Forum Discussion
Security loophole in Private Channels?
This is not the isolation model Microsoft documents for a private channel. A private channel has a SharePoint site; membership is synchronized from Teams, and site permissions cannot be managed independently. Only channel owners and members should have site access.
The subsite appears to have broken inheritance and received a direct grant. SharePoint evaluates that subsite’s unique permissions, explaining why you can reach it while the channel site remains denied. Treat this as a configuration exposure, not proof that private-channel isolation is designed this way.
Have a SharePoint administrator audit the subsite’s unique permissions, sharing links, site-collection administrators, and sharing events. Remove the direct grant and restore inheritance if the content belongs to the channel. If permissions cannot be corrected, open a Microsoft support case before moving data. For content requiring another audience, use a separate SharePoint site with deliberately managed permissions rather than a subsite beneath a private-channel site.