Document Property Demotion

Iron Contributor

Hi,

 

We have had an issue where documents that have been added to SharePoint library which contained metadata columns have been modified to have the column properties inside the document. The document was then downloaded and sent to an external party and if they opened the downloaded file and looked at the properties they can see all the metadata tags available. 

 

You can clean the document properties before its sent out but is there a way to restrict the properties being added to the document in the first place when they are uploaded into a library?

 

I have read about Document Property demotion but this doesnt seem to be an option to SharePoint online.

 

3 Replies
Hello! I suppose, your issue isn’t the restriction of metadata, because you need it for so much things in SharePoint. Your problem is granting restricted access to external/ internal users. I recommend to manage it with permissions in your user groups. Ask your site owner about that. Greets, Eva

Thanks @Eva Vogel 

 

Its not really the issue about permissions. The site is for internal users and they have the possibility to download documents from the site. The issue is that if they then decide to email the document to an external party then they will not know that the document contains inherited document properties, which may contain sensitive information, come from SharePoint. 

 

I hope that makes sense?

Hello! I suggest, you could give them access to a library or list with a certain view, containing only public columns (metadata without restrictions). and with standard view your internal users get all columns (metadata) in default.

 

If you have created that 2 views, advice your users about the first view (for all) and the 2nd view (restricted view for external use). To be more certain, you could additionally create a new page and insert one or more webparts, where they see only the 2nd views in different lists or libraries. So they can publish files to others with the restricted column settings. So there will be e.g. a new entry like "FOR EXTERNAL USE" in your left navigation with entering that page and then they could share docs only with extern contacts. But every user must be informed about that and if they ignore it, its on their own risk and they will be held responsible for that handling.

 

 

Hope that helps. Greets, Eva