SharePoint Team Site Permissions #Share4Biz

80
SHARE 2013| 1 Access Denied! How to Successfully Manage Team Site Permissions in SharePoint 2010 Veronique Palmer, Lets Collaborate

description

Presented at Share Conference in Jhb on 12 March 2013. Apologies for uploading the PDf, Slideshare keeps rejecting the Ppt version. I can Dropbox it if required.

Transcript of SharePoint Team Site Permissions #Share4Biz

Page 1: SharePoint Team Site Permissions #Share4Biz

SHARE 2013| 1

Access Denied!

How to Successfully Manage Team Site Permissions in SharePoint 2010

Veronique Palmer, Lets Collaborate

Page 2: SharePoint Team Site Permissions #Share4Biz
Page 3: SharePoint Team Site Permissions #Share4Biz

Getting on the Same Page

Page 4: SharePoint Team Site Permissions #Share4Biz

Intranet Sites Team Sites My Sites

Site Types Extranet Sites Internet Sites

Built on Publishing or Team Site Templates, etc

Page 5: SharePoint Team Site Permissions #Share4Biz
Page 6: SharePoint Team Site Permissions #Share4Biz

2 questions to ask when uploading

content

Page 7: SharePoint Team Site Permissions #Share4Biz

1. Who needs to

see it

Page 8: SharePoint Team Site Permissions #Share4Biz

Everyone Just You Your Team

Team Site My Site Intranet

Who Are We What We Do Contact Us

Shared Operational

Working Docs

Shared Docs Personal Docs

Page 9: SharePoint Team Site Permissions #Share4Biz

2. What must they do with it

Page 10: SharePoint Team Site Permissions #Share4Biz

Default Team Site Permissions

Members Owners Visitors

Page 11: SharePoint Team Site Permissions #Share4Biz

Manage

Edit / Upload / Delete

Read / Download

Site Owners

Site Members

Site Visitors

Page 12: SharePoint Team Site Permissions #Share4Biz

Default Team Site Permissions

Page 13: SharePoint Team Site Permissions #Share4Biz

Super Power Rights

Site Collection Administrators

Page 14: SharePoint Team Site Permissions #Share4Biz

Considerations

Page 15: SharePoint Team Site Permissions #Share4Biz

Build sites first Add users last

Page 16: SharePoint Team Site Permissions #Share4Biz

Content owners Content Creators

Consumers

Naming Standards

Avoid confusion

= Site Owners = Site Members = Site Visitors

Page 17: SharePoint Team Site Permissions #Share4Biz

Add users to groups!

Page 18: SharePoint Team Site Permissions #Share4Biz

Add users to groups!

Page 19: SharePoint Team Site Permissions #Share4Biz

Planning!

Page 20: SharePoint Team Site Permissions #Share4Biz

LC Intranet

Future?

Part time contractors

Full time staff

Accountant

Page 21: SharePoint Team Site Permissions #Share4Biz

Information Architecture …

Page 22: SharePoint Team Site Permissions #Share4Biz

Can’t expect beginners to just

get this!

Page 23: SharePoint Team Site Permissions #Share4Biz

Training!

Beginners

Lists and Libraries

Intermediate

Advanced

START HERE

Site Collection Administrator

Shar

ePo

int

Advanced

Beginners

Lists and Libraries

Intermediate

Site Collection Administrator

Page 24: SharePoint Team Site Permissions #Share4Biz

What Can You Restrict?

Page 25: SharePoint Team Site Permissions #Share4Biz

Site Level (Unique or Inherited Permissions)

Document (Item) Level

List and Library Level

Page 26: SharePoint Team Site Permissions #Share4Biz

Called “Breaking

inheritance”

Page 27: SharePoint Team Site Permissions #Share4Biz

Bad idea on document level!

Page 28: SharePoint Team Site Permissions #Share4Biz

SHAREPoint

remember?

Page 29: SharePoint Team Site Permissions #Share4Biz

Unique vs Inherited Site Permissions

Page 30: SharePoint Team Site Permissions #Share4Biz

Top : HR Site Collection HR Members,

Owners Visitors

Training HR Members,

Owners, Visitors

Performance Performance Members,

Owners, Visitors

Recruitment HR Members,

Owners Visitors

Course Packs Course Packs Members,

Owners, Visitors

Disciplinaries Performance Members,

Owners, Visitors

Internal Only HR Members,

Owners Visitors

Exco Reviews Exco Reviews Members,

Owners, Visitors

CV Management HR Members,

Owners Visitors

What you do on the site below affects the site above, and vice versa!

U = Unique Site

I I

I

I

U

I U

U

I = Inherited Site

Inheritance is broken, what you do here will not

affect the site above it.

Page 31: SharePoint Team Site Permissions #Share4Biz

Everyone

Intranet

Who Are We What We Do Contact Us

Your Team

Team Site

Shared Operational

Working Docs

Inherited Unique

Page 32: SharePoint Team Site Permissions #Share4Biz

“Too many groups with unique sites”

So…?

Page 33: SharePoint Team Site Permissions #Share4Biz

500 million social tags, notes and ratings

30 million documents per library

30 million items in a list

2 million users per service application

1 million alerts on Searches

1 million terms and terms sets

400 000 major versions per document

250 000 site and subsites per site collection

10 000 user groups per site collection

10 000 metadata tags recognised per item when searched

5000 documents or list items displayed per page

5000 blogs per site

5000 groups is how many each user can belong to

5000 users can be in one Active Directory group

2000 site collections per content database

2000 subsites under View All Site Content

1000 comments per blog post

1500 projects deliverables per Project Server plan

1800 documents in a SharePoint Workspace

100 items at a time you can bulk edit

99 people editing Word / PowerPoint simultaneously

25 web parts per page / wiki

2GB per document upload size

SharePoint can handle it!

Can you handle it?

Page 34: SharePoint Team Site Permissions #Share4Biz

ALWAYS click More Options first!

Page 35: SharePoint Team Site Permissions #Share4Biz

The default

setting is to inherit, change!

Page 36: SharePoint Team Site Permissions #Share4Biz

Watch the Visitors group

Page 37: SharePoint Team Site Permissions #Share4Biz

Watch the Visitors group

Page 38: SharePoint Team Site Permissions #Share4Biz

Unique permissions correct

Page 39: SharePoint Team Site Permissions #Share4Biz

Limited Access

Page 40: SharePoint Team Site Permissions #Share4Biz

= Limited Access Chaos

Page 41: SharePoint Team Site Permissions #Share4Biz

Don’t just delete these!

No undo button = Access Denied

Page 42: SharePoint Team Site Permissions #Share4Biz

Document it!

Page 43: SharePoint Team Site Permissions #Share4Biz

Check who or what is unique

Who

What

Page 44: SharePoint Team Site Permissions #Share4Biz

But! Per site only!

Page 45: SharePoint Team Site Permissions #Share4Biz

Custom Groups

Page 46: SharePoint Team Site Permissions #Share4Biz

Where possible, stick to default

groups, but…

Page 47: SharePoint Team Site Permissions #Share4Biz

Tie groups to lists / libraries

Page 48: SharePoint Team Site Permissions #Share4Biz

PS : Delete site – delete custom

groups manually

Page 49: SharePoint Team Site Permissions #Share4Biz

Active Directory vs

SharePoint Groups

Page 50: SharePoint Team Site Permissions #Share4Biz

SharePoint Groups Pros Cons

• Can see the users in the groups

• Site Owners can add and remove users

• Displays sites in your My Sites Memberships list

• Cannot have duplicate group names

• Must delete users manually • Can’t add a group into a

group • Strain on Site Owners

Page 51: SharePoint Team Site Permissions #Share4Biz

Active Directory Groups

Pros

• Groups can be in groups • Easier to add / remove a user to

multiple site collections

Page 52: SharePoint Team Site Permissions #Share4Biz

Active Directory Groups Cons

• Can’t see users in SharePoint

• Dependent on accurate AD • Red tape to update (3rd

party workaround)

• Person / Group metadata Column doesn’t work

• Disempowers users • Strain on AD team

Page 53: SharePoint Team Site Permissions #Share4Biz

SharePoint Groups

Hybrid Approach

AD Groups

Page 54: SharePoint Team Site Permissions #Share4Biz

AD SP

Page 55: SharePoint Team Site Permissions #Share4Biz
Page 56: SharePoint Team Site Permissions #Share4Biz

Governance

Page 57: SharePoint Team Site Permissions #Share4Biz

Control or enablement

Page 58: SharePoint Team Site Permissions #Share4Biz

Who can be Site Owners or SCA’s?

Page 59: SharePoint Team Site Permissions #Share4Biz

Adding NT AUTHORITY\ authenticated

users?

Page 60: SharePoint Team Site Permissions #Share4Biz

Delete Rights

Page 61: SharePoint Team Site Permissions #Share4Biz

Site Permissions

Page 62: SharePoint Team Site Permissions #Share4Biz

Site Members can delete content and versions!

Page 63: SharePoint Team Site Permissions #Share4Biz

Cannot change setting On a subsite level

Page 64: SharePoint Team Site Permissions #Share4Biz

Only on site collection level!

Page 65: SharePoint Team Site Permissions #Share4Biz

Item level permissions

(top of the food chain)

Page 66: SharePoint Team Site Permissions #Share4Biz

Options available when creating a new group or assigning permissions

Page 67: SharePoint Team Site Permissions #Share4Biz

Communicate!!

Page 68: SharePoint Team Site Permissions #Share4Biz

Management Tools

Page 69: SharePoint Team Site Permissions #Share4Biz

Farm level changes? Specific user report?

Specific document report?

etc…

Page 70: SharePoint Team Site Permissions #Share4Biz
Page 71: SharePoint Team Site Permissions #Share4Biz

Key Insights

Page 72: SharePoint Team Site Permissions #Share4Biz

Enemy? Can’t prevent Breed culture Educate Automate

Page 73: SharePoint Team Site Permissions #Share4Biz

Switch off?

Page 74: SharePoint Team Site Permissions #Share4Biz

Planning Training

Governance 3rd Party Tool

Page 75: SharePoint Team Site Permissions #Share4Biz

Ideas to Action

Page 76: SharePoint Team Site Permissions #Share4Biz

Search for “sensitive” content

Review permissions

Clean up

Page 77: SharePoint Team Site Permissions #Share4Biz
Page 78: SharePoint Team Site Permissions #Share4Biz

SharePoint 2010 Permissions for Site Owners – 3 Part Series http://veroniquepalmer.com/2012/03/18/sharepoint-2010-permissions-for-site-owners-part-1-creating-a-team-site/ http://veroniquepalmer.com/2012/03/19/sharepoint-2010-permissions-for-site-owners-part-2-members-owners-and-visitors/ http://veroniquepalmer.com/2012/03/24/sharepoint-2010-permissions-for-site-owners-part-3-creating-a-new-group/ SharePoint Permissions Song for Fun http://veroniquepalmer.com/2010/01/14/sharepoint-permissions-song/ Site Collection Administrator and Farm Administrator Duties http://office.microsoft.com/en-us/sharepoint-server-help/permissions-for-site-collection-administrators-HA101943260.aspx?CTT=1 More Info for Site Collection Administrators http://office.microsoft.com/en-us/sharepoint-server-help/control-user-access-with-permissions-HA101794487.aspx?CTT=5&origin=HA101794118 SharePoint 2010 Groups and Permissions Reference Chart http://office.microsoft.com/en-us/templates/results.aspx?qu=SharePoint&origin=HA101943260&CTT=5#ai:TC101977256| Control Access to a Specific Piece of Content http://office.microsoft.com/en-us/sharepoint-server-help/control-access-for-a-specific-piece-of-content-HA101805400.aspx?CTT=5&origin=HA101794118 Information Rights Management http://office.microsoft.com/en-za/sharepoint-server-help/apply-information-rights-management-to-a-list-or-library-HA101790603.aspx Windows Rights Management Services Download http://www.microsoft.com/en-us/download/details.aspx?id=13781 SharePoint 2013 Permissions http://technet.microsoft.com/en-us/library/cc262939.aspx

Resources

Page 79: SharePoint Team Site Permissions #Share4Biz

Office 365 Permissions Basics http://community.office365.com/en-us/blogs/office_365_technical_blog/archive/2012/05/30/understanding-permissions-in-office-365-the-basics.aspx Working with Permission Levels http://office.microsoft.com/en-us/sharepoint-server-help/edit-create-and-delete-permission-levels-HA101805381.aspx?CTT=5&origin=HA101794118 Choosing a Security Group http://technet.microsoft.com/en-us/library/cc261972.aspx Manage Memberships of SharePoint 2010 Groups http://office.microsoft.com/en-us/sharepoint-server-help/manage-membership-of-security-groups-HA101794106.aspx?CTT=5&origin=HA101794118 Setting Permissions on Views http://www.sharepoint911.com/blogs/laura/Lists/Posts/Post.aspx?ID=76 Allowing Anonymous Users to Comment on Blogs http://www.sharepointedutech.com/2011/01/20/how-to-allow-anonymous-users-to-comment-on-a-sharepoint-2010-blog/ TechNet Explanation of Permission Levels http://technet.microsoft.com/en-us/library/cc721640(v=office.14).aspx Restricting Access for Search Purposes http://office.microsoft.com/en-us/sharepoint-server-help/enable-content-to-be-searchable-HA010379092.aspx SharePoint Security Issues http://community.bamboosolutions.com/blogs/sharepoint-2010/archive/2010/06/09/teched-2010-sharepoint-security-permissions-identities-amp-objects-including-a-gotcha-that-breaks-security-trimming.aspx

Page 80: SharePoint Team Site Permissions #Share4Biz

Veronique Palmer

Lets Collaborate

@veroniquepalmer

[email protected]

Phone +27 11 966 8060