File server permission audit: the spreadsheet that ends "who can see this folder?"

File permissions sprawl the way shared drives sprawl: one folder at a time, one "quick, can you give her access" at a time, until the day a departure triggers the question nobody can answer — what exactly could they see? The user access review covers accounts and apps; this page is the pass for the folders themselves: the NAS share, the SharePoint site, the Google Drive, and the "old-server" share somebody forgot to decommission. One afternoon for the first audit, thirty minutes per quarter after that.

1. Inventory the shares — from the console, not from memory (60 minutes)

2. The two dangerous defaults: Everyone groups and unbroken inheritance

3. Group-based access only: no per-person grants

4. External sharing links: the shadow perimeter

5. Admins, service accounts, and the backup job with god rights

6. Wire access to joiner-mover-leaver, not hallway conversations

7. The quarterly thirty minutes, and the evidence it produces

Small-team honesty note: this audit will not make your file server perfectly locked — small teams run on hallway conversations, and some of that looseness is the cost of moving fast. What it buys is a map: one spreadsheet that answers "who can see this folder" in minutes instead of folklore, a quarterly diff that catches drift while it is still one folder instead of a rebuild, and the evidence artifact that insurance and enterprise customers both ask for. One afternoon, then thirty minutes a quarter. That is the whole program.

Related: user access review · access request and offboarding · employee offboarding · employee onboarding · Microsoft 365 security · Google Workspace security · break-glass accounts · cyber insurance requirements · customer security questionnaire · SaaS sprawl audit · shadow IT audit · backup encryption · server hardening · power failure IT checklist · new admin's first week