Home

SPO access issues - guest user suddenly only has access to 2 out of 4 SPO sites

%3CLINGO-SUB%20id%3D%22lingo-sub-801552%22%20slang%3D%22en-US%22%3ESPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-801552%22%20slang%3D%22en-US%22%3E%3CP%3EHello.%20We%20have%20a%20guest%20user%20who%20until%20today%2C%20could%20access%20all%204%20SPO%20sites%20to%20which%20they'd%20been%20granted%20access.%20As%20of%20today%2C%20they%20can%20only%20access%202%20of%20those%20sites.%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EThey%20are%20listed%20as%20(one%20of%20many)%20guest%20users%20in%20Azure%20AD%3C%2FLI%3E%3CLI%3ETheir%20permissions%20are%20the%20same%20across%20all%204%20SPO%20sites%20(read)%3C%2FLI%3E%3CLI%3EWe've%20removed%20and%20re-added%20them%20to%20their%20SPO%20security%20groups%3C%2FLI%3E%3CLI%3EThey%20tried%20Internet%20Explorer%20and%20Chrome%3C%2FLI%3E%3CLI%3EThey've%20tried%20normal%20and%20in%20private%20browsing%3C%2FLI%3E%3CLI%3EWe've%20looked%20at%20broken%20permissions%20to%20make%20sure%20the%20URL%20they're%20using%20isn't%20uniquely%20secured%3C%2FLI%3E%3CLI%3EWe%20had%20them%20request%20access%20via%20the%20site%20and%20we've%20clicked%20to%20allow%20them%2C%20and%20they%20still%20cannot%20access%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-801552%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-801598%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-801598%22%20slang%3D%22en-US%22%3E%3CP%3Eanother%20detail%20-%20when%20i%20export%20users%20from%20the%20O365%20admin%20portal%2C%20this%20guest%20who%20has%20been%20using%20the%20SPO%20sites%20for%20year%20shows%20as%20just%20being%20added%20on%207%2F30%2F19%2C%20corresponding%20with%20the%20password%20change%20timestamp.%20They%20have%20no%20ProxyAddress%20listed%2C%20while%20everyone%20else%20does.%20Not%20sure%20if%20this%20is%20important...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-801834%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-801834%22%20slang%3D%22en-US%22%3EShouldn%E2%80%99t%20if%20they%20have%20access%20to%20two%20other%20sites.%20Wondering%20if%20a%20similar%20bug%20got%20reintroduced%20where%20if%20you%20had%20a%20people%20web%20part%20of%20a%20people%20hover%20card%20link%20such%20as%20created%20by%20column%20showing%20on%20a%20page%20it%20would%20give%20access%20request%20error.%20Or%20if%20comments%20were%20turned%20on%20the%20page.%20Are%20comments%20turned%20on%2C%20on%20the%20pages%20they%20have%20%2F%20don%E2%80%99t%20have%20access%20too%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-802192%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-802192%22%20slang%3D%22en-US%22%3EHave%20you%20tried%20to%20re-add%20the%20user%20directly%20in%20Azure%20AD%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803102%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803102%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%26nbsp%3B-comments%20are%20not%20turned%20on%20for%20the%20pages%20they%20can't%20access.%20The%20people%20web%20part%20shows%20no%20errors%20when%20I%20hover%20over%20her%20initials.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803103%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803103%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F60%22%20target%3D%22_blank%22%3E%40Juan%20Carlos%20Gonz%C3%A1lez%20Mart%C3%ADn%3C%2FA%3E%26nbsp%3B-%20as%20guests%2C%20they%20are%20added%20nightly%20as%20guests%20from%20the%20subsidiary's%20Azure%20AD%2C%20via%20a%20script.%20So%20far%2C%20the%20script%20had%20been%20working%20great%2C%20but%20I%20now%20have%203%20guest%20users%20who%20all%20show%20a%20password%20reset%20timestamp%20within%20a%20minute%20of%20each%20other%2C%20all%20suddenly%20locked%20out%20of%20certain%20sites.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803134%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803134%22%20slang%3D%22en-US%22%3Eif%20there%20is%20a%20people%20webpart%20on%20the%20pages%20that%20could%20be%20triggering%20the%20error.%20In%20the%20past%20anything%20that%20pulled%20up%20personal%20info%20from%20the%20tenant%20woudl%20trigger%20in%20the%20past.%20Is%20there%20something%20different%20on%20the%20pages%20that%20error%20vs.%20not%20in%20terms%20of%20people%20web%20parts%20%2F%20document%20libraries%20with%20created%20by%20links%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-803418%22%20slang%3D%22en-US%22%3ERe%3A%20SPO%20access%20issues%20-%20guest%20user%20suddenly%20only%20has%20access%20to%202%20out%20of%204%20SPO%20sites%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-803418%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%26nbsp%3B-%20on%20the%20sites%20they%20can't%20access%2C%20I%20also%20had%20them%20try%20links%20of%20just%20document%20libraries%20and%20lists%20they%20should%20have%20access%20to%2C%20and%20access%20denied%20there%20as%20well.%20it's%20so%20strange.%20but%20i%20do%20appreciate%20the%20info%20on%20those%20web%20parts%20causing%20issues.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hello. We have a guest user who until today, could access all 4 SPO sites to which they'd been granted access. As of today, they can only access 2 of those sites. 

  • They are listed as (one of many) guest users in Azure AD
  • Their permissions are the same across all 4 SPO sites (read)
  • We've removed and re-added them to their SPO security groups
  • They tried Internet Explorer and Chrome
  • They've tried normal and in private browsing
  • We've looked at broken permissions to make sure the URL they're using isn't uniquely secured
  • We had them request access via the site and we've clicked to allow them, and they still cannot access

Any ideas?

7 Replies

another detail - when i export users from the O365 admin portal, this guest who has been using the SPO sites for year shows as just being added on 7/30/19, corresponding with the password change timestamp. They have no ProxyAddress listed, while everyone else does. Not sure if this is important...

Highlighted
Shouldn’t if they have access to two other sites. Wondering if a similar bug got reintroduced where if you had a people web part of a people hover card link such as created by column showing on a page it would give access request error. Or if comments were turned on the page. Are comments turned on, on the pages they have / don’t have access too?
Highlighted
Have you tried to re-add the user directly in Azure AD?
Highlighted

Hi @Chris Webb -comments are not turned on for the pages they can't access. The people web part shows no errors when I hover over her initials.

Highlighted

Hi @Juan Carlos González Martín - as guests, they are added nightly as guests from the subsidiary's Azure AD, via a script. So far, the script had been working great, but I now have 3 guest users who all show a password reset timestamp within a minute of each other, all suddenly locked out of certain sites.

Highlighted
if there is a people webpart on the pages that could be triggering the error. In the past anything that pulled up personal info from the tenant woudl trigger in the past. Is there something different on the pages that error vs. not in terms of people web parts / document libraries with created by links?
Highlighted

@Chris Webb - on the sites they can't access, I also had them try links of just document libraries and lists they should have access to, and access denied there as well. it's so strange. but i do appreciate the info on those web parts causing issues.

Related Conversations
SharePoint
jcoloningpr in SharePoint on
1 Replies
question about access microsoft 365
NancyLWein in Access on
5 Replies
List displaying filter and hash
BurntNorton in SharePoint on
1 Replies