Approdo is in build and not yet available. Register your interest →
Approdo › Guides › Keep permissions

How to migrate a file server to SharePoint and keep permissions

Updated October 2026 · 8 min read

Short answer: fix the permissions before you move. Survey the NTFS ACLs, repair broken inheritance and ownership, clean orphaned SIDs, then map the cleaned groups to SharePoint permission levels during migration. Approdo automates all of that — so access is preserved faithfully, not flattened to three roles.

Why permissions break during migration

What “keeping permissions” really means

There are two honest goals, and it's worth deciding which you want before you start:

The wrong approach is an accidental third option: a tool that flattens everything to a few broad roles and drops what it can't translate, so you neither replicated nor cleaned up — you just lost fidelity.

The right order

How Approdo preserves permissions

Approdo's agent does steps 1–2 on your server automatically: it audits the ACLs, takes ownership where needed, repairs inheritance, and handles orphaned SIDs — detecting them, remapping where it can, and safely dropping the rest with a logged record. Then, during migration, it maps the cleaned groups to SharePoint permission levels and verifies the result. You see the plan and the diff before anything is applied, and it's reversible.

NTFS → SharePoint mapping, briefly

In practice: NTFS Full Control → SharePoint Full Control; Modify/Write → Edit/Contribute; Read & Execute → Read. Group‑based access maps cleanly; per‑user ACLs and Deny rules need decisions — which Approdo surfaces rather than silently dropping.

Replicate or start clean?

Approdo can do either: reproduce exactly what you had, or propose a recommended clean‑slate model — with the difference shown so you choose deliberately. For many firms, migration is the best moment they'll ever get to fix permissions, not just carry the mess across.

Approdo is coming soon

Approdo's assessment maps your NTFS permissions and flags every orphaned SID and broken inheritance before you migrate.

Register your interest →

FAQ

How do I keep permissions when migrating to SharePoint?

Remediate the NTFS ACLs first (ownership, inheritance, orphaned SIDs), then map the cleaned groups to SharePoint permission levels. Approdo automates this so access is preserved, not flattened.

Do SharePoint permissions work like NTFS?

No — SharePoint uses permission levels on groups, not granular NTFS rights, so a mapping is always required.

What happens to deleted users / orphaned SIDs?

They can't be mapped to anyone, so most tools drop them. Approdo detects, remaps where possible, and safely drops the rest with an audit trail.