Forum Discussion

JZMartinez's avatar
JZMartinez
Tin Contributor
Oct 01, 2026

Provide a global setting to hide the User Information List in SharePoint Online Sites

Many organization uses SharePoint Online sites that include external guests, suppliers, partners, and other collaborators. Today, any user with appropriate site permissions can access and enumerate the site's User Information List, either through the SharePoint interface or directly through REST API calls.

While this list is scoped to a specific site collection and is not a tenant-wide directory, it can still expose a significant amount of user profile information. On large collaboration sites, enterprise portals, or widely shared workspaces, users may be able to retrieve names, email addresses, job titles, departments, phone numbers, and other synchronized profile data for everyone known to that site.

A current workaround is removing the Browse User Information permission from site permission levels. However:

  • This can impact legitimate SharePoint functionality and user experiences.
  • It must be managed on a site-by-site basis.
  • Site Owners can re-enable the permission, unintentionally reintroducing the risk.
  • It is difficult to govern consistently across large environments with thousands of sites.

Requested Enhancement: Introduce a tenant-level setting that allows SharePoint Online administrators the ability to:

  • Hide the User Information List from end users.
  • Block direct access through SharePoint REST APIs.
  • Enforce the setting regardless of site-level permission changes.
  • Optionally scope the control to sites that allow external sharing.

This would provide organizations with a more reliable way to reduce unnecessary exposure of user profile information while maintaining consistent governance across their SharePoint environment.

No RepliesBe the first to reply