Make Your SharePoint Pages Load Faster - Stop Them from Dragging!
Become a Master at SharePoint Permissions With This Video!
If you're working with SharePoint and struggling to manage permissions effectively, you're not alone. Allison Gonzalez, a Microsoft-certified trainer at Pragmatic Works, walks you through the complexities of SharePoint permissions and offers actionable insights on when to use Microsoft 365 groups and SharePoint groups. In this blog post, we'll explore the core strategies for mastering SharePoint permissions, including managing guest access, creating custom permissions, and understanding the nuances of SharePoint and 365 groups.
The Basics: Microsoft 365 Groups vs. SharePoint Groups
Understanding the difference between Microsoft 365 groups and SharePoint groups is key to managing permissions in SharePoint. Here’s what you need to know:
- Microsoft 365 Groups: These are ideal when you need to streamline access across several tools. They automatically control access to email, Teams, Planner, and SharePoint sites. When you create a Team site in SharePoint or Microsoft Teams, it comes with a 365 group that manages permissions across multiple platforms.
- SharePoint Groups: SharePoint groups offer more granular control over permissions, especially for standalone communication sites or when you need specific roles such as reviewers or contributors. These groups are customizable and ideal for tight control over who can do what in SharePoint.
When to Use Which?
- Use Microsoft 365 Groups when you want to give users access to multiple tools (Teams, Outlook, Planner, SharePoint) at once, and need to manage these access levels efficiently.
- Use SharePoint Groups when you need more precise control over permissions, such as allowing users to edit, read, or contribute to content in SharePoint without providing access to other apps like Teams or Outlook.
Setting Up Guest Access
Managing external access is a critical component of SharePoint administration. Allison recommends configuring external sharing settings carefully to ensure sensitive data remains secure. There are several levels of external sharing:
- Anyone: This is the most permissive setting and is usually not recommended for sensitive data.
- Existing Guests: SharePoint users must be registered as guests before accessing your content.
- Only People in Your Organization: The strictest control, ensuring only internal members have access.
SharePoint administrators can control these settings at both the organizational and site level. For sensitive departments like HR or Finance, it’s a best practice to disable guest access completely.
Customizing Permission Levels
One of the most powerful features of SharePoint is the ability to customize permission levels. Here’s how you can set them up:
- Advanced Permissions: In the Site Permissions section, you can access the "Advanced Permissions Settings" to create specific roles with tailored access.
- Permission Levels: You can define granular permission levels for members. For instance, you can allow members to have "Full Control," "Design," "Edit," "Contribute," or "Read" access depending on their role.
- Combining 365 and SharePoint Groups: For even more control, combine 365 groups with custom SharePoint permissions. This approach allows you to manage broader access while fine-tuning roles within SharePoint.
Best Practices for Permission Management
- Create a Guest Access Policy: Establish a policy for guest access and apply it consistently across your sites. Always review your external users regularly to prevent unauthorized access.
- Granular Control: Always opt for custom permission levels when you need precise control over what users can see and do. This helps maintain security while ensuring everyone has the right access to the tools they need.
- Use Site-Level Control: Site administrators can further lock down permissions by restricting external sharing for specific sites. This is especially useful for departments dealing with sensitive information.
Final Thoughts
Managing SharePoint permissions doesn’t have to be overwhelming. By understanding the differences between Microsoft 365 groups and SharePoint groups, setting up guest access carefully, and customizing permissions, you can create a secure and efficient permission strategy for your organization.
As Allison Gonzalez explains, using a combination of 365 groups and SharePoint groups, along with granular permissions, allows SharePoint administrators to finely tune who has access to what, ensuring that users only see what they need to and preventing accidental data leaks or mistakes.
For more tips and in-depth learning, check out Pragmatic Works’ SharePoint Management class available on their on-demand platform. Want to share your permission strategy? Let us know in the comments below!
Sign-up now and get instant access
ABOUT THE AUTHOR
Allison graduated from Flagler College in 2011. She has worked in management and training for tech companies for the past decade. As a Microsoft Certified Trainer, her primary focus is helping our customers learn the ins and outs of Power BI, along with Excel and Teams.
Free Community Plan
On-demand learning
Most Recent
private training

Leave a comment