
Google Drive makes sharing files incredibly easy. Removing that access later, especially across hundreds, thousands, or even millions of files, is where things get complicated.
While Google provides native ways to change permissions across multiple files, these options are limited when security teams need to identify and remediate sharing across an entire Google Workspace environment.
For organizations, bulk permission removal is about identifying which access shouldn't exist, remediating years of accumulated exposure, and preventing the same risky sharing from building back up.
That's an important part of maintaining a strong Google Drive security posture as the volume of files, users, and collaborators grows.
Here's how to approach it.
Can You Bulk Remove Sharing Permissions in Google Drive?
Yes, you can remove sharing permissions from multiple Google Drive files at once, but the best method depends on the scale and complexity of the cleanup.
For a small number of known files, users can select multiple files in Google Drive and modify their sharing settings together. For larger environments, administrators can also use the Google Drive API to manage permissions programmatically.
The challenge for enterprises is scale.
If you have thousands of users and potentially millions of files spread across My Drive and Shared Drives, simply knowing which files need remediation becomes difficult.
Security teams need a way to identify risky permissions across their entire environment, determine which access is actually inappropriate, and then remediate those permissions without disrupting legitimate collaboration.
In other words, removing the permission is only one part of the problem.
How to Bulk Remove Sharing Permissions in Google Drive
There are several ways to remove Google Drive sharing permissions, ranging from native manual controls to automated bulk remediation.
Method 1: Select Multiple Files in Google Drive
For a small, targeted cleanup, you can modify permissions across multiple files directly in Google Drive.
- Open Google Drive.
- Select the files you want to modify using Ctrl on Windows or Cmd on Mac.
- Right-click the selected files and choose Share.
- Review the users and groups with access.
- Remove the appropriate users or change their permission levels.
- Review the General access setting and restrict link-based access if necessary.
- Save your changes.
This works when you already know which files need to be changed.
The limitation is discovery. If risky permissions are scattered across different folders, users, Shared Drives, and years of historical data, manually finding and selecting those files quickly becomes impractical.
At that point, permission cleanup becomes part of a much broader Google Drive security challenge: gaining visibility into where sensitive data lives and who can access it across the environment.
Method 2: Remove Sharing Permissions Folder by Folder
Another option is to work through Google Drive one folder at a time.
Open the folder, select the relevant files, open the sharing settings, and modify the permissions for the selected items.
This can be useful when a cleanup is isolated to a particular project or folder. For example, a team may want to remove an external agency's access after a project ends.
However, organizations need to be careful with inherited permissions. Access granted at a parent folder or Shared Drive level can affect the content underneath it. Removing a direct permission from an individual file does not necessarily address the source of inherited access.
That makes understanding how a user received access just as important as knowing that the user has access.
Method 3: Use the Google Drive API
Technical teams can also use the Google Drive API to identify and modify permissions programmatically.
This provides more flexibility than manually editing files through the Drive interface and can be useful for organizations building their own internal remediation processes.
However, an API doesn't make the security decision for you.
Organizations still need to determine:
- Which files are improperly shared?
- Which users should have their access removed?
- Is the file sensitive?
- Is the external collaborator still trusted?
- Is access direct or inherited?
- Should a public link be removed?
- Is organization-wide access appropriate?
- Will remediation interfere with a legitimate business process?
At enterprise scale, this becomes less of a scripting problem and more of a data access governance problem.
Method 4: Use a Security Platform for Organization-Wide Bulk Remediation
For large Google Workspace environments, security teams may need to remediate permissions across hundreds of thousands or millions of assets.
This requires visibility across the environment before remediation begins.
Instead of starting with individual files, security teams can identify categories of exposure such as:
- Sensitive files shared publicly
- Files accessible through "Anyone with the link"
- Sensitive files shared organization-wide
- Files shared with personal email accounts
- Files accessible to former employees
- Old files still accessible to external collaborators
- Inactive files with unnecessary permissions
- Files exposed to unauthorized users or groups
Security teams can then target the specific permissions that violate policy and remediate them in bulk.
This is where bulk removal becomes much more useful than simply selecting multiple files. It also becomes part of a broader Google Workspace security strategy, where organizations continuously govern users, applications, configurations, data access, and sharing across their SaaS environment.
The Bigger Problem: Google Drive Permission Debt
Google Drive permissions rarely become unmanageable overnight. They accumulate over time.
- An employee shares a folder with a contractor.
- A sales team shares documents with a prospect.
- An agency receives access to campaign assets.
- Someone makes a file available to everyone in the organization because it's easier than adding individual collaborators.
The work gets done, but the permissions often remain.
Months or years later, the project has ended, employees have changed roles, contractors have left, and thousands of new files have been created.
Yet much of that historical access may still exist.
Think of this as Google Drive permission debt: years of sharing decisions that were reasonable at the time but have never been reevaluated.
That's why organizations should periodically perform a historical audit of Google Drive permissions rather than relying exclusively on controls for newly created files.
Reducing this accumulated access is a fundamental part of securing Google Drive because it addresses exposure that may have existed unnoticed for months or even years.
{{cta-1}}
What Google Drive Permissions Should You Audit?
Not every shared file is a security problem.
Collaboration is the entire point of Google Workspace. The goal isn't to stop users from sharing; it's to identify sharing that creates unnecessary risk.
Security teams should pay particular attention to several types of exposure.
The important question isn't simply "Is this file shared?"
It's: Who can access this data, what data is it, why do they have access, and should they still have it?
That context is what turns permission management into data security and makes access governance an important component of an organization's overall Google Workspace security program.
Internal Oversharing Matters, Too
Google Drive security discussions often focus on external sharing, but external exposure is only part of the problem.
Sensitive data can also be overexposed inside an organization.
Consider an HR document containing employee information or a financial spreadsheet containing acquisition plans. Neither file needs to be publicly accessible to create risk. If either is available to "Anyone in the organization with the link," hundreds or thousands of employees may technically have access even though only a handful need it.
This becomes increasingly important as organizations deploy AI throughout the enterprise. Specifically, Gemini.
AI tools and agents can interact with SaaS applications and the data users are already permitted to access. Broad internal permissions can therefore expand the pool of information that may be discoverable or retrievable through AI-enabled workflows.
Internal does not automatically mean secure.
Gemini now changes how data is discovered. Before AI, finding information inside Google Workspace required effort.
Employees needed to know a document existed, remember what it was called, know which Shared Drive or folder it lived in, and manually search through files to locate it. Even if permissions were broader than intended, many sensitive documents remained effectively buried simply because they were difficult to find.
Gemini changes that experience entirely. Instead of searching for a file, employees now search for answers. They can ask Gemini to summarize next quarter's revenue projections, explain a company policy, compare pricing documents, or find information related to a specific customer or project.
To generate those responses, Gemini scans the files a user already has permission to access and retrieves the relevant information from across Google Workspace.
This is where years of excessive internal permissions become much more significant.
The AI isn't bypassing Google's security controls or creating new permissions. It's operating within the access that already exists. By making enterprise knowledge conversational and instantly searchable, it dramatically increases the visibility of information that was never meant to be broadly discoverable.
Organizations need to apply least-privilege principles to internal access just as they do to external sharing. Identifying and remediating internal oversharing should therefore be treated as a core Google Drive security practice, rather than focusing exclusively on files that have left the organization.
Why a One-Time Bulk Cleanup Isn't Enough
Let's say your security team completes a Google Drive audit and identifies 100,000 unnecessary permissions.
You then remove them manually. The environment is cleaner, but employees haven't stopped collaborating.
The next day, someone shares a file with a personal Gmail account. Someone else creates an "Anyone with the link" URL. A new contractor is granted access to a folder. Another employee makes sensitive information available organization-wide.
Aaaand the cycle begins again.
That's why effective Google Drive permission management should follow three stages:
1. Audit your exposure with a free risk assessment
Understand your existing Google Drive attack surface.
Identify historical external, public, internal, former-employee, personal-account, group, and inherited exposure across My Drive and Shared Drives.
2. Remediate the existing permissions in bulk
Determine which permissions create unnecessary risk and remove them at scale.
Remediation should be contextual rather than indiscriminate. The objective isn't to make every file private; it's to remove access that violates your organization's security policies while preserving legitimate collaboration.
3. Enforce an ongoing remediation policy with granular controls
Continuously monitor new sharing activity and enforce policies when risky access appears.
This prevents security teams from repeating the same massive cleanup every six months.
Audit. Remediate. Enforce.
Bulk remediation should be the beginning of a stronger Google Workspace security posture, not the end of the project. Historical cleanup addresses the permissions that already exist; continuous monitoring and enforcement help prevent unnecessary access from accumulating again.
How DoControl Bulk Remediates Google Drive Sharing Permissions
DoControl approaches Google Drive permission management as an ongoing data security problem rather than a one-time file cleanup.
Security teams can inventory Google Drive assets across My Drive and Shared Drives and filter data using context such as sharing status, data ownership, external collaborators, activity, Google Labels, and other business context.
This allows teams to identify specific categories of historical exposure before taking action.
For example, an organization could identify sensitive, inactive files that remain externally shared or highly sensitive files available organization-wide, and then target those permissions for remediation.
DoControl's Bulk Remediation capability allows security teams to remediate permissions across up to one million assets in a single action, including actions such as removing external collaborators, removing public sharing, reducing organization-wide access, and addressing historical exposure.
Critically, remediation doesn't have to stop with the historical cleanup.
DoControl's automated remediation workflows can continuously monitor Google Drive activity and apply policies when new risky sharing occurs. Organizations can build controls around scenarios such as public sharing, external collaborators, sensitive data exposure, employee lifecycle changes, and other business context.
This creates a continuous cycle:
Discover → Assess → Remediate → Monitor → Enforce
Instead of periodically discovering that the same sharing problem has returned, security teams can address both the historical backlog and the new exposure being created every day.
This combination of historical remediation and ongoing enforcement helps organizations move from reactive permission cleanup toward continuous Google Drive security and a stronger overall Google Workspace security posture.
Bulk Permission Removal Should Protect Data Without Breaking Collaboration
The goal of Google Drive security isn't to eliminate sharing.
It's to make sure the right people have the right access to the right data for the right amount of time.
For a handful of files, Google's native sharing controls may be all you need. For larger organizations, however, bulk permission removal quickly becomes a question of scale, context, and continuous enforcement.
Security teams need to know what's exposed, determine which permissions actually create risk, remediate historical exposure in bulk, and prevent unnecessary access from accumulating again.
Because removing 100,000 risky permissions today is valuable.
Making sure you don't have another 100,000 to clean up next year is better.
🧹 See how DoControl helps you discover and clean up Google Drive exposure.
Frequently Asked Questions
Can you remove sharing permissions from multiple Google Drive files at once?
Yes. Google Drive allows users to select multiple files and modify certain sharing permissions together. This works well for small, known groups of files. Larger organization-wide cleanups typically require APIs or security tooling capable of identifying and remediating permissions across the environment.
How do I remove someone's access from multiple Google Drive files?
If the files are known and located together, you can select multiple files, open the sharing settings, and remove the user's access. If the user's permissions exist across many folders, users, or Shared Drives, organizations may need to first identify every asset the person can access before performing bulk remediation.
How do I find externally shared files in Google Drive?
Google Workspace administrators can use native administrative and audit capabilities to investigate sharing activity. For larger environments, security platforms can inventory Google Drive assets and filter them by sharing status, external collaborators, ownership, sensitivity, and other context.
Can I bulk remove "Anyone with the link" permissions?
Public or link-based sharing needs to be addressed separately from permissions granted directly to named users. At enterprise scale, organizations should first identify all assets with public or link-based exposure and then determine which links violate policy before bulk remediation.
How do I remove former employees from Google Drive files?
Suspending or deleting an employee's corporate Google account addresses access through that account, but security teams should also investigate historical sharing involving personal accounts, external identities, ownership, and other permissions associated with the employee's activity. This is why offboarding should include a data access review rather than only account deactivation.
How often should Google Drive permissions be reviewed?
There isn't one frequency that works for every organization. High-risk sharing should ideally be monitored continuously, while broader access reviews and historical audits can be performed on a scheduled basis. The objective is to prevent unnecessary permissions from accumulating between periodic audits.
What is the difference between auditing and remediating Google Drive permissions?
An audit identifies who has access to Google Drive data and where potentially risky exposure exists. Remediation actually changes or removes those permissions. A mature Google Workspace security program needs both: visibility tells you where the risk is; remediation reduces it.


