Home

Breaking inheritance permissions

%3CLINGO-SUB%20id%3D%22lingo-sub-646021%22%20slang%3D%22en-US%22%3EBreaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-646021%22%20slang%3D%22en-US%22%3E%3CP%3EHaving%20issues%20with%20permissions%20in%20my%20SP%202016%20site.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20Site%20%26gt%3B%20SubSite%26gt%3BList.%26nbsp%3B%20In%20the%20both%20the%20SubSite%20and%20the%20List%2C%20I%20have%202%20groups%3B%20edit%20and%20read%20only.%26nbsp%3B%20I%20need%20a%20group%20of%20people%20to%20have%20read%20only%20access%20to%20the%20SubSite%20but%20edit%20access%20to%20the%20list.%26nbsp%3B%20I've%20broken%20the%20inherited%20permissions%20but%20that%20is%20not%20working.%26nbsp%3B%20When%20ever%20I%20move%20the%20group%20of%20people%20to%20read%20only%20in%20the%20SubSite%2C%20it%20also%20moves%20them%20to%20the%20same%20read%20only%20group%20in%20the%20list.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20a%20setting%20I'm%20missing%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-646021%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-646067%22%20slang%3D%22en-US%22%3ERe%3A%20Breaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-646067%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F325149%22%20target%3D%22_blank%22%3E%40Bryan123%3C%2FA%3E%26nbsp%3BThe%20%22Edit%22%20and%20%22Read%20only%22%20group%20are%20present%20in%20the%20scope%20of%20Site%20collection%20and%20there%20is%20only%20one%20copy%20of%20it.%20There%20is%20no%20different%20copy%20of%20the%20groups%20for%20the%20subsite%20or%20the%20list.%20So%20if%20users%20are%20added%2Fremoved%20from%20any%20of%20these%202%20groups%20they%20get%2Floose%20access%20from%20both%20the%20subsite%20and%20the%20list%20(even%20though%20permissions%20are%20broken).%20In%20your%20situation%2C%20you%20have%20two%20options%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E1.%20Grant%20users%20access%20directly%20to%20List%3A%26nbsp%3B%3C%2FSTRONG%3E%20You%20can%20grant%20users%20read%2F%20edit%20access%20directly%20to%20the%20list%20(without%20using%20groups).%20This%20is%20good%20if%20you%20have%20very%20less%20number%20of%20users%20and%20each%20list%20has%20its%20own%20unique%20permissions%20(i.e%20you%20dont%20have%20to%20replicate%20the%20same%20permissions%20in%20any%20other%20resource%20in%20SharePoint).%3C%2FP%3E%3CP%3E%3CSTRONG%3E2.%20Create%20groups%20for%20each%20unique%20resource%3A%3C%2FSTRONG%3E%20Instead%20of%20creating%20just%201%20edit%20%26amp%3B%20read%20only%20group%2C%20you%20need%20to%20create%20%22Subsite%20Edit%22%2C%20%22List%20Edit%22%2C%20%22Subsite%20Readonly%22%2C%20%22List%20read%20only%22.%20Grant%20the%20Susbite%20groups%20access%20to%20the%20subsite%20and%20List%20groups%20access%20to%20list.%20In%20this%20way%20when%20you%20add%20a%20user%20to%20Subsite%20readonly%20or%20edit%20group%2C%20they%20will%26nbsp%3B%20not%20get%20access%20to%20List.%20You%20can%20rarely%20go%20wrong%20if%20you%20choose%20this%20method.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-646080%22%20slang%3D%22en-US%22%3ERe%3A%20Breaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-646080%22%20slang%3D%22en-US%22%3EWas%20using%20the%20default%20visitor%20and%20member%20groups%20so%20I'll%20just%20create%20new%20groups%20per%20your%20suggestion.%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-648721%22%20slang%3D%22en-US%22%3ERe%3A%20Breaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-648721%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F29544%22%20target%3D%22_blank%22%3E%40unnie%20ayilliath%3C%2FA%3E%26nbsp%3B%20%26nbsp%3BSo%2C%20I%20can%20create%20a%20new%20group%20in%20the%20SubSite%20but%20I%20can't%20create%20a%20group%20in%20the%20list.%26nbsp%3B%20When%26nbsp%3B%20I%20created%20the%20group%20in%20the%20SubSite%2C%20it%20does%20not%20let%20me%20choose%20what%26nbsp%3B%20resource%20to%20use%20with%20that%20new%20group%3B%20I%20can%20only%20use%20it%20in%20the%20SubSite.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20I%20create%20a%20edit%20group%20only%20for%20the%20list%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-648775%22%20slang%3D%22en-US%22%3ERe%3A%20Breaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-648775%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F325149%22%20target%3D%22_blank%22%3E%40Bryan123%3C%2FA%3E%26nbsp%3BSharePoint%20Groups%20are%20only%20created%20at%20the%20site%20level%2C%20they%20cannot%20be%20created%20at%20the%20List%20level.%20To%20accomplish%20your%20goal%2C%20you%20can%20create%20a%20new%20group%20in%20the%20subsite%2C%20and%20assign%20it%20the%20Permission%20level%20that%20will%20be%20appropriate%20for%20most%20of%20the%20objects%20in%20the%20site%2C%20THEN%20go%20to%20the%20list%2C%20break%20the%20permissions%20there%20and%20reassign%20the%20group%20to%20the%20desired%20permission%20level.%3C%2FP%3E%3CP%3EHTH%2C%20let%20us%20know%20if%20you%20have%20any%20questions.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-652111%22%20slang%3D%22en-US%22%3ERe%3A%20Breaking%20inheritance%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-652111%22%20slang%3D%22en-US%22%3EThat%20worked%2C%20thank%20you%3CBR%20%2F%3E%3CBR%20%2F%3ESeems%20as%20if%20there%20could%20be%20a%20better%20way%20of%20doing%20this%3C%2FLINGO-BODY%3E
Highlighted
Bryan123
Occasional Contributor

Having issues with permissions in my SP 2016 site.

 

I have a Site > SubSite>List.  In the both the SubSite and the List, I have 2 groups; edit and read only.  I need a group of people to have read only access to the SubSite but edit access to the list.  I've broken the inherited permissions but that is not working.  When ever I move the group of people to read only in the SubSite, it also moves them to the same read only group in the list.

 

Is there a setting I'm missing?  

5 Replies

@Bryan123 The "Edit" and "Read only" group are present in the scope of Site collection and there is only one copy of it. There is no different copy of the groups for the subsite or the list. So if users are added/removed from any of these 2 groups they get/loose access from both the subsite and the list (even though permissions are broken). In your situation, you have two options:

 

1. Grant users access directly to List:  You can grant users read/ edit access directly to the list (without using groups). This is good if you have very less number of users and each list has its own unique permissions (i.e you dont have to replicate the same permissions in any other resource in SharePoint).

2. Create groups for each unique resource: Instead of creating just 1 edit & read only group, you need to create "Subsite Edit", "List Edit", "Subsite Readonly", "List read only". Grant the Susbite groups access to the subsite and List groups access to list. In this way when you add a user to Subsite readonly or edit group, they will  not get access to List. You can rarely go wrong if you choose this method.

 

Was using the default visitor and member groups so I'll just create new groups per your suggestion.

Thank you

@unnie ayilliath   So, I can create a new group in the SubSite but I can't create a group in the list.  When  I created the group in the SubSite, it does not let me choose what  resource to use with that new group; I can only use it in the SubSite.

 

How do I create a edit group only for the list?

@Bryan123 SharePoint Groups are only created at the site level, they cannot be created at the List level. To accomplish your goal, you can create a new group in the subsite, and assign it the Permission level that will be appropriate for most of the objects in the site, THEN go to the list, break the permissions there and reassign the group to the desired permission level.

HTH, let us know if you have any questions. 

That worked, thank you

Seems as if there could be a better way of doing this