SharePoint Manager Plus helps you review item-level permissions from a centralized reporting console, without switching between multiple site reviews or relying on custom PowerShell scripts. The Permissions Non Inherited List Items report gives administrators a focused view of broken-inheritance items across SharePoint.
Why you need a report to monitor non-inherited SharePoint items
Permission inheritance in SharePoint works quietly in the background. When an administrator deliberately breaks inheritance to restrict or expand access on an item, a unique security scope is created and the permission model for that item diverges from its parent. Sharing actions and direct item-level permission changes can also create or coincide with unique permission scopes, increasing the number of exceptions that administrators need to review.
These exceptions are not just administrative noise; they can become material security and financial risks when sensitive data is involved. IBM's 2025 Cost of a Data Breach Report found that the global average breach cost was $4.44 million, underscoring why unmanaged permission drift should be identified and remediated before it contributes to unauthorized access.
Microsoft provides SharePoint governance and permission review capabilities through data access governance reports and related review workflows, but those native views are limited to sites. They do not provide a ready-made tenant-wide report focused specifically on list items whose permissions differ from their parent objects. For administrators trying to investigate permission drift across many sites and lists, native review quickly becomes fragmented and slow.
A non-inherited SharePoint item report replaces that fragmented process with a centralized, immediately actionable view of item-level permission exceptions:
- Start every permission drift audit at the exceptions: Because the report is prefiltered to non-inherited items only, administrators see the complete set of unique permission scopes across the tenant without having to filter out the inherited majority.
- Detect item-level permission drift earlier: Surface items whose permissions have diverged from their parent objects so they can be reviewed before those exceptions accumulate.
- Assess group-based access risks behind role assignments: Where a role assignment on a broken-inheritance item is made through a SharePoint group or Microsoft Entra group, the actual access population may be broader than the principal name suggests.
- Prioritize remediation using sensitivity context: Cross-reference this report with site, library, or content sensitivity context to identify which broken-inheritance items may require review first.
- Support access reviews without building scripts: Use a ready-made, filterable, exportable view of item-level permission exceptions instead of building and maintaining custom retrieval workflows.
What is the Permissions Non Inherited List Items report in SharePoint Manager Plus?
The Permissions Non Inherited List Items report provides a consolidated, prefiltered view of every list item across your SharePoint tenant where permission inheritance has been broken, meaning the item's permissions differ from those of its parent object. For each such item, the report shows the site and list location, the item's name and type, the users and groups assigned through that unique scope, the principal type, the permission levels they hold, the parent URL from which inheritance would normally flow, and the hierarchy level at which the unique scope exists. Every record in this report represents an item whose permissions differ from its parent, making it a targeted remediation queue rather than a general permissions audit that requires post-filtering.

Compliance frameworks this report can support
Organizations across industries are subject to information security and privacy frameworks such as the GDPR, ISO/IEC 27001, HIPAA, NIST SP 800-53, and the PCI DSS, many of which expect stronger least-privilege enforcement, access reviews, and oversight of permission exceptions.
The Permissions Non Inherited List Items report supports these efforts by giving administrators a consolidated view of SharePoint list items whose permissions differ from their parent objects. This visibility can help teams support access reviews, investigate permission drift, validate least-privilege decisions, and prepare for governance or audit discussions more efficiently.
What does the Permissions Non Inherited List Items report show?
Using SharePoint Manager Plus, you can filter the Permissions Non Inherited List Items report with the following fields:
- Farm: Select the SharePoint farm or Microsoft 365 tenant from which you want to pull broken-inheritance item data.
- Site: Narrow the report to a specific site to focus the broken-inheritance audit on a particular team, department, or project environment.
The Permissions Non Inherited List Items report displays the following details for every item with broken permission inheritance.
| Attribute | Description |
|---|---|
| Site URL | The full web address of the SharePoint site that contains the list holding the item with broken permission inheritance |
| Object Name | The name of the specific list item where permission inheritance has been broken and a unique security scope exists |
| Object Type | Indicates whether the object with broken inheritance is a list item, a document, or another content type within SharePoint |
| Location | The name or path of the list or library within the site that contains the item |
| User/Group Name | The display name of the user or SharePoint group assigned directly to the item through its unique permission scope |
| Principal Type | Indicates whether the access principal is an individual user, a SharePoint group, a Microsoft Entra group, or another principal type |
| User Group ID | The internal identifier of the SharePoint group or user object assigned to the item |
| Permissions | The specific permission level assigned to the user or group on the item through its unique scope |
| Inherited URL | The URL of the parent object from which this item's permissions would flow under the default SharePoint permission inheritance model |
| Is Inherited | Confirms that permission inheritance has been broken for this item. All items in this report return false for this attribute |
| Hierarchy Level | Indicates the level within the SharePoint object hierarchy at which the unique permission scope exists |
Native SharePoint reporting and PowerShell vs. SharePoint Manager Plus
In Microsoft 365, administrators can review permissions through data access governance reports, permission state snapshots, site access reviews, and manual object-level permission checks. Those native options are useful, but they are still site-, snapshot-, or review-oriented. They do not provide one ready-made tenant-wide report focused specifically on list items whose permissions differ from their parent objects.
PowerShell can help bridge those gaps. PnP PowerShell can enumerate item-level unique permissions, but tenant-wide scripting still requires elevated permissions, careful setup, iteration across sites and lists, output formatting, and ongoing maintenance.
SharePoint Manager Plus reduces that overhead by bringing this visibility into a single report that administrators can run, filter, export, and schedule without building the workflow from scratch.
| Capability | SharePoint admin center | PowerShell | The SharePoint Manager Plus advantage |
|---|---|---|---|
| Report accessibility | ❌ Manual filtering is required every time. | ❌ Script execution is required for every run. | ✅ Get one-click access to categorized reports. |
| Custom reports | ❌ | ❌ | ✅ Create custom reports by saving granular, attribute-based conditional filters. |
| Report exports | ✅ Reports can be exported only in CSV or JSON formats. | ✅ Requires additional scripting to format and export data. | ✅ Reports can be exported in CSV, HTML, PDF, and XLSX formats. |
| Emailing reports to admins | ❌ | ❌ | ✅ Send report emails to stakeholders and admins in preferred formats. |
| Automated report generation | ❌ This requires technical scripting or separate complex add-ons. | ❌ This requires Task Scheduler or Azure Automation. | ✅ Schedule multiple reports that can be generated, filtered, emailed, and exported between defined periods automatically. |
For a more detailed comparison, check out our page on how to audit a site collection.
Features that enhance the Permissions Non Inherited List Items report
SharePoint Manager Plus provides several built-in tools to help you act on, schedule, and distribute the broken-inheritance data surfaced by the Permissions Non Inherited List Items report.
- Export reports: Download the report in CSV, PDF, HTML, or XLSX formats for audit submissions; compliance evidence packages; and distribution to security reviewers, data protection officers, or auditors.
- Automated report generation: Schedule the report to run daily, weekly, or monthly so the broken-inheritance remediation queue stays current and newly created unique scopes are surfaced promptly.
- Instant alerts for inheritance breaks: Configure alerts to notify administrators when permission inheritance is broken on SharePoint lists, files, and folders, or when the count of unique permission scopes within a site collection crosses a defined threshold.
- Restore permission inheritance: Act directly on the broken-inheritance items surfaced by the report by restoring inheritance, removing unique permission assignments, or adjusting role assignments from the SharePoint Manager Plus interface.
- Custom reports: Customize reports by applying filters to tailor the data, then save it for future quick access and easy replication.
Reports that complement the Permissions Non Inherited List Items report
If you are auditing broken inheritance, governing permission drift, or enforcing least privilege at the item level in SharePoint Online, SharePoint Manager Plus provides several reports that extend the focused view delivered by the Permissions Non Inherited List Items report.
List Item Permissions report: Provides the broader item-level permission picture, including inherited and non-inherited items, helping you investigate exceptions in more detail.
Item Wise Sharing Access report: Maps sharing activity at the item level, helping you connect item-level permission exceptions with sharing actions where relevant.
Anonymously Shared Items report: Identifies items currently shared through active anonymous Anyone links, helping administrators prioritize risky exposure paths during broken-inheritance reviews.
List Wise External Users report: Identifies external users with access to specific lists and libraries, helping you assess whether unique-permission items are part of broader external exposure.
SharePoint permissions reports: Detail permission assignments at the site and list level, helping you compare item-level exceptions with the parent access model.
Other features of SharePoint Manager Plus
- SharePoint management: Grant, remove, or copy SharePoint permissions, and manage group members in bulk without relying on complex scripts, simplifying your SharePoint administration.
- SharePoint reporting: Access over 140 prebuilt and custom reports for SharePoint—including permissions, site usage, content inventory, and security insights—all from a centralized dashboard.
- SharePoint auditing: Maintain a comprehensive, searchable audit trail of all activities across your SharePoint environment, including user actions, permission changes, and content modifications.
- SharePoint alerting: Get real-time alerts on critical events such as permission changes, suspicious user activities, site access anomalies, and policy violations.
- Delegated administration: Empower help desk technicians with granular, role-based access to perform specific SharePoint administrative tasks, without elevating native privileges.
- SharePoint migration: Simplify SharePoint migration by enabling seamless content and permission migration across sites and tenants, with minimal downtime and full visibility into migration progress.

