Home

How MS-Teams/Office-365-Group Owners got Full control permissions on the underlying sharepoint site

%3CLINGO-SUB%20id%3D%22lingo-sub-717370%22%20slang%3D%22en-US%22%3ERe%3A%20How%20MS-Teams%2FOffice-365-Group%20Owners%20got%20Full%20control%20permissions%20on%20the%20underlying%20sharepoint%20s%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-717370%22%20slang%3D%22en-US%22%3E%3CP%3ETo%20answer%20your%20first%20question%2C%20TestTeam123%20Owners%20you%20see%20in%20the%20Site%20Collection%20Administrators%20seems%20to%20be%20the%20Office%20365%20Owners%20role%20group%20and%20not%20the%20site's%20SharePoint%20security%20owners%20group.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20reason%20I%20think%20this%20is%20because%20if%20you%20open%20your%20browser's%20dev%20tools%20and%20inspect%20the%20HTML%20for%20that%20element%20(the%20group%20as%20you%20see%20it%20when%20viewing%20the%20Site%20Collection%20Admins)%2C%20you%20will%20see%20that%20it%20is%20a%20domain-type%20federated%20group%20and%20not%20a%20SharePoint%20security%20group.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-717672%22%20slang%3D%22en-US%22%3ERe%3A%20How%20MS-Teams%2FOffice-365-Group%20Owners%20got%20Full%20control%20permissions%20on%20the%20underlying%20sharepoint%20s%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-717672%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F62361%22%20target%3D%22_blank%22%3E%40Kevin%20McKeown%3C%2FA%3E%26nbsp%3Bwrote%3A%3CBR%20%2F%3E%3CP%3ETo%20answer%20your%20first%20question%2C%20TestTeam123%20Owners%20you%20see%20in%20the%20Site%20Collection%20Administrators%20seems%20to%20be%20the%20Office%20365%20Owners%20role%20group%20and%20not%20the%20site's%20SharePoint%20security%20owners%20group.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20reason%20I%20think%20this%20is%20because%20if%20you%20open%20your%20browser's%20dev%20tools%20and%20inspect%20the%20HTML%20for%20that%20element%20(the%20group%20as%20you%20see%20it%20when%20viewing%20the%20Site%20Collection%20Admins)%2C%20you%20will%20see%20that%20it%20is%20a%20domain-type%20federated%20group%20and%20not%20a%20SharePoint%20security%20group.%3C%2FP%3E%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F62361%22%20target%3D%22_blank%22%3E%40Kevin%20McKeown%3C%2FA%3E%26nbsp%3B%20thanks%20for%20the%20reply.%20but%20what%20about%20my%20third%20question%2C%20which%20is%20the%20most%20important%20to%20me...%20any%20idea%20what%20is%20going%20on%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713847%22%20slang%3D%22en-US%22%3EHow%20MS-Teams%2FOffice-365-Group%20Owners%20got%20Full%20control%20permissions%20on%20the%20underlying%20sharepoint%20site%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713847%22%20slang%3D%22en-US%22%3E%3CP%3EUsing%20the%20office%20365%20admin%20center%20and%20the%20office%20365%20admin%20username%20i%20created%20a%20new%20MS%20Teams%20as%20follow%2C%20and%20i%20name%20it%20%22TestTeam123%22%3A-%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Enow%20this%20have%20created%20a%20new%20Office%20365%20group%20%2B%20sharepoint%20modern%20team%20site.%20I%20also%20realized%20the%20following%3A-%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20adding%20a%20member%20to%20the%20MS-Teams%20or%20Office%20365%20group%20will%20automatically%26nbsp%3B%20grant%20the%20member%20user%20Edit%20permission%20on%20the%20sharepoint%20site.%20now%20this%20behavioure%20is%20understandable%20as%20inside%20the%20SharePoint%20site%2C%20we%20can%20find%20that%20inside%20the%20sharepoint%20member%20group%20%26gt%3B%26gt%3B%20there%20is%20an%20office%20365%20group's%20member%20added%20by%20default%20(which%20have%20the%20same%20name%20as%20the%20sharepoint%20members%20group)%20as%20follow%3A-%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3Eand%20most%20importantly%2C%20if%20i%20remove%20the%20above%20office%20365%20group's%20member%20from%20the%20sharepoint%20members%20group%20(i%20did%20this%20for%20testing%20purposes%20only%2C%20as%20on%20reality%20we%20should%20not%20do%20so)%2C%20the%20Office%20365%20group's%20members%20will%20not%20longer%20have%20access%20to%20sharepoint%20site.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20But%20what%20i%20did%20not%20understand%20is%20that%20if%20we%20add%20an%20owner%20to%20the%20MS%20Teams%2FOffice-365-group%20then%20the%20owner%20will%20have%20full%20control%20permission%20on%20the%20sharepoint%20site.%20so%20i%20thought%20that%20similar%20to%20the%20members%20case%2C%20i%20will%20find%20that%20the%20office%20365%20group's%20owner%20is%20added%20inside%20the%20sharepoint%20owner%20group%2C%20but%20this%20is%20not%20the%20case.%20but%20on%20the%20other%20hand%20i%20checked%20the%20SharePoint's%20site%20collection%20admins%20section%2C%20and%20i%20found%20this%20group%20is%20added%20by%20default%3A-%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Enow%20based%20on%20the%20above%20case%2C%20i%20have%20the%20following%203%20questions%3A-%3C%2FP%3E%3CP%3E1.%20for%20the%20above%20%22TestTeam123%20Owner%22%20group%20added%20inside%20the%20site%20collection%20admins%20section%2C%20is%20this%20the%20sharepoint%20owner%20group%3F%20or%20it%20is%20the%20office%20365%20group's%20owners%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Why%20did%20Microsoft%20add%20the%20office%20365%20group's%20member%20inside%20the%20sharepoint%20member%20group%2C%20while%20it%20did%20not%20add%20the%20office%20365%20group's%20owner%20inside%20the%20sharepoint%20owner%20group%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3.%20for%20testing%20purposes%20i%20remove%20the%20%22TestTeam123%20Owner%22%20group%20from%20the%20site%20collection%20admins%20section%2C%20but%20still%20the%20office%20365%20group's%20owners%20users%20have%20full%20control%20on%20the%20sharepoint%20site..%20so%20what%20is%20going%20behind%20the%20scenes%20%3F%20i%20did%20the%20remove%20around%2020%20hours%20ago%2C%20so%20i%20do%20not%20think%20it%20is%20a%20sync%20or%20timing%20issue...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-713847%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
john john
Super Contributor

Using the office 365 admin center and the office 365 admin username i created a new MS Teams as follow, and i name it "TestTeam123":-

admin123.png

 

now this have created a new Office 365 group + sharepoint modern team site. I also realized the following:-

 

1. adding a member to the MS-Teams or Office 365 group will automatically  grant the member user Edit permission on the sharepoint site. now this behavioure is understandable as inside the SharePoint site, we can find that inside the sharepoint member group >> there is an office 365 group's member added by default (which have the same name as the sharepoint members group) as follow:-

 

memebrs2.png

and most importantly, if i remove the above office 365 group's member from the sharepoint members group (i did this for testing purposes only, as on reality we should not do so), the Office 365 group's members will not longer have access to sharepoint site.

 

2. But what i did not understand is that if we add an owner to the MS Teams/Office-365-group then the owner will have full control permission on the sharepoint site. so i thought that similar to the members case, i will find that the office 365 group's owner is added inside the sharepoint owner group, but this is not the case. but on the other hand i checked the SharePoint's site collection admins section, and i found this group is added by default:-

 

SCA.png

 

now based on the above case, i have the following 3 questions:-

1. for the above "TestTeam123 Owner" group added inside the site collection admins section, is this the sharepoint owner group? or it is the office 365 group's owners?

 

2. Why did Microsoft add the office 365 group's member inside the sharepoint member group, while it did not add the office 365 group's owner inside the sharepoint owner group?

 

3. for testing purposes i remove the "TestTeam123 Owner" group from the site collection admins section, but still the office 365 group's owners users have full control on the sharepoint site.. so what is going behind the scenes ? i did the remove around 20 hours ago, so i do not think it is a sync or timing issue...

 

 

2 Replies

To answer your first question, TestTeam123 Owners you see in the Site Collection Administrators seems to be the Office 365 Owners role group and not the site's SharePoint security owners group. 

 

The reason I think this is because if you open your browser's dev tools and inspect the HTML for that element (the group as you see it when viewing the Site Collection Admins), you will see that it is a domain-type federated group and not a SharePoint security group.

 


@Kevin McKeown wrote:

To answer your first question, TestTeam123 Owners you see in the Site Collection Administrators seems to be the Office 365 Owners role group and not the site's SharePoint security owners group. 

 

The reason I think this is because if you open your browser's dev tools and inspect the HTML for that element (the group as you see it when viewing the Site Collection Admins), you will see that it is a domain-type federated group and not a SharePoint security group.


@Kevin McKeown  thanks for the reply. but what about my third question, which is the most important to me... any idea what is going on?

Related Conversations
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
Early preview of Microsoft Edge group policies
Sean Lyndersay in Discussions on
65 Replies
*Updated 9/3* Syncing in Microsoft Edge Preview Channels
Elliot Kirk in Articles on
201 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
2 Replies