Set up FileAudit permissions

Grant or deny FileAudit console features to specific users and groups so non-admins get exactly the access they need.

Published June 16, 2026

Before you begin

FileAudit permissions let you give specific users or groups access to console features without granting them full administrative rights. You decide, per account, which features are allowed or denied.

Note

These permissions control the FileAudit console only: they do not change file system permissions on your audited resources.

Before you start, make sure you have:

Grant access to a user or group

  1. In the Settings > Permissions view, click Add a user or Add a group.

    Settings configuration User and Groups
  2. In the Microsoft account selector, type the account name and click Check Names. Once the name is validated, click OK.

    Permissions - Add a user


  3. A panel opens on the right of the Permissions view. Set each feature to Allow or Deny for this user or group.

  4. Save your changes. Denied features are immediately greyed out in the FileAudit hub for that account.

    Tile denied


  5. To confirm the result, sign in as the delegated user, or ask them to, and open the FileAudit hub. The tiles for any denied feature must appear disabled, and allowed features must be accessible.

For what each feature controls, see Permissions Reference.

Troubleshooting

Note

⚠️ Important
Never delete the default administrators rule. Doing so can lock everyone out of the Permissions section, with no way back through the console.

If a user is unexpectedly denied a feature, check every account they belong to. FileAudit follows the same rule as Windows: a single Deny on any group overrides an Allow elsewhere. Full resolution logic is documented in Permissions Reference.