What it decides
- Rule
SPO-LIST-002- Applies to
sharepoint·list- Default severity
- high
- Basis
- documented-limit
On what authority
The number is enforced by the product rather than recommended by it. The second source states what a scope is and how one is created, which is what makes the count reproducible by a reader: breaking inheritance on a file or folder creates a scope, and two files sharing an inherited ACL do not.
What it needs to decide
permissions.unique_scope_count
Without these facts the rule answers unknown, which is not a pass and is not a failure: it is the rule saying the evidence could not settle the question.
Where the evidence comes from
No published capability supplies this rule's evidence.
What a pass does not establish
A list at 49,000 scopes passes and is one sharing operation away from the ceiling, and a list at 6,000 passes this rule while sitting well above the number Microsoft recommends for performance. This rule measures only the supported ceiling, and passing it says nothing about whether the list is usable.
- Counting scopes requires walking the items of the list. A collector that stopped early reports a lower bound, and this rule then answers only when that bound already settles the question.
- The rule does not read the scopes themselves. It cannot say who has access, or whether any of it is intentional.
Source
The rule as the Engine holds it, at the revision this page was generated from: 1.0.0b6@b4bf9c325233.
Generated from capability-manifest/1.0.0 at1.0.0b6@b4bf9c325233, contract1.0.0b6. Every fact on this page is the Engine's; this site publishes it and does not maintain it.