SOURCE-CHECKED GUIDE · BUSINESS DOCUMENTS

Move a file share to SharePoint: permission test before migration

Evaluate file-share permission mapping, explicit deny rules, and pilot reports before moving a shared drive to SharePoint.

Published September 29, 2026Checked September 29, 2026HowCurio editorial research
A document selection checklist
Illustration of the topic. The article links to the source instructions.

Schedule the migration only after a pilot proves that the intended users can open the right content and excluded users cannot. Microsoft’s SharePoint Migration Tool (SPMT) guidance says it carries documents, folder structure, and user-level file and folder permissions. Explicit deny permissions and advanced NTFS permissions do not survive this migration. A folder protected by an explicit deny may become accessible through a parent or parallel permission. Source access rules, destination mapping, and an access test therefore decide the schedule. Microsoft’s SPMT file-share migration guide

Decision matrix

Source content Decision before scheduling Pilot evidence needed
Ordinary files with straightforward user access Include in a small pilot after choosing the destination and checking user mapping. Intended users can open the migrated files; users without access cannot.
Folders that rely on explicit deny or advanced NTFS rules Hold these folders until their destination permissions are redesigned and checked. An account that the source rule excluded still cannot reach the content, including through a parent or parallel permission.
Documents with embedded file-share links Identify links that users still need and plan their correction. Needed links lead to the intended destination; migration does not convert embedded URLs.
Obsolete content Decide what is still relevant before selecting migration scope. The pilot contains the approved content and omits content deliberately left behind.

The hold on deny-sensitive folders follows Microsoft’s warning about permissions removed during migration. Its guide also says embedded URLs are not converted, Windows hidden attributes are not migrated, and assessing current content should inform how much is moved. These are separate checks: a successful file transfer would not establish that access or links work as intended. Microsoft’s file-share migration guide

Run a permission-focused pilot

Consider a small team with a shared project folder, a routine working folder, and a restricted folder for manager-only material. The team’s owner selects the SharePoint destination and lists who should be able to open each folder. If the restricted source folder uses an explicit deny, the team pauses that folder and defines its destination access before moving it. The pilot includes an authorized manager, an ordinary team member, and an account with no intended access. Each signs in separately and attempts to open the migrated folders and files. The result to record is the effective access each account receives, not just whether a permission-setting option was selected.

Before that pilot, use SPMT’s Only perform scanning setting to assess the selected files. Its Preserve file share permissions setting carries supported permissions. SPMT uses Automatic user mapping by default; a custom user mapping file is another option. Confirm which identities the pilot maps to before interpreting its access results. The preservation setting is not a promise that every source ACL survives: Microsoft explicitly excludes deny permissions and says advanced NTFS permissions are removed. SPMT settings · SPMT file-share migration guide

The team should also choose a document containing an embedded link and check it after migration. If the link still points to the old share, record the required correction before moving the wider set. Decide which obsolete folders belong outside the migration scope rather than treating the move as a retention decision. Microsoft’s recommended sequence includes assessment and remediation, target mapping, migration, and user onboarding; the pilot should produce enough evidence to complete each applicable step for the team. Microsoft’s file-share migration guide

Pilot acceptance checklist

  • The selected source folders, destination locations, and intended users have been recorded.
  • Scan findings have been reviewed, and issues affecting the pilot have been resolved or assigned an explicit hold.
  • User mappings resolve to the intended destination accounts.
  • Authorized pilot users can open the files they need.
  • Least-privilege test accounts cannot open restricted content through direct, parent, or parallel access.
  • Needed embedded links have been checked and corrections recorded; obsolete content has an agreed migration decision.
  • Users have a communicated changeover plan, and the team has reviewed the pilot results before setting a wider date.

Go only for the content that passes those checks. Keep folders with unresolved access, link, or scope questions out of the scheduled move until their owners resolve them. confirm the live quote and tenant settings before making the scheduling decision.

How this guide was made

This guide explains a workflow using the linked primary sources. We did not independently run every step or verify the result for your files; check the current service screen and your own output.

Primary sources: