permissions
2086 TopicsStrengthening Security in SharePoint Document Libraries: 5 Essential Best Practices
SharePoint Online has become a critical platform for storing, managing, and collaborating on documents across Microsoft 365 environments. Its flexibility and ease of access make it invaluable to modern organisations. However, if document libraries are not properly managed, businesses can face risks such as unauthorised access, accidental sharing of sensitive data, and compliance challenges. Effective SharePoint security is not about restricting productivity. It is about creating a secure framework that allows teams to collaborate confidently while ensuring business information remains protected. This article was written by https://www.bridgeall.com/a leading https://www.bridgeall.com/microsoft-365-consultancy/sharepoint/offering https://www.bridgeall.com/microsoft-365-consultancy/sharepoint/sharepoint-document-management-systems-implementation/ Five Ways to Improve SharePoint Document Library Security Limit Access Using Role-Based Permissions One of the most effective ways to secure SharePoint is by restricting access to only those who genuinely need it. Many organisations grant broad permissions across sites, creating unnecessary exposure. Following a least-access approach ensures users receive only the permissions required for their responsibilities. Rather than assigning permissions to individual files and folders, consider using Microsoft 365 Groups or SharePoint Security Groups to manage access centrally. This not only improves governance but also makes ongoing administration significantly easier. Review and Restrict External Sharing External collaboration is often necessary, but it can also become a source of data leakage if not controlled appropriately. Review sharing settings at both the tenant and site level to ensure they align with your organisation's security requirements. Good practices include: Preventing anonymous sharing links for libraries containing confidential information. Allowing access only to verified external users where appropriate. Applying expiry dates to shared links so access is automatically revoked after a defined period. Regularly auditing active external sharing relationships. By tightening these controls, organisations can reduce the likelihood of sensitive information being exposed outside the business. Protect Content with Sensitivity Labels Protecting the library itself is important, but protecting the documents within it adds another layer of security. Microsoft Purview Sensitivity Labels enable organisations to categorise content according to its sensitivity and automatically apply protection measures. Depending on the classification, labels can: Encrypt files. Restrict downloading, printing, or copying. Display visual markings such as headers, footers, or watermarks. Maintain protection even when a document is shared or moved outside SharePoint. This approach helps ensure security travels with the information rather than relying solely on where it is stored. Strengthen User Authentication Document-level security should always be backed by strong identity protection measures. Multi-Factor Authentication (MFA) remains one of the most effective ways to prevent unauthorised access resulting from compromised credentials. Combining MFA with Microsoft Entra Conditional Access policies provides even stronger protection. For example, organisations can: Block access from unmanaged devices. Restrict downloads on non-compliant endpoints. Trigger additional verification requirements for sign-ins from unfamiliar locations. Apply risk-based access controls based on user behaviour. These safeguards help ensure only trusted users and devices can access critical information. Continuously Monitor and Review Access Security is not a one-off project. Permissions and risks evolve over time, making ongoing monitoring essential. Microsoft Purview auditing capabilities provide visibility into activities such as file sharing, downloads, edits, deletions, and permission changes. Regular access reviews help identify: Outdated permissions. Dormant guest accounts. Excessive access rights. Unnecessary group memberships. Routine governance reviews help maintain a secure SharePoint environment and reduce the risk of privilege creep. Building a Secure and Collaborative SharePoint Environment A well-secured SharePoint platform should balance protection with usability. Organisations that invest in strong governance, identity controls, information protection, and ongoing monitoring are better positioned to support collaboration without compromising sensitive business data. By implementing these best practices, businesses can significantly reduce security risks while ensuring employees continue to work efficiently within Microsoft 365. At Bridgeall we offer a range of https://www.bridgeall.com/microsoft-365-consultancy/sharepoint/sharepoint-document-management-systems-implementation/ that help you build and maintain a secure platform of SharePoint document librarires.40Views0likes0CommentsSharePoint Permissions Management
Over the last 3 years of managing permissions across a suite of sites, I have uncovered more new issues with the way SharePoint permissioning is designed at every turn. A few examples, before the question: If I "Share" a file or folder somewhere on the site (breaking permissions inheritance), it is very inconvenient to find it again. If I "copy link" in this one particular way, permissions inheritance is broken. When looking at site-level permissions, I see site-level permissions groups, but there could be hundreds of other users who have been added to my site(s) without my knowing. If I want to reset permissions in an area (set of folders or library), I have to do it file-by-file or folder-by folder. If I want to get an excel snapshot of - anything really - IT has to pull it and it takes a couple days. Not to mention the permissions interface is incredibly clunky. All-in-all, there seem to be a million ways to break permissions inheritance, creating an access tracking and security nightmare. AND there's no easy way to truly see and understand who has access to what or what is broken, without spending hours with IT to pull a bunch of narrow-visibility reports. So my question is: what is the best way to navigate full permissions visibility? Am I doing something wrong? Is anyone else experiencing these issues? We have resorted to having a very strict "no outsides besides a few exceptions" policy and only managing permissions at the site-level, which really hampers on the collaboration benefits that SharePoint is trying to enable. It is also very administratively intensive. One of the benefits to SharePoint is that users don't really need to understand how it works to use it, but that's becoming less and less true with the increasing lack of security we feel in the platform.418Views3likes4CommentsSharePoint security broken between Microsoft 365 group and SharePoint group
Hi, Users are giving Member privilege through Teams, which gave them Member privilege in the Member SharePoint group. All good for 99% of the company. PROBLEM : I have 4 users without access to the SharePoint by this method. Security is not broken between Microsoft 365 Group and SharePoint group and is working fine for everybody else. Strangely, I saw that these 4 users are members of more than 1500+ Microsoft 365 Group, since they have been in the business for a long time and touch many projects here). I heard the limit is 7000 but they still have problem. Using the "Check permission", I got "None" for these people, but "Edit - Given through the XYZ Member group" for every other people in the Microsoft 365 Group. Any advice ? Thanks ! Patriccote207Views1like4CommentsUsers unable to determine who has access to document library due to security groups
Greetings, Maybe I went about this the wrong way. Looking for advice on either the proper way we should be moving forward on this or any other comments or insight we should be considering. This is for SharePoint online via Microsoft 365 Business license. Scenario: 1. SharePoint Document Library per department (Each Document Library exists in its own SharePoint site), essentially being used as a company drive. 2. Some users should only officially have access to specific folders in some of the document library. 3. If say a person in accounting has access to some specific folders, and either they are replaced or a new accounting user comes in.... should be able to reference the access the existing person has in order to give the same access to the new user. 4. Common Request: Give UserB the same folder access as UserA. 5. Some users should have access to the entire document libraries while other users only have access to specific subfolders. Current Implementation: 1. In Entra, created Security Groups that tied to specific folders. -- For Example for the accounting folder, only management has access to the entire folder but the accounting staff only have access to specific folders. So like there is a FiscalYear2024 folder, so I created a security group called sec-Accounting-FiscalYear2024 and assigned the members that should only have access to that folder and not the rest of the library. -- My thought behind this was if a new user was replacing the existing user or joining the department, I can just reference the existing user security group membership and copy it to the new user. 2. In the SharePoint document Library, I create a shareLink that is assigned to the security group I made for that access. Then I give that link to the users I assigned the membership to. Current Issue: 1. Aside from the official document sharing/access that is being done from the security groups above. There are occasions where users of a sharepoint need to share specific files or folders to other users. 2. However, they are all panicking and confused because aside from themselves they are unsure who has access to the existing folders/files in the document library. 3. When going to manage permissions of a file/folder, it only shows the group assigned to it but not the members of the group. 4. So since users can't see the members of the group assigned to a folder, they have no idea who has access to that folder and are getting confused. If this was an NTFS drive, it would be super easy for users to see who has access and etc by looking at the properties but I'm stuck behind some limitations of sharepoint I didn't realize existed until I tried to implement certain workflows. Any advice here would be greatly appreciated, as my implementation has turned into a point of frustration for end users. Thank you in advance!331Views1like4CommentsExternal Users Unable to Access Microsoft List Form
We have created a Microsoft List and are using the default Microsoft Lists Form for data entry / intake form. Internal users can access the form URL and submit items successfully. However, external users are unable to access the form link, even though they have been granted Contribute permissions to the SharePoint list. External users can: Access the list Create new items using the + New button Edit items based on their permissions However, they cannot access the dedicated Microsoft Lists Form URL and getting following error. This link is only available to internal users. This link is not available to you. Our requirement is to allow external users to: Open the Microsoft Lists Form URL View the form Submit new items without providing additional access beyond what is required for form submission, and without using Microsoft Forms. Is guest/external user access to the Microsoft Lists Form experience supported? If so, what configuration or permissions are required to enable external users to access and submit items through the form URL?Solved278Views0likes3CommentsDynamic Mandatory Fields
In a SharePoint library, I have folders which are = a. Admin b. Events c. Furniture and Moves d. Janitorial and Maintenance e. Parking and Transportation f. Shipping and Receiving g. Supplies and Equipment h. Waste and Recycling I have Meta data across the library whose data type are all choices and are: a. Document Type = Contract, Financial, planning b. Building = Gym, Garage, Heating c. Asset Category = Office, Playground d. Fiscal Year = FY23, FY24, FY25, FY26, FY27 e. Vendor = Maple Leaf, Canadian Tire, Home Depot f. Status = Active, Pending, Not Active g. Retention Label = 3 years, 5 years h. Service Type = Admin, Events, Furniture and Moves, Janitorial and Maintenance, Parking and Transportation, Shipping and Receiving, Supplies and Equipment, Waste and Recycling Service Type and Retention Label are mandatory fields, with the Rule below for all the files in the various folders: IF Folder Name = Admin, then Service Type = Admin and Retention Label = 5 years; the mandatory fields should be Document Type, Status and Fiscal Year IF Folder Name = Events, then Service Type = Events and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Fiscal Year, Building and Vendor IF Folder Name = Furniture and Moves, then Service Type = Furniture and Moves and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Building IF Folder Name = Janitorial and Maintenance, then Service Type = Janitorial and Maintenance and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Fiscal Year IF Folder Name = Parking and Transportation, then Service Type = Parking and Transportation and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Fiscal Year IF Folder Name = Shipping and Receiving, then Service Type = Shipping and Receiving and Retention Label = 3 years; the mandatory fields should be Document Type, Status IF Folder Name = Supplies and Equipment, then Service Type = Supplies and Equipment and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Fiscal Year IF Folder Name = Waste and Recycling, then Service Type = Waste and Recycling and Retention Label = 3 years; the mandatory fields should be Document Type, Status and Vendor I have used Column Default Value Settings for SharePoint to display Auto-Display the Service Type and Retention Label, but I cannot seem to perform the conditional mandatory fields using Validations setting for the other requirements. Please help184Views0likes1CommentHow to map permission of Dynamics 365 to SharePoint Online ?
How to replicate permission from Dynamics 365 to SharePoint Online ? Is there any out of box approach/custom solution like Power Automate/Azure Functions available to meet this requirement ? And, what kind of limitations may occur in longer run when data grows?162Views0likes1CommentRecycle Bin and Site Content Hidden for Site Members and Site Visitors
I have a requirement that the Recycle bin and Site Contents should not be be hidden from the Site Members and Site Visitors. Please how can I achieve this because the Server Infrastructure activation is not working for me. Any workarounds? Please help191Views0likes2CommentsRecycle Bin and Site Content Hidden for Site Members and Site Visitors
I posted this before but made a mistake with my write up, so I am reposting. I have a requirement that the Recycle bin and Site Contents should be be hidden from the Site Members and Site Visitors. Please how can I achieve this because the Server Infrastructure activation is not working for me. Any workarounds? Please help74Views0likes0CommentsAccessing External Sharepoint Site
I am able to access internal Sharepoints within my company and have up until now been able to access Sharepoints outside the company. When I now try to access an external Sharepoint, I get the following message on the external company's landing page. "Your account has been locked. Contact your support person to unlock it, then try again...." The external company states they have not made changes any access protocols. Likewise, my company says nothing has changed with respect to the rules/ability to access external Sharepoints. Someone indicated that the Microsoft “federation” settings/setup of the two companies may (now) be incompatible. Has anyone encountered this issue?93Views0likes1Comment