SOLVED

Stop Access to secure files for admin

%3CLINGO-SUB%20id%3D%22lingo-sub-2108089%22%20slang%3D%22en-US%22%3EStop%20Access%20to%20secure%20files%20for%20admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108089%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI%20have%20been%20tasked%20to%20setup%20a%20SharePoint%20Site%20for%20my%20company%20which%20i%20have%20nearly%20completed%2C%20i%20have%20uploaded%20all%20files%20that%20are%20accessible%20by%20me.%20My%20CEO%20now%20wants%20to%20add%20his%20files%20but%20i%20cannot%20see%20a%20way%20of%20him%20doing%20this%20without%20removing%20me%20from%20being%20SharePoint%20Admin.%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20i%20make%20myself%20%22Admin%22%20instead%20of%20%22Primary%20Admin%22%2C%20then%20i%20can%20remove%20my%20access%20to%20the%20secure%20%22Corporate%22%20site%20but%20i%20can%20still%20go%20back%20to%20SharePoint%20Admin%20and%20change%20myself%20to%20Primary%20Admin%20and%20then%20gain%20access.%20Is%20there%20a%20way%20to%20stop%20this%20please%3F%20(i%20am%20self%20taught%20so%20i%20am%20possibly%20missing%20a%20glaring%20option%20somewhere%20or%20maybe%20looking%20at%20it%20from%20the%20wrong%20angle%20or%20something!!)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20greatly%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENathan%20Humphreys%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2108089%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2109319%22%20slang%3D%22en-US%22%3ERe%3A%20Stop%20Access%20to%20secure%20files%20for%20admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2109319%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F60%22%20target%3D%22_blank%22%3E%40Juan%20Carlos%20Gonz%C3%A1lez%20Mart%C3%ADn%3C%2FA%3E%26nbsp%3BThanks.%20I%20will%20look%20into%20that.%26nbsp%3B%3C%2FP%3E%3CP%3EMight%20be%20just%20what%20my%20CEO%20needs%20to%20put%20his%20mind%20at%20ease.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108332%22%20slang%3D%22en-US%22%3ERe%3A%20Stop%20Access%20to%20secure%20files%20for%20admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108332%22%20slang%3D%22en-US%22%3ETake%20a%20look%20also%20at%20what%20Privileged%20Identity%20Management%20can%20do%20for%20you%20in%20the%20scenario%20described.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108104%22%20slang%3D%22en-US%22%3ERe%3A%20Stop%20Access%20to%20secure%20files%20for%20admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108104%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F214649%22%20target%3D%22_blank%22%3E%40Andrew%20Hodges%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20taking%20the%20time%20and%20confirming%20that.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20other%20option%20is%20great%20except%20i%20will%20be%20doing%20lots%20of%20changes%20over%20the%20coming%20weeks%20and%20he%20wants%20to%20upload%20soon.%3C%2FP%3E%3CP%3EI%20have%20suggested%20he%20use%20ODfB%20for%20the%20ultra%20secure%20files%20and%20share%20those%20which%20need%20to%20be%20shared.%20We%20shall%20see%20what%20the%20outcome%20of%20that%20is.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20will%20discuss%20this%20on%20Monday.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Nathan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108095%22%20slang%3D%22en-US%22%3ERe%3A%20Stop%20Access%20to%20secure%20files%20for%20admin%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108095%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F947428%22%20target%3D%22_blank%22%3E%40Nathan_Humphreys%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EShort%20answer%20no.%20As%20a%20SharePoint%20Admin%20or%20Global%20Admin%20you%20will%20always%20be%20able%20to%20add%20yourself%20back%20into%20the%20site.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20practice%20it%20to%20have%20one%20user%20account%20and%20one%20Admin%20account%2C%20so%20your%20user%20account%20would%20never%20have%20access%20but%20your%20Admin%20account%20could%20add%20you%20back%20in%20as%20an%20Admin%20if%20the%20CEO%20needed%20support.%20In%20these%20situations%20you%20need%20to%20be%20trusted%20that%20you%20wouldn't%20look%20at%20the%20content%20in%20the%20site%20and%20the%20Audit%20logs%20are%20there%20to%20prove%20this%20if%20that%20were%20ever%20needed.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

I have been tasked to setup a SharePoint Site for my company which i have nearly completed, i have uploaded all files that are accessible by me. My CEO now wants to add his files but i cannot see a way of him doing this without removing me from being SharePoint Admin. 

If i make myself "Admin" instead of "Primary Admin", then i can remove my access to the secure "Corporate" site but i can still go back to SharePoint Admin and change myself to Primary Admin and then gain access. Is there a way to stop this please? (i am self taught so i am possibly missing a glaring option somewhere or maybe looking at it from the wrong angle or something!!)

 

Any help greatly appreciated.

 

Nathan Humphreys

4 Replies
best response confirmed by Nathan_Humphreys (Occasional Contributor)
Solution

@Nathan_Humphreys 

 

Short answer no. As a SharePoint Admin or Global Admin you will always be able to add yourself back into the site. 

 

Best practice it to have one user account and one Admin account, so your user account would never have access but your Admin account could add you back in as an Admin if the CEO needed support. In these situations you need to be trusted that you wouldn't look at the content in the site and the Audit logs are there to prove this if that were ever needed. 

@Andrew Hodges 

Thanks for taking the time and confirming that.

 

The other option is great except i will be doing lots of changes over the coming weeks and he wants to upload soon.

I have suggested he use ODfB for the ultra secure files and share those which need to be shared. We shall see what the outcome of that is. :)

 

We will discuss this on Monday.

 

Thanks Nathan

Take a look also at what Privileged Identity Management can do for you in the scenario described.

@Juan Carlos González Martín Thanks. I will look into that. 

Might be just what my CEO needs to put his mind at ease. :)