SOLVED

Deny access to Sharepoint for some O365 User

%3CLINGO-SUB%20id%3D%22lingo-sub-1555914%22%20slang%3D%22en-US%22%3EDeny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1555914%22%20slang%3D%22en-US%22%3E%3CP%3EI%20want%20to%20forbid%20user%20access%20to%20sharepoint%20and%20to%20give%20him%20access%20to%20other%20Office365%20applications.User%20has%20Office%20E3%20licence.%3C%2FP%3E%3CP%3EI%20removed%20user%20from%20Sharepoint%20collection%20%3CA%20href%3D%22https%3A%2F%2Fcompany.sharepoint.com%2F_layouts%2F15%2Fpeople.aspx%3FMembershipGroupId%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fcompany.sharepoint.com%2F_layouts%2F15%2Fpeople.aspx%3FMembershipGroupId%3D0%3C%2FA%3E%3C%2FP%3E%3CP%3ERemoved%20from%20SPO%20site%3C%2FP%3E%3CP%3E%3CEM%3ERemove-SPOUser%20-Site%20%22%3CA%20href%3D%22https%3A%2F%2Fcompany.sharepoint.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fcompany.sharepoint.com%2F%3C%2FA%3E%22%20-LoginName%20%22user%40company.com%22%3C%2FEM%3E%3CBR%20%2F%3EBut%20user%20can%20still%20login%20to%20%3CA%20href%3D%22https%3A%2F%2Fcompany.sharepoint.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fcompany.sharepoint.com%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CEM%3EGet-SPOUser%20-Site%20%22%3CA%20href%3D%22https%3A%2F%2Fcompany.sharepoint.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fcompany.sharepoint.com%2F%3C%2FA%3E%22%20-LoginName%20%22test%40company.com%22%3C%2FEM%3E%3C%2FP%3E%3CP%3E%3CEM%3EDisplay%20Name%20Login%20Name%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20Groups%20User%20Type%3C%2FEM%3E%3CBR%20%2F%3E%3CEM%3E------------%20----------%20------%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B---------%3C%2FEM%3E%3CBR%20%2F%3E%3CEM%3Etest%20test%20test%40company.com%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%7B%7D%20Member%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1555914%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556217%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556217%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693767%22%20target%3D%22_blank%22%3E%40jarvis2020%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20possible%20that%20even%20if%20he's%20been%20removed%20from%20the%20Member%20group%20he's%20still%20got%20some%20item%20level%20permissions%20or%20access%20to%20a%20style%20gallery.%26nbsp%3B%20I'd%20try%3B%20-%3C%2FP%3E%3COL%3E%3CLI%3EUse%20the%20site%20Cog%20--%26gt%3B%20Site%20Settings%3C%2FLI%3E%3CLI%3EOn%20this%20new%20page%20click%20on%20Site%20Permissions%3C%2FLI%3E%3CLI%3EIn%20the%20ribbon%20check%20the%20user's%20name%20in%20the%20Check%20Permissions%20tool.%26nbsp%3B%20This'll%20highlight%20where%20they%20need%20to%20be%20removed%20from.%26nbsp%3B%20Act%20on%20this%20and%20let%20us%20know%20what%20happens%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556236%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556236%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11625%22%20target%3D%22_blank%22%3E%40Steven%20Andrews%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EHere%20are%20permissions%3A%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EEditGiven%20through%20the%20%22Members%22%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgroup.limited%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20ugc%20noreferrer%22%3Egroup.%3C%2FA%3E%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%3CA%20href%3D%22https%3A%2F%2Fgroup.limited%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20ugc%20noreferrer%22%3ELimited%3C%2FA%3E%26nbsp%3BAccessGiven%20through%20the%20%22SharePointHome%20OrgLinks%20Viewers%22%20group.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EOn%20site%20i%20want%20to%20remove%20access%20from%2Con%20site%20permissions%2C%20Site%20visitors%20are%20%22%3CSPAN%3EEveryone%20except%20external%20users%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20located%20above%20groups%20and%20both%20have%20only%20one%26nbsp%3B%20member%26nbsp%3B%22Everyone%20except%20external%20users%22%3C%2FP%3E%3CP%3EIs%20it%20safe%20to%20remove%20this%20group%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556290%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556290%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693767%22%20target%3D%22_blank%22%3E%40jarvis2020%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDepends%20on%20the%20use%20of%20your%20site.%26nbsp%3B%20Your%20organisation%20has%20set%20ALL%20users%20access%20to%20these%20two%20groups.%26nbsp%3B%20If%20you%20remove%20%22Everyone%20except%20external%20users%22%20from%20these%20groups%20you'll%20disable%20everyone%20that%20can%20access%20the%20site.%3C%2FP%3E%3CP%3EMight%20be%20worth%20discussing%20this%20internally%20with%20your%20IT%20colleagues%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556295%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556295%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693767%22%20target%3D%22_blank%22%3E%40jarvis2020%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIts%20not%20safe%20to%20remove%20that%20group.%20Its%20everyone%20in%20your%20company.%20So%20if%20you%20remove%20it%20from%20any%20site%20all%20users%20that%20are%20not%20explicitly%20given%20access%20through%20another%20group%20will%20loose%20access%20to%20the%20site.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20do%20indeed%20need%20everyone%20in%20your%20company%20to%20access%20a%20site%20but%201%20person%20not%20too%20then%20the%20only%20way%20to%20solve%20that%20is%20to%20create%20an%20AD%20Group%20for%20instance%20%22All%20SharePoint%20users%22%20and%20add%20everyone%20except%20that%20one%20user%2C%20then%20use%20that%20group.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20could%20maybe%20block%20them%20with%20conditional%20access%20too%2C%20may%20be%20worth%20a%20look.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1556960%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1556960%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F214649%22%20target%3D%22_blank%22%3E%40Andrew%20Hodges%3C%2FA%3E%26nbsp%3B%2C%20so%20if%20i%20understood%20correctly%2C%20remove%20%22Everyone%20except%20external%20users%22%2C%20and%20then%20add%3C%2FP%3E%3CP%3EAzure%20AD%20group%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1557829%22%20slang%3D%22en-US%22%3ERe%3A%20Deny%20access%20to%20Sharepoint%20for%20some%20O365%20User%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1557829%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693767%22%20target%3D%22_blank%22%3E%40jarvis2020%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20is%20right%2C%20but%20make%20sure%20everyone%20is%20in%20that%20AD%20group%20apart%20from%20that%20one%20user%20otherwise%20some%20of%20your%20users%20will%20loose%20access.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I want to forbid user access to sharepoint and to give him access to other Office365 applications.User has Office E3 licence.

I removed user from Sharepoint collection https://company.sharepoint.com/_layouts/15/people.aspx?MembershipGroupId=0

Removed from SPO site

Remove-SPOUser -Site "https://company.sharepoint.com/" -LoginName "user@company.com"
But user can still login to https://company.sharepoint.com/

Get-SPOUser -Site "https://company.sharepoint.com/" -LoginName "test@company.com"

Display Name Login Name                        Groups User Type
------------ ---------- ------                               ---------
test test test@company.com                           {} Member

6 Replies

@jarvis2020 

It's possible that even if he's been removed from the Member group he's still got some item level permissions or access to a style gallery.  I'd try; -

  1. Use the site Cog --> Site Settings
  2. On this new page click on Site Permissions
  3. In the ribbon check the user's name in the Check Permissions tool.  This'll highlight where they need to be removed from.  Act on this and let us know what happens

 

@Steven Andrews 

 

Here are permissions:

EditGiven through the "Members" group.

Limited AccessGiven through the "SharePointHome OrgLinks Viewers" group.

On site i want to remove access from,on site permissions, Site visitors are "Everyone except external users"

 

I located above groups and both have only one  member "Everyone except external users"

Is it safe to remove this group ?

@jarvis2020 

 

Depends on the use of your site.  Your organisation has set ALL users access to these two groups.  If you remove "Everyone except external users" from these groups you'll disable everyone that can access the site.

Might be worth discussing this internally with your IT colleagues?

Hi @jarvis2020 ,

 

Its not safe to remove that group. Its everyone in your company. So if you remove it from any site all users that are not explicitly given access through another group will loose access to the site.

 

If you do indeed need everyone in your company to access a site but 1 person not too then the only way to solve that is to create an AD Group for instance "All SharePoint users" and add everyone except that one user, then use that group. 

 

You could maybe block them with conditional access too, may be worth a look.

@Andrew Hodges , so if i understood correctly, remove "Everyone except external users", and then add

Azure AD group ?

 

thanks

best response confirmed by jarvis2020 (Occasional Contributor)
Solution

@jarvis2020 

 

That is right, but make sure everyone is in that AD group apart from that one user otherwise some of your users will loose access.