Forum Discussion
Matt Coats
Nov 07, 2017Steel Contributor
Ability to Share with "Anyone" permission change?
Our organization very recently discovered that the ability to share a document from a library in an external-sharing-enabled site seemingly requires higher permissions than it once did. In debugging this issue, I found that the only permission levels outside of "Full Control" that could share documents with "Anyone" were those that included the "Manage Permissions" and "Enumerate Permissions" privileges, which are considered Site-level permissions; the most any other permission level allows our users to do is share with users that already have access or specific people. This had not always been the case, and as my organization creates many of these links every day, I've only just heard of this from my users today. This is a problem for us in that the only OOTB permission level that includes "Manage Permissions" and "Enumerate Permissions" is Full Control, which we clearly can't start giving out to everyone.
I recognize that it is not outside the realm of possibility that some other Sharing setting could have caused this to occur, but after checking our Sharing settings org-wide, I see no indication that external sharing has been affected, and the fact that "Manage Permissions" and "Enumerate Permissions" do allow us to share as we normally have been make me think that Microsoft might have made a change to who is and who isn't allowed to create anonymous access links. Is anyone else experiencing this, or has anyone else encountered this issue to find that some setting had been changed to create this scenario?
- Deleted
Make sure someone didn't mess with the Site access requests page. /_layouts/15/user.aspx
Shown here, maybe this got turned off?
- Matt CoatsSteel Contributor
Checked this, was left untouched. This issue isn't site-specific, though--it's org-wide.
- DeletedAre these group connected sites or stand alone? I've never been able to share with external users without powershelling the sharing options on a group site even though my tenant is set to allow sharing. Wondering if with this latest rollout they are doing they fixed this? What are your tenant SharePoint sharing settings set to in the OneDrive admin?