A Microsoft file hosting and synchronization service.
Common causes for a OneDrive shared folder Access Denied error are:
- The shared folder permissions are not configured correctly.
- The signed-in account is different from the account that received the sharing invitation.
- The site has Limited-access user permission lockdown mode enabled, which can block access to shared folders when the user does not also have access to the parent site or folder.
Try these fixes in order:
- Confirm the correct account is signed in
- If the error says the link is not available to the current account, sign out and open the shared link again with the account that received the invitation.
- Check the user’s permissions on the site
- In the OneDrive site, go to Settings > Site Settings > Site permissions.
- In the ribbon, select Check Permissions.
- Enter the user name in User/Group, then select Check Now.
- Review the permissions, including any related security group permissions.
- Grant the required access again
- If the user does not have the correct permissions, grant access to the file or site again.
- Remove and re-add the user if the error continues
- Remove the affected user from the site, then share the file or folder again.
- If this affects a guest account, remove the guest account completely from the Microsoft 365 admin center, make sure the user is also removed from the site collection, and then grant permissions again.
- If this happens only for shared folders, check for Limited-access user permission lockdown mode
- This feature can prevent access to a shared folder when the user cannot access the parent folder or site.
- Workarounds:
- Share individual files instead of folders.
- Share the whole site collection or subsite.
- If the site does not require it, disable Limited-access user permission lockdown mode. Note: other features such as publishing might require this feature.
- If the issue is with a user’s own OneDrive site
- Check for a site user ID mismatch. If a new UPN exists, delete the new UPN and restore the original UPN, or use the automated solution in the SharePoint troubleshooting guidance.
If available in the tenant, Microsoft 365 administrators can also run the Check User Access diagnostic. It is not available for GCC High, DoD, or Microsoft 365 operated by 21Vianet.