Forum Discussion
Users unable to determine who has access to document library due to security groups
Hi,
A good practice is to grant the minimum permissions required to get the work done and to assign permissions at the highest possible level, as well as to separate content with distinct permissions into separate libraries/site collections… that’s the theory.
In practice, as you wrote, situations vary: there are power users, exceptions, and temporary needs. It seems to me that a lot depends on the policy you define—for example, exceptions are managed only by IT, which, based on a request, maintains a register and grants additional permissions according to its own scheme (who, where, for how long, etc.).
If you are more focused on users managing these permissions themselves, then appointing site owners and training them to use SharePoint groups instead of Security Groups, as far as I remember, provides greater transparency for users in terms of who belongs to which group, and so on. Entra ID groups offer better performance (related to indexing, as I recall) and centralized management, but they require permissions outside of SharePoint to manage them. Additionally, from an IT perspective, it is worth conducting periodic audits of sharing links and exceptional permissions to identify and remove outdated or excessive access as staffing and project structures change. The sites themselves should also be covered by top-level policies defining access rules, etc.
I hope this helps you somehow in finding the solution that works best for you.
Thank you for your reply and sorry for taking so long to get back. It's been a wild few months.
I agree with what you are saying. I guess the situation is more niche than I originally thought.
Technically everything is working as it should, where certain users have access to specific folders of a sites document library via the security group and not having access to the site itself. Because of the way the company operates it was hard to determine any other way of doing this. They still want the flexibility to allow users who have access to be able to share the folders.
The only road blocks I am seeing are:
Security groups are the only way I can see to make it easy to give a new hire the same permissions as a current user or a user they are replacing. Custom shares would need to be handled by the users, but when the client says give user B access to all the folders User A had, I see no way of easily accomplishing this without security groups.
If users were able to see the members of the security group, I would be able to call it a day. This is the only thing that is holding me back from using groups. I figured users clicking on manage access and seeing groups having access to a resource, that it would be more common for users to want to know who are members of those groups so they have a better idea of who has access to the files/folders they are working on.