Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All Projects
Interactive security buildLatest release case study

SharePoint Analyzer

AI-Powered Access & Permission Analysis

SharePoint permissions become difficult to audit when inheritance, nested groups, and site-level access produce hidden exposure.

Interactive preview
Full demo

SharePoint Analyzer

Permission exposure review

SharePoint AnalyzerWorkspace3 updates

CONTOSO / ACCESS REVIEW

Effective permissions and sharing exposure

Effective access graph

/Finance/Payroll

CONFIDENTIAL

Payroll

318 DOCUMENTS

Payroll AdminsFULL
Everyone except external usersREAD

Sharing paths

UNIQUE ACL

Anonymous links

2

Risk findings

3

Zain Khalil Khan

My Role

Security automation and full-stack engineer

What I Built

Enterprise SharePoint security analysis platform that maps users, security groups, files, folders, sharing links, and permissions into a unified access hierarchy. Analyzes permission inheritance and excessive access to identify security risks and simplify SharePoint cleanup, with a planned remediation workflow for creating security groups and automatically applying least-privilege access.

Evidence

Working interface, documented system behavior, and implementation-level decisions.

Technical Architecture

From system input to explainable output.

The control gate is shown as a first-class stage, not an afterthought added around the workflow.

Five stages connect inputs to processing, security controls, stored state, and user output.SYSTEM FLOW / SHAREPOINT ANALYZERTRACEABLE PIPELINE01INPUTSSites, ACLs & groupsVERIFIED STAGE02PROCESSINGPermission resolutionVERIFIED STAGE03SECURITY CONTROLSScope & access checksCONTROL GATE04STORAGE / STATEExposure graphVERIFIED STAGE05USER OUTPUTReview findingsVERIFIED STAGEINPUT TO OUTCOME / EVIDENCE PRESERVED

Technical Decisions

  • Crawled a SharePoint site collection and resolved every scope's effective ACL, including scopes with broken inheritance that a site-level review would miss.
  • Flagged tenant-wide claims such as Everyone except external users holding rights over content classified confidential.
  • Detected external guest identities granted edit or full control, the finding class that turns a sharing convenience into a data exposure.

Security Considerations

  • Crawled a SharePoint site collection and resolved every scope's effective ACL, including scopes with broken inheritance that a site-level review would miss.
  • Paired each finding with the specific remediation, from replacing a tenant-wide claim with a security group to setting sharing expiry on guest access.

Outcome & Evidence

  • Counted anonymous sharing links, which bypass conditional access entirely and are unattributable to any user.
  • Severity-weighted findings by content sensitivity and item count so remediation is ordered by exposure, not alphabetically.
  • Paired each finding with the specific remediation, from replacing a tenant-wide claim with a security group to setting sharing expiry on guest access.
Microsoft SharePointMicrosoft GraphPowerShellReactAccess ControlAI

Working product

Try the interactive demo.

The product experience is part of this case study. Explore it here, reset its state, or switch viewport sizes without leaving the project page.

SharePoint Analyzer

Permission exposure review

SharePoint AnalyzerWorkspace3 updates

CONTOSO / ACCESS REVIEW

Effective permissions and sharing exposure

Effective access graph

/Finance/Payroll

CONFIDENTIAL

Payroll

318 DOCUMENTS

Payroll AdminsFULL
Everyone except external usersREAD

Sharing paths

UNIQUE ACL

Anonymous links

2

Risk findings

3

Zain Khalil Khan

Next Case Study

Encrypted File Vault

Read Next Case Study