OneDrive for Business Site Collection user permissions

%3CLINGO-SUB%20id%3D%22lingo-sub-31857%22%20slang%3D%22en-US%22%3EOneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-31857%22%20slang%3D%22en-US%22%3E%3CP%3EI%20found%20today%20that%20if%20anyone%20with%20an%20Office%20365%2FOD4B%20account%20goes%20to%20the%20About%20Me%20page%20and%20selects%20apps%20they%20are%20taken%20to%20a%20full%20SharePoint%20style%20Site%20Contents%20page%20which%20allows%20them%20to%20create%20sub-sites%2C%20lists%20libraries%20and%20add%20other%20apps%20to%20their%20own%20personal%20site%20collection.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20645px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F8796i6F2F98BBB332670A%2Fimage-dimensions%2F645x350%3Fv%3D1.0%22%20width%3D%22645%22%20height%3D%22350%22%20alt%3D%22OneDriveSiteContents.PNG%22%20title%3D%22OneDriveSiteContents.PNG%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EPage%20linked%20to%20by%20clicking%20'Apps'%20on%20the%20About%20Me%20page.%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdditionally%2C%20this%20gives%20the%20user%20access%20to%20their%20full%20site%20settings%20(at%20site%20collection%20admin%20level).%20This%20also%20means%20they%20can%2C%20in%20theory%2C%20access%20their%20site%20in%20SharePoint%20Designer%20as%20access%20is%20turned%20on%20by%20default.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20645px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F8798iB3DBCEF25C4B73B8%2Fimage-dimensions%2F645x350%3Fv%3D1.0%22%20width%3D%22645%22%20height%3D%22350%22%20alt%3D%22OneDriveSiteSettings.PNG%22%20title%3D%22OneDriveSiteSettings.PNG%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESite%20Settings%20for%20One%20Drive%20for%20Business%20personal%20Site%20Collection%3C%2FSPAN%3E%3C%2FSPAN%3ENeither%20of%20the%20above%20pages%20can%20be%20accessed%20from%20the%20cog%20when%20in%20OneDrive%20for%20Business%2C%20where%20you%20get%20the%20standard%20Office%20365%20options.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20this%20be%20ability%20be%20removed%20asap%20as%20users%20should%20not%20have%20this%20level%20of%20access%20over%20the%20back-end%20of%20their%20OD4B%20area%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-31857%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-31874%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-31874%22%20slang%3D%22en-US%22%3EYeap%2C%20Site%20settings%20has%20always%20been%20there...in%20the%20old%20and%20in%20the%20new%20UI%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-31867%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-31867%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20my%20cog%20menu%20(in%20Italian)%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20201px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F8803i015FDF9B2B6BB4E4%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%222016-11-24%2017_23_26-Program%20Manager.jpg%22%20title%3D%222016-11-24%2017_23_26-Program%20Manager.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20you%20can%20see%2C%20Site%20Settings%20is%20there.%3C%2FP%3E%3CP%3EI%20don't%20know%20why%20you%20don't%20see%20it...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20BTW%2C%20being%20the%20SCA%20of%20his%2Fher%20own%20ODFB%2C%20every%20user%20can%20do%20what%20he%20wants...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-31863%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-31863%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20screenshot%20below%20is%20the%20cog%20menu%20from%20OneDrive%20for%20business.%20Also%2C%20these%20features%20should%20not%20even%20be%20available%20within%20OneDrive%20as%20it%20is%20supposed%20to%20predominantly%20be%20a%20file%20store.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20the%20very%20least%20we%2C%20as%20Office%20365%2FSharePoint%20admins%2C%20need%20the%20ability%20to%20turn%20this%20ability%20off%20for%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%3E%3CSPAN%20class%3D%22lia-message-image-wrapper%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F8800i5351E819CFBE5459%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20border%3D%220%22%20alt%3D%22OD4B%20Cog%20Menu.PNG%22%20title%3D%22OD4B%20Cog%20Menu.PNG%22%20width%3D%22185%22%20height%3D%22334%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-31858%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-31858%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20go%20to%20the%20same%20pages%20by%20(1)%20Cog%20-%26gt%3B%20Site%20Settings%20and%20(2)%20App%20in%20the%20left%20menu.%3C%2FP%3E%3CP%3EIt%20has%20always%20been%20there.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1631159%22%20slang%3D%22en-US%22%3ERe%3A%20OneDrive%20for%20Business%20Site%20Collection%20user%20permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1631159%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F32063%22%20target%3D%22_blank%22%3E%40Iain%20Prout%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20encountered%20the%20same%20situation%20and%20wonder%20how%20to%20disable%20this%20functionality%20of%20managing%20own%20site%20collection%2C%20but%20still%20providing%20a%20working%20onedrive%20account%20and%20synchronisation.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsers%20should%20not%20access%20any%20site%20collection%20setting%20and%20grant%20permissions%20for%20the%20whole%20onedrive%20to%20other%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20official%20solution%20for%20this%20problem%20from%20Microsoft%3F%3C%2FP%3E%3CP%3EOr%20at%20least%20a%20workaround%20(for%20example%20to%20remove%20a%20users%20as%20site%20collection%20admin%20and%20only%20grant%20rights%20to%20the%20document%20list%20which%20is%20used%20by%20OneDrive)%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I found today that if anyone with an Office 365/OD4B account goes to the About Me page and selects apps they are taken to a full SharePoint style Site Contents page which allows them to create sub-sites, lists libraries and add other apps to their own personal site collection.Page linked to by clicking 'Apps' on the About Me page.Page linked to by clicking 'Apps' on the About Me page.

 

Additionally, this gives the user access to their full site settings (at site collection admin level). This also means they can, in theory, access their site in SharePoint Designer as access is turned on by default.Site Settings for One Drive for Business personal Site CollectionSite Settings for One Drive for Business personal Site CollectionNeither of the above pages can be accessed from the cog when in OneDrive for Business, where you get the standard Office 365 options.

 

Can this be ability be removed asap as users should not have this level of access over the back-end of their OD4B area?

5 Replies
Highlighted

You can go to the same pages by (1) Cog -> Site Settings and (2) App in the left menu.

It has always been there.

Highlighted

The screenshot below is the cog menu from OneDrive for business. Also, these features should not even be available within OneDrive as it is supposed to predominantly be a file store. 

 

At the very least we, as Office 365/SharePoint admins, need the ability to turn this ability off for users.

 

OD4B Cog Menu.PNG

 

Highlighted

This is my cog menu (in Italian):

 

2016-11-24 17_23_26-Program Manager.jpg

 

As you can see, Site Settings is there.

I don't know why you don't see it...

 

And BTW, being the SCA of his/her own ODFB, every user can do what he wants...

Highlighted
Yeap, Site settings has always been there...in the old and in the new UI
Highlighted

@Iain Prout 

We have encountered the same situation and wonder how to disable this functionality of managing own site collection, but still providing a working onedrive account and synchronisation. 

 

Users should not access any site collection setting and grant permissions for the whole onedrive to other users.

 

Is there any official solution for this problem from Microsoft?

Or at least a workaround (for example to remove a users as site collection admin and only grant rights to the document list which is used by OneDrive)?