SOLVED

Why have group owners full control in the SharePoint teamsite

Brass Contributor

Lets say I create a new Microsoft Team called "MyTest". Now a SharePoint team site will be created in the background with three SharePoint security groups:

 

MyTest Visitors (empty)

MyTest Members (contains an item with the name "MyTest Members")

MyTest Owners (empty)

 

Now I have two questions about this:

 

1. The mysterical "MyTest Members" item inside the "MyTest Members"-SharePoint group is the "Members" part of the Microsoft 365 group? Can I understand it like this?

 

2. If my first assumption is correct, why is there not an "Owners-Part" of the same Microsoft 365 group that is either:

 

- A site collection admin

- Part of the "My Test Owners"-SharePoint group"?

 

The owners are not mentioned anywhere in the permissions. That appears strange to me, because they seem to have the "Full control"-Permission level somehow?

 

Can you shed some light on that?

 

 

7 Replies
best response confirmed by David_Elsner (Brass Contributor)
Solution

Hi @David_Elsner - I just checked a couple of SharePoint site collections tied to Teams.  In both cases, there is a "Group Members" listed in the SharePoint members group and a "Group Owners" listed in the Site Collection Administrators.  However, the SharePoint Owners group is empty.

 

Do you see a "MyTest Owners" in the Site Collection Administrators?

Who ever creates a SharePoint site automatically becomes the site collection administrator for the site and as a site collection administrator you have full control on the site.
The owner permission Level allows you to add new users or groups as owners to the site .

If you check the permission on the site level you will see everyone that has permission to the site.
Click on any of the groups and change the last digits on the URL to 0 and enter.
This will give you a display of all user's permissions
Your first assumption is correct and for the second question part, the "MyTest Owners" group gets added to Site collection administrators in SPO site permissions and that's how the owners have Full Control permissions on the site.
With M365/O365 group, there are only two modes, Owners and Members and the group membership is maintained via these two modes. With Owners having full control of the group membership and resources (Calendar, SharePoint, Planner, Team etc) and Members having Contribute/Edit rights to all the resources.
Since the SPO site gets created as part of O365 group creation process, the Membership from O365 group gets populated to SPO site. Owners -> Site Collection Administrator and Members -> SPO "MyTest Members" group.
- Since there is no visitors mode in O365 group, nothing gets added to SPO "MyTest Visitors" group.
As to the reason as to why "MyTest Owners" SPO group is empty, it's because O365 "MyTest Owners" group is already added to Site collection administrator so no point in duplicating that same action.

You can always add additional users, AD groups to any of these SPO groups , however, they will only have access to SPO site and not to any other resources in the O365 group, so it's always a good idea to manage the group membership via O365 group so that it percolates to all the resources in the O365 group. I hope this information helps.
https://docs.microsoft.com/en-us/microsoft-365/admin/create-groups/office-365-groups?view=o365-world...
Exactly here is my point. If I go to the site collection administrators, I do not see the Microsoft365 group there. The owners list is just empty... however - this might be, because I look there with the classical experience. Maybe that is not up-to-date...

Hi @David_Elsner - what you're seeing isn't the same that I see.  My Site Collection Administrators has the Microsoft 365 Group in it (name group + " Owners").

In the modern admin center I see the same. I was looking in the classical experience. This was my mistake. I think my question is answered... 🙂

The group owners are added as hidden principal MS Learn M365 Group 

1 best response

Accepted Solutions
best response confirmed by David_Elsner (Brass Contributor)
Solution

Hi @David_Elsner - I just checked a couple of SharePoint site collections tied to Teams.  In both cases, there is a "Group Members" listed in the SharePoint members group and a "Group Owners" listed in the Site Collection Administrators.  However, the SharePoint Owners group is empty.

 

Do you see a "MyTest Owners" in the Site Collection Administrators?

View solution in original post