SharePoint Online Backdoor to OneDrive

Well, first of all, let me just say, that I think the title I chose for this post is, well, sort of stupid, since this is a good governance best practice to put into play, maybe a topic for another post. Anyways, I hope my opinion of my title does not offend anyone and what you’re about to read is really SharePoint admin 101 stuff, and not truly a backdoor, by any hacker sense of the word; but it sounds cool, maybe. Nothing is being hacked or is a backdoor; but, I digress and OK here goes, OK? And I really hope this helps someone.

Purpose or uses for this post: Someone leaves the organization and has potentially a plethora of things that the organization could use, things that were recommended to the team internally and possibly not shared with higher leadership for whatever reason. And these known issues are only stored in that users One Drive, possibly in files or maybe in a One Note.

Scenario: Enquiring minds must feed and must know

How to access that super awesome info: Give an account access to the site collection.

See steps below, and you’ll need to pim up to either SharePoint Online Administrator or higher.

Access the SharePoint admin center, you know how, tenantID-Admin.sharepoint.com or us, depending.

Then more features and open user profiles, steps 1 and 2 in the attached screen grab.

Add an account that you have creds for into the SCA’s for the user profile that you’re looking to access the “super awesome” info that you desperately want to see, read, and then hold meetings around, probably. Once that is done you will have to Navigate to the site collection of the users my site
and you will need the URL to the site collection.


This URL will be something like the URL below:

https://stacyslab-my.sharepoint.com/personal/admin_hopandpophostel_com

https://tenant-my.sharepoint.com/managedpath to mysites/user_name Please note: your org might use a different managed path, for example my vs personal, and this is not reason for concern, just look at the drop down on step 3 above, and then to get to the first part of the url show above, click on Manage Personal Site, then replace the user_name with the User name whose info you are looking to steal, cough and he he he [laughter], get access into.

Don’t be a stealer, no one wants that and besides, it is a crime to steal. Stealing is bad; but, so is missing out on numerous, opportunities, that are potentially just sitting out there in a former contractor or users one drive, not being indexed by the crawler, and full of good stuff that your organization, might be able to utilize.

Happy hunting and may the force be with you!