Collaborate, Innovate, Automate

Get-WhoAssignedUser

Ever wondered who assigned permission directly to a user in a SharePoint site? This script searches the Microsoft 365 unified audit log for "AddedToGroup" events on a specific SharePoint site, scoped to a specific user, to answer a common access-review question: who added this person to a SharePoint group, and when. It's built for exactly that question rather than general audit log exploration — point it at a site and a user, and it returns a sorted list of matching group-membership events with the actor, the site, the target user, and the raw event detail, which usually names the SharePoint group itself.

Purpose

Scope

Prerequisites

PowerShell Script

<#
.SYNOPSIS
    Searches the Microsoft 365 unified audit log for "AddedToGroup" events
    on a specific SharePoint site, scoped to a specific user, to find who
    added that user to a SharePoint group and when.
#>

Connect-ExchangeOnline

$user = ""   # UPN or exact display name of the user to search for
$site = ""   # SharePoint site URL (or prefix) to scope the search to

$results = Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-180) -EndDate (Get-Date) `
  -Operations "AddedToGroup" -ObjectIds "$site*" -FreeText $user -ResultSize 5000

$results | ForEach-Object {
    $d = $_.AuditData | ConvertFrom-Json
    [pscustomobject]@{
        Date   = $_.CreationDate
        Actor  = $_.UserIds                  # who performed the add
        Site   = $d.SiteUrl
        Target = $d.TargetUserOrGroupName    # should match $user
        Detail = $d.EventData                # contains the SharePoint group name
    }
} | Where-Object { $_.Site -like "$site*" } | Sort-Object Date

Usage Notes