAccess = $true
        break
    }
}

# Check for group membership-based permissions
$siteGroups = $web.SiteGroups
$ctx.Load($siteGroups)
$ctx.ExecuteQuery()

foreach ($group in $siteGroups) {
    $ctx.Load($group.Users)
    $ctx.ExecuteQuery()
    if ($group.Users | Where-Object { $_.LoginName -eq $user.LoginName }) {
        $hasGroupAccess = $true
        $accessGroups += $group.Title
    }
}

# Output the results
Write-Host "`n=== Permission Check Results for $targetUser ==="
Write-Host "Direct site permissions: $hasDirectAccess"
Write-Host "Permissions via SharePoint groups: $hasGroupAccess"
if ($hasGroupAccess) {
    Write-Host "Groups providing access: $($accessGroups -join ', ')"
}
if ($hasDirectAccess -and $hasGroupAccess) {
    Write-Host "⚠️ Alert: This user has BOTH direct permissions AND group-based access to the site!"
}

How the Script Works

  • Direct Permissions Check: It loops through the site's role assignments and checks if any assignment is directly linked to the target user (not a group)
  • Group Permissions Check: It iterates through all site groups, loads their members, and checks if the user is part of any group that has site access
  • Dual Permissions Detection: The script explicitly checks if both flags ($hasDirectAccess and $hasGroupAccess) are $true, so it will clearly alert you if the user has both types of permissions

内容的提问来源于stack exchange,提问作者Mayank Surana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:04:00