SharePoint User Access Permissions

%3CLINGO-SUB%20id%3D%22lingo-sub-353045%22%20slang%3D%22en-US%22%3ESharePoint%20User%20Access%20Permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-353045%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20created%20a%20site%20as%20a%20tactical%20solution%20for%20a%20problem.%20I've%20set%20up%20various%20User%20groups%20for%20the%20people%20who%20will%20be%20using%20the%20tool%20day%20to%20day%20and%20I've%20created%20a%20group%20called%20'Access%20Managers'%20for%20the%20team%20managers%20who%20I'd%20like%20to%20manage%20any%20user%20admin%20without%20having%20full%20control%20of%20the%20site.%20The%20following%20options%20have%20failed%3C%2FP%3E%3CP%3E1)%20I've%20given%20the%20group%20full%20control%20of%20all%20the%20other%20user%20group%20lists%3C%2FP%3E%3CP%3E2)%20I've%20created%20a%20new%20access%20level%20as%20a%20copy%20of%20full%20control%20but%20unticked%20all%20the%20things%20I%20don't%20want%20them%20to%20be%20able%20to%20do%26nbsp%3B%3C%2FP%3E%3CP%3E3)%20I've%20created%20a%20new%20access%20level%20as%20a%20copy%20of%20Contribute%20but%20with%20'Grant%20Permissions'%20ticked%20as%20well%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20what%20I'm%20trying%20to%20do%20even%20possible%3F%20If%20not%2C%20why%20not%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-354219%22%20slang%3D%22en-US%22%3ERe%3A%20SharePoint%20User%20Access%20Permissions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-354219%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F286853%22%20target%3D%22_blank%22%3E%40wendraa%3C%2FA%3E%20%2C%20which%20version%20of%20SharePoint%3F%3C%2FP%3E%3CP%3EYou%20can%20change%20Group%20Settings%2C%20and%20assign%20an%20owner%20(1%20person%20or%201%20AD%20Group%2C%26nbsp%3B%3CSPAN%3EI%20can%20image%2C%20you're%20farm%20is%20Active%20Directory%20based)%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F83771i5C8D45F79F06E649%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Cattura.PNG%22%20title%3D%22Cattura.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EThis%20SharePoint%20Group%2C%20can%20have%20some%20permission%20level%20(reader%20too%20if%20you%20need)%2C%20and%20the%20owner%20can%20manage%20SharePoint%20group%20membership%20without%20problems%20(maybe%20they%20need%20direct%20link%20to%20the%20SharePoint%20group%20membership%20like%26nbsp%3B%2F_layouts%2F15%2Fpeople.aspx%3FMembershipGroupId%3DXX%20%2C%20because%20of%20they%20don't%20have%20access%20to%20site%20settings%2C%20if%20permission%20level%20is%20reader).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnother%20way%20is%20the%20follow%3A%20instead%20adding%20users%20to%20SharePoint%20groups%2C%20and%20manage%20group%20membership%2C%20think%20about%20use%20Active%20Directory%20groups%20(or%20Azure%20AD)%20.%20You%20can%20then%20put%20those%20AAD%20groups%20into%20the%20target%20SP%20Group%20one%20time%2C%20and%20manage%20Active%20Directory%20Groups%20Membership.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3EFederico%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

Hi 

 

I've created a site as a tactical solution for a problem. I've set up various User groups for the people who will be using the tool day to day and I've created a group called 'Access Managers' for the team managers who I'd like to manage any user admin without having full control of the site. The following options have failed

1) I've given the group full control of all the other user group lists

2) I've created a new access level as a copy of full control but unticked all the things I don't want them to be able to do 

3) I've created a new access level as a copy of Contribute but with 'Grant Permissions' ticked as well

 

Is what I'm trying to do even possible? If not, why not? 

1 Reply

Hi @wendraa , which version of SharePoint?

You can change Group Settings, and assign an owner (1 person or 1 AD Group, I can image, you're farm is Active Directory based)

Cattura.PNG

This SharePoint Group, can have some permission level (reader too if you need), and the owner can manage SharePoint group membership without problems (maybe they need direct link to the SharePoint group membership like /_layouts/15/people.aspx?MembershipGroupId=XX , because of they don't have access to site settings, if permission level is reader).

 

Another way is the follow: instead adding users to SharePoint groups, and manage group membership, think about use Active Directory groups (or Azure AD) . You can then put those AAD groups into the target SP Group one time, and manage Active Directory Groups Membership.

 

Cheers,

Federico