Posted in

Extended SharePoint Permissions (ESP)

๐Ÿ”น Feature: Extended SharePoint Permissions (ESP)
๐Ÿ”น What It Does: Your SharePoint permissions โ€” extended everywhere. Lose access in SharePoint, and the downloaded file wonโ€™t open anymore. Anywhere.

๐Ÿ’ก Thesis: The perimeter follows the file, not the other way around.

What is it giving you:

โœ… Permissions That Travel: SharePoint site permissions are automatically applied to files when downloaded, copied, or moved off the site โ€” no manual labeling required.
โœ… Just-in-Time Protection: If permissions are revoked, the file is deleted, the site goes inactive, or the file is moved โ€” the downloaded copy stops opening. Instantly.
โœ… Live Permission Sync: Change a userโ€™s SharePoint access and the change reflects immediately on every downloaded copy of the file.
โœ… Move/Copy Lockdown: Files canโ€™t be moved or copied to a different site. Within the same site only if the user has list create/delete rights.
โœ… Zero-Effort Rollout: Applies to unlabeled files and files with non-encrypting labels โ€” perfect for organizations early in their labeling journey.
โœ… Permission Mapping Built-In: SharePoint Owner/Edit/Read maps directly to RMS usage rights (Owner/Editor/Viewer) โ€” no custom rights policies to design.

โš ๏ธ Worth knowing:
Requires Microsoft 365 Apps 2402+ (Current/Monthly Enterprise/Semi-Annual)
Files wonโ€™t open offline โ€” connection to the original site is required
Copilot can reference but not summarize ESP-protected files
Mutually exclusive with default labels that donโ€™t apply encryption
Enabled per-tenant via: Set-SPOTenant -ExtendPermissionsToUnprotectedFiles $true

๐ŸŒ https://learn.microsoft.com/en-us/purview/sensitivity-labels-sharepoint-extend-permissions

Microsoft Certified Trainer, Office 365, AWS, Azure and Cloud Expert-Architect. In the IT world for over than 20 years.

Apart from the main area of Microsoft Azure expert in the field of infrastructure servers Windows Server 2003-2019, Microsoft Active Directory, Hyper-V Private Cloud, IIS, System Center, SQL.

Private Cloud, System Center, Hyper-V, Open Stack Expert and all Microsoft products Expert. Linux Server administrator.

My Azure community projects:

https://mazeball.azurewebsites.net/
https://github.com/MariuszFerdyn?tab=repositories

More