Source review: September 15, 2026. Tenant validation pending.
Page tools and document details
Check identity and the exact item first
Use your normal approved device and network. A private browser window can help isolate a wrong browser account, but it does not bypass device or location policy.
Have the content owner define intended access
The owner must confirm who should read or edit which content. A site owner or authorized administrator can inspect permissions; the affected user should not change group membership or create a public link.
- Scope
- SharePoint Online sites and files, including files opened through Teams. A user's own inaccessible OneDrive can instead involve an account/site ID mismatch.
- Access
- Use the least privileged existing role that can inspect the relevant site. Membership changes to a Microsoft 365 group can affect Teams and other resources too.
- Licensing
- Check the actual account and service entitlement when relevant. A permissions failure is not evidence that the user needs a more expensive plan. Guest access and internal-user licensing are different questions.
Find which layer blocks the request
- Identity: reopen the invitation with the intended account. Record any account switch. Do not delete and recreate an identity just to test access.
- Item and link: the owner opens the file's Manage access panel. Check direct access, links, inherited access and whether the intended person is covered. A link for people with existing access grants no new permission.
- Site/group: open Settings → Site permissions, then the advanced permissions view where available → Check Permissions. Enter the exact user and inspect the group that provides access. Check the affected item separately if it has unique permissions.
- Policy: if the error names an untrusted device, network location or organizational policy, have the administrator inspect that control. A successful site permission check does not override it.
| Result | Next step |
|---|---|
| Wrong account | Use the invited identity and repeat the same URL. |
| Missing or incorrect permission/link coverage | Ask the owner for the smallest approved correction below. |
| Policy-specific denial | Use a compliant access path or escalate to the policy owner. Do not broaden file sharing. |
| Correct permissions but a recreated account or old identity is involved | Ask a SharePoint administrator to assess the Site User Mismatch diagnostic and its prerequisites. |
| Many users fail or the service returns 503 | Check service health and service/throttling symptoms. Do not reset site permissions. |
Change the layer you verified
Before changing access, record the existing person/group, link type, permission level and affected scope. The content owner then grants the intended read or edit access using the approved group or a specific-person share. For an expired or incorrect link, create the correct scoped link and deliver it to the intended person through your normal channel.
For an approved single-file share:
- Select that file in its library and choose Share.
- Enter the exact recipient, then choose Can view or Can edit beside the recipient field.
- Recheck recipient, item and access before Send. If sharing is blocked, stop and ask the owner.
For guests, check the invited identity and allowed sharing policy with the owner. Do not enable anonymous sharing to repair a guest sign-in. For an ID mismatch, use the Microsoft diagnostic with a SharePoint administrator and review the proposed repair; deleting a guest or employee identity can affect other resources.
If no layer explains the failure, keep the case unresolved and use the Check User Access diagnostic or Microsoft support. Read the diagnostic's data-use notice before running it. Availability differs in sovereign clouds, as described in the Microsoft sources.
Test as the intended user
If the change gives too much access or affects other resources, the authorized owner restores the recorded prior membership/link state. Do not reset all permissions or inheritance as a general rollback.
Prepare the permissions handoff
Problem: SharePoint access denied Expected identity and intended read/edit access: Site works / only item fails / broad failure: Exact error and time with UTC offset: Link, direct/group access and item permissions checked: Policy or account-recreation evidence: Owner-approved change and affected-user test: Unresolved question / next owner:
Request a permissions review with a redacted summary. Keep raw site URLs, guest details and exports in approved storage until a secure transfer channel is agreed.