SharePoint / Script to locate documents encrypted with passwords
Published Jul 09 2020 12:34 PM 6,962 Views


A customer asked if there was a method to identity documents stored in SharePoint online that were encrypted with passwords. Since nothing like this existed, it was created using PowerShell. I’m sharing this because the logic in the script may be useful for others.


The Code

#Title: find-docpasswords
#Description: Iterates through each item in a specified list to find documents stored with passwords.
#Date: 7/8/2020
#Author: Mike Lee
#Disclaimer: This PowerShell script is provided "as-is" with no warranties expressed or implied. Use it at your own risk.
#Dependencies: SharePoint Online Client Components SDK:
#Tested with SharePoint Online Client Components SDK version 16.0.6906.1200
#Parameters: $SiteURL, $ListName, $username

#Add references to SharePoint client assemblies

#Your SPO Tenant
$SiteURL = ""

#The name of your document library
$Listname = "Documents"

#The admin account that has access to the library
$username = ""
$password = Read-Host "Enter Password" -AsSecureString

#Building Context
$ctx = New-Object Microsoft.SharePoint.Client.ClientContext($SiteURL)
$ctx.Credentials = New-Object Microsoft.SharePoint.Client.SharePointOnlineCredentials($userName, $password)
$List = $ctx.Web.Lists.GetByTitle($ListName)

#CAML Query to recursively look at all items in the library with a 5000 item row limit.
$camlQuery = New-Object Microsoft.SharePoint.Client.CamlQuery
$camlQuery.ViewXml = @"
<View Scope="RecursiveAll">
<OrderBy><FieldRef Name='ID' Ascending='TRUE'/></OrderBy>
<RowLimit Paged="TRUE">5000</RowLimit>

$items = $list.GetItems($camlQuery)

#function to read documents

function find-docpasswords($ctx, $FileUrl)
#Collect Documents Data
$FileURL = $Item.FieldValues['FileRef']

#Read the files from SharePoint online document library.
$fileInfo = [Microsoft.SharePoint.Client.File]::OpenBinaryDirect($ctx,$FileURL)
$stream = New-Object System.IO.MemoryStream

#Read the first row of bytes as text
$Start = [System.Text.Encoding]::Default.GetString($stream.ToArray()[0000..2000])

# Record files that are password protected
if($Start -match "E.n.c.r.y.p.t.e.d.P.a.c.k.a.g.e")
Write-Host "$SiteURL$FileURL -- Is Password Protected" -ForegroundColor Yellow
Write-Host "$SiteURL$FileURL -- Not Password Protected" -ForegroundColor Green


#Run the function to loop through all items in the library and find documents stored with passwords

foreach($item in $items)
$fileUrl = $item.FieldValues["fileref"]
find-docpasswords $ctx $fileurl



This scripts loops though a specified document library and reads the first 200 binary bytes as text. If the encrypted string is found, the document URL is reported in the console output.


Here is an example of the output:




You will need a few things to make this works.


  1. Installed the SharePoint Online Client Components SDK
  1. Specify the “$SiteURL, $Listname, and $username in the script.


Version history
Last update:
‎Sep 01 2020 12:55 PM
Updated by: