What it works with
Module: PnP.PowerShell
Context: PowerShell 7.4+ · SharePoint Online · PnP.PowerShell
Compatibility: PowerShell 7.4+ is required by current PnP.PowerShell releases.
Builds a configurable SharePoint permissions report for selected sites with explicit site, list/library and bounded item-level depth.
Pro generation after license validation · Review before running · No tenant access
Builds a configurable SharePoint permissions report for selected sites with explicit site, list/library and bounded item-level depth.
Configure Deep SharePoint permissions report in the Builder, review the generated PowerShell and run it in your own environment.
Use this report when you need principals and role definitions on selected SharePoint permission scopes. Start shallow and enable item depth only for a targeted investigation.
Current PnP.PowerShell releases require PowerShell 7.4 or later. Interactive authentication requires your own Entra application/client ID, or a configured PnP default client ID. This script is read-only and does not intentionally change SharePoint configuration.
Opselith does not connect to your tenant or execute the script on your behalf. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation. Template source remains server-side.
Builds a configurable SharePoint permissions report for selected sites with explicit site, list/library and bounded item-level depth. Review these details before generating or running the script.
Module: PnP.PowerShell
Context: PowerShell 7.4+ · SharePoint Online · PnP.PowerShell
Compatibility: PowerShell 7.4+ is required by current PnP.PowerShell releases.
Permissions: AllSites.Read · Site Owner / Site Collection Administrator
Risk: Low
Execution impact: Read-only. Reads SharePoint securable-object role assignments. Item-level depth is opt-in and bounded; no permissions are changed.
Output: CSV permissions report with SiteUrl, ObjectType, ObjectUrl, ObjectTitle, HasUniquePermissions, Principal, PrincipalType, RoleDefinitions, InheritedFrom, ScanStatus and Error.
This template is part of the Pro library. The full Pro script is generated by Opselith after server-side license validation; only the configuration values needed by this template are sent for generation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.
Builds a configurable SharePoint permissions report for selected sites with explicit site, list/library and bounded item-level depth.
Enter the required values in the Builder, review the generated script and confirm the output before running it.