Forum Discussion

Vimmi Rawat's avatar
Vimmi Rawat
Brass Contributor
Jun 25, 2019

SharePoint root site permissions issue

We see below post pushed to our tenant's message center in the last week of May :

 

"Microsoft is committed to transparency regarding the privacy and security of our customers. As part of this commitment we’re providing details related to a permissions issue that we’ve detected. On April 4, 2019, an update to the service responsible for synchronizing tenant configuration changes within SharePoint introduced a code defect that caused root site permissions to revert to the default setting of Everyone Except External Users (EEEU). The update was related to a new feature that adds a SharePoint Communications Site as the root site for new tenants. On April 18, 2019, we disabled the new feature to prevent further existing tenants from being configured incorrectly, and in parallel released an update to address the underlying code defect. As a final step of remediation, we developed and executed a fix to revert the permission configuration issue on your root site. In order to prevent similar issues, we’re reviewing our update procedures and are including additional testing to ensure existing configurations and permissions are always maintained during our development cycles."

 

Considering Data privacy and security in mind as root site was exposed to all users ; we tried to reach out Microsoft Support and all we got to hear is ; there is no way to check which all users made the changes on site during affected duration . 

 

What can we do in such situation ?

3 Replies

    • Vimmi Rawat's avatar
      Vimmi Rawat
      Brass Contributor
      We do not have auditing enabled and infact auditing at Site Collection level was also disabled.
      • Norman Young's avatar
        Norman Young
        MVP

        Hi Vimmi Rawat,

         

        That's too bad auditing is not on. It has helped us out numerous times.

         

        I guess what MS support said is true then. You / they have no way of knowing.

         

        Norm

Resources