Skip to main content

SP_EmptyDomainGroupPerms Job

The SP_EmptyDomainGroupPerms Job identifies empty security groups with directly assigned permissions to resources, these groups should be deleted from SharePoint farms, where found. Inadvertent changes to group membership may open up unwanted access.

Analysis Tasks for the SP_EmptyDomainGroupPerms Job

Navigate to the Jobs > SharePoint > 1.Direct Permissions > SP_EmptyDomainGroupPerms > Configure node and select Analysis to view the analysis tasks.

CAUTION: Do not modify or deselect the selected analysis tasks. The analysis tasks are preconfigured for this job.

Analysis Tasks for the SP_EmptyDomainGroupPerms Job

The default analysis tasks are:

    1. Find Empty Group Permission – Creates the SA_SP_EmptyDomainGroupPerms_DirectPermissions table accessible under the job’s Results node
    1. Find Affected Resource Count per Group – Creates the SA_SP_EmptyDomainGroupPerms_ResourceCount table accessible under the job’s Results node

In addition to the tables created by the analysis tasks which display direct permissions and resource counts for empty groups, the SP_EmptyDomainGroupPerms Job produces the following pre-configured report:

ReportDescriptionDefault TagsReport Elements
Empty Domain Group PermissionsThis report identifies empty security groups with directly assigned permissions to resources. These groups add no access, and should be deleted from SharePoint farms, where found. Inadvertent changes to group membership may open up unwanted access.NoneThis report is comprised of three elements: - Bar chart – Displays the top 5 groups by affected resources - Table – Provides details on permissions - Table – Provides details on top groups by affected resources