SOLVED

Users see libraries they dont have permissions to

%3CLINGO-SUB%20id%3D%22lingo-sub-1422469%22%20slang%3D%22en-US%22%3EUsers%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1422469%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20site%20with%2010%20document%20libraries%20on%20it%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20each%20library%2C%20I%20broke%20inheritance%20and%20gave%20each%20unique%20permissions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20give%20edit%20permission%20to%20each%20library%20using%20separate%20O365%20Security%20groups.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20a%20user%20is%20in%20only%20one%20O365%20Security%20Group%2C%20then%20they%20only%20have%20permissions%20to%20one%20library%20on%20the%20site.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EProblem%20is%20they%20can%20still%20see%20all%20the%20other%20libraries%20listed%20in%20navigation%2C%20even%20the%20ones%20they%20have%20no%20permissions%20to.%26nbsp%3B%20They%20can%20click%20on%20them%20and%20it%20opens%20up%20the%20library%2C%20but%20its%20empty%2C%20they%20cant%20see%20or%20do%20anything%20in%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20see%20all%2010%20libraries%2C%20but%20they%20only%20have%20access%20to%20one%20of%20them%20and%20since%20they%20don't%20know%20which%20one%2C%20they%20need%20to%20randomly%20open%20libraries%20with%20dead%20ends%20until%20they%20find%20the%20one%20with%20their%20files.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20how%20this%20is%20supposed%20to%20work%3F%26nbsp%3B%20I%20thought%20if%20they%20didn't%20have%20permissions%20to%20a%20library%2C%20the%20library%20will%20be%20hidden.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20check%20that%20particular%20users%20permissions%20on%20a%20libraries%20they%20don%E2%80%99t%20have%20access%20to%2C%20it%20says%20they%20have%20limited%20permissions%20because%20of%20the%20permissions%20I%20gave%20them%20to%20the%20one%20library%20on%20the%20site%20they%20actually%20should%20have%20permissions%20to.%3C%2FP%3E%3CP%3EWhy%20does%20giving%20permission%20to%20one%20library%20somehow%20jump%20to%20another%20library%20that%20it%20has%20no%20connection%20to%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOddly%20enough%20this%20does%20work%20using%20by%20assigning%20permission%20via%20users%20instead%20of%20groups%20-%20If%20I%20take%20a%20user%20out%20of%20their%20particular%20O365%20Security%20group%20and%20add%20that%20user%20just%20as%20a%20user%2C%20then%20it%20works.%20All%20the%20other%20libraries%20are%20hidden.%20But%20who%20wants%20to%20manage%20SharePoint%20libraries%20via%20individual%20users.%20Sounds%20like%20a%20nightmare.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIve%20tried%20adding%20O365%20groups%20to%20the%20Libraries%20and%20Ive%20tried%20using%20SharePoint%20Groups%20populated%20with%20the%20O365%20Groups.%20Same%20result.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20I%20use%20O365%20groups%20and%20keep%20the%20other%20libraries%20hidden%20from%20the%20people%20who%20don%E2%80%99t%20need%20them%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3ETom%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1422469%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDocument%20Library%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPermissions%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1422681%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1422681%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F681714%22%20target%3D%22_blank%22%3E%40IT_Ad10%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20think%20you%20will%20be%20able%20to%20use%20O365%20groups%20to%20achieve%20what%20you%20want%20here.%20%26nbsp%3BI%20find%20the%20most%20effective%20way%20to%20achieve%20what%20you%20are%20trying%20to%20do%20is%20very%20close%20to%20what%20you%20have%20tried%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1).%20Go%20to%20Library%20settings%2C%20permissions%20for%20this%20library.%3C%2FP%3E%3CP%3E2).%20Break%20Inheritance.%3C%2FP%3E%3CP%3E3).%20Create%20new%20SharePoint%20groups.%3C%2FP%3E%3CP%3E4).%20Assign%20individual%20users%20(not%20O365%20groups)%20to%20the%20new%20SharePoint%20groups%20as%20required.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20in%20my%20opinion%20should%20do%20the%20trick.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1423750%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1423750%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F681714%22%20target%3D%22_blank%22%3E%40IT_Ad10%3C%2FA%3E%26nbsp%3B%3A%20Make%20sure%20that%200365%20group%20should%20not%20be%20a%20part%20of%20Site%20collection%20admin.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1424490%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1424490%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%26nbsp%3B%20Thanks%20PeterRising!%26nbsp%3B%20I%20was%20hoping%20for%20a%20different%20answer%2C%20like%20I%20was%20missing%20a%20checkbox%20somewhere.%20But%20confirming%20that%20it%20cant%20be%20done%20means%20I%20can%20move%20on%20at%20least.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1424496%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1424496%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F679665%22%20target%3D%22_blank%22%3E%40Ashish_Kohale%3C%2FA%3EThanks%20Ashish_Kohale%2C%20I%20will%20check%20that.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1426777%22%20slang%3D%22en-US%22%3ERe%3A%20Users%20see%20libraries%20they%20dont%20have%20permissions%20to%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1426777%22%20slang%3D%22en-US%22%3E%3CP%3EI%20figured%20this%20out%2C%20this%20is%20what%20worked%20for%20me.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20added%20a%20library%20and%20broke%20inheritance%20and%20use%20a%20either%20a%20SharePoint%20Group%20or%20a%20O365%20Security%20Group%20to%20give%20permissions%20to%20that%20library%20(actually%20not%20sure%20if%20you%20need%20all%20these%20to%20happen)%20-%20SharePoint%2C%20without%20telling%20me%20add%20that%20group%20to%20other%20libraries%20in%20the%20site%20with%20%22Unique%22%20permissions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESometimes%20it%20added%20this%20group%20to%20all%20the%20other%20libraries%2C%20some%20times%20only%20one%20or%20two%2C%20sometime%20no%20libraries.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20know%20why%2C%20or%20what%20these%20unique%20permissions%20are%20for.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20tell%20which%20libraries%20it%20added%20the%20group%20to%20by%20opening%20the%20site%20with%20a%20user%20who%20only%20has%20permission%20to%20one%20Library.%20If%20you%20can%20see%20any%20other%20libraries%20you%20need%20to%20fix%20those%20libraries.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20I%20saw%20this%20when%20I%20opened%20the%20permissions%20to%20a%20library%20that%20just%20broke%3A%3C%2FP%3E%3CP%3E%22There%20are%20limited%20access%20users%20on%20this%20site.%20users%20may%20have%20limited%20access%20if%20an%20item%20or%20document%20under%20the%20site%20has%20been%20shared%20with%20them.%20%3CFONT%20color%3D%22%233366ff%22%3EShow%20User%3C%2FFONT%3E.%20This%20library%20has%20unique%20permissions%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20saw%20the%20%3CFONT%20color%3D%22%233366ff%22%3EShow%20User%3C%2FFONT%3E%20part%2C%20I%20needed%20to%20fix%20things.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20click%20%3CFONT%20color%3D%22%233366ff%22%3Eshow%20user%3C%2FFONT%3E%20you%20will%20see%20all%20the%20other%20permissions%20added%20by%20SharePoint.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere's%20the%20part%20that%20took%20me%20an%20embarrassing%20two%20days%20to%20figure%20out%20-%20at%20this%20point%20just%20check%20their%20checkboxes%20and%20delete%20all%20groups%20with%20the%20extra%20permission.%20That's%20it.%20I%20got%20so%20hung%20up%20on%20what%20I%20did%20wrong%20for%20them%20to%20show%20up%20there%2C%20that%20it%20never%20occurred%20to%20me%20to%20try%20deleting%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESucks%20you%20need%20to%20do%20this.%20If%20anyone%20know%20why%20this%20happens%20and%20how%20to%20avoid%20it%20I'd%20love%20to%20know.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ETom%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello,

 

I have a site with 10 document libraries on it

 

For each library, I broke inheritance and gave each unique permissions.

 

I give edit permission to each library using separate O365 Security groups.

 

If a user is in only one O365 Security Group, then they only have permissions to one library on the site.

 

Problem is they can still see all the other libraries listed in navigation, even the ones they have no permissions to.  They can click on them and it opens up the library, but its empty, they cant see or do anything in it.

 

They see all 10 libraries, but they only have access to one of them and since they don't know which one, they need to randomly open libraries with dead ends until they find the one with their files.

 

Is this how this is supposed to work?  I thought if they didn't have permissions to a library, the library will be hidden.

 

If I check that particular users permissions on a libraries they don’t have access to, it says they have limited permissions because of the permissions I gave them to the one library on the site they actually should have permissions to.

Why does giving permission to one library somehow jump to another library that it has no connection to?

 

Oddly enough this does work using by assigning permission via users instead of groups - If I take a user out of their particular O365 Security group and add that user just as a user, then it works. All the other libraries are hidden. But who wants to manage SharePoint libraries via individual users. Sounds like a nightmare.

 

Ive tried adding O365 groups to the Libraries and Ive tried using SharePoint Groups populated with the O365 Groups. Same result.

 

How do I use O365 groups and keep the other libraries hidden from the people who don’t need them?

 

Thanks,

Tom

5 Replies

@IT_Ad10 

 

I don't think you will be able to use O365 groups to achieve what you want here.  I find the most effective way to achieve what you are trying to do is very close to what you have tried;

 

1). Go to Library settings, permissions for this library.

2). Break Inheritance.

3). Create new SharePoint groups.

4). Assign individual users (not O365 groups) to the new SharePoint groups as required.

 

That in my opinion should do the trick.

@IT_Ad10 : Make sure that 0365 group should not be a part of Site collection admin.

 

@PeterRising   Thanks PeterRising!  I was hoping for a different answer, like I was missing a checkbox somewhere. But confirming that it cant be done means I can move on at least.

@Ashish_KohaleThanks Ashish_Kohale, I will check that.

best response confirmed by IT_Ad10 (New Contributor)
Solution

I figured this out, this is what worked for me.

 

When I added a library and broke inheritance and use a either a SharePoint Group or a O365 Security Group to give permissions to that library (actually not sure if you need all these to happen) - SharePoint, without telling me add that group to other libraries in the site with "Unique" permissions.

 

Sometimes it added this group to all the other libraries, some times only one or two, sometime no libraries.

 

I don't know why, or what these unique permissions are for.

 

I can tell which libraries it added the group to by opening the site with a user who only has permission to one Library. If you can see any other libraries you need to fix those libraries.

 

And I saw this when I opened the permissions to a library that just broke:

"There are limited access users on this site. users may have limited access if an item or document under the site has been shared with them. Show User. This library has unique permissions

 

If I saw the Show User part, I needed to fix things.

 

If you click show user you will see all the other permissions added by SharePoint.

 

Here's the part that took me an embarrassing two days to figure out - at this point just check their checkboxes and delete all groups with the extra permission. That's it. I got so hung up on what I did wrong for them to show up there, that it never occurred to me to try deleting them.

 

Sucks you need to do this. If anyone know why this happens and how to avoid it I'd love to know.


Tom