SharePoint 2010 Permissions Keith Tuomi. profile KEITH TUOMI SharePoint Consultant / Developer at itgroove Developing Online Systems since 1991 10 years.

Slides:



Advertisements
Similar presentations
JERRY GILES MNIS Unclassified Information Sharing Service PAUL HILTON.
Advertisements

Kentico CMS 5.5 R2 What’s New. Highlights Intranet Solution Document management package – WebDAV support – Project & task management – Document libraries.
Implementing enterprise governance can sometimes feel like trying to corral an exuberant crowd.
1 Chapter Overview Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions.
Agenda Who is Secured What is Secured Logic and the Effective Permissions Guidelines and Best Practices.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
1 of 6 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
1 of 6 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Hands-On Microsoft Windows Server 2003 Administration Chapter 5 Administering File Resources.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW  Create and manage file system shares and work.
1 of 7 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Agenda 22 7.SharePoint Changes 8.Items & Lists 9.Files & Libraries 10.SharePoint & Office 11.Help 12.Wrap Up.
5.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 5: Working with File Systems.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
1 of 5 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2006 Microsoft Corporation.
1 Securing Network Resources Understanding NTFS Permissions Assigning NTFS Permissions Assigning Special Permissions Copying and Moving Files and Folders.
EBO Overview Part 1 Ingrid Bongers MT(ASCP) MBA eClinicalWorks Certified Trainer.
Definitions Collaboration – working together on team projects and sharing information, often through ad-hoc processes, to accomplish project goals. Document.
Mark Kashman Senior Product Manager –
Welcome to the Minnesota SharePoint User Group. Quick Intro Announcements Personalization in SharePoint Configuring User Profiles Configuring Audiences.
11 SHARING FILE SYSTEM RESOURCES Chapter 9. Chapter 9: SHARING FILE SYSTEM RESOURCES2 CHAPTER OVERVIEW Create and manage file system shares and work with.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
SMART Agency Tipsheet Staff List This document focuses on setting up and maintaining program staff. Total Pages: 14 Staff Profile Staff Address Staff Assignment.
Managing, Organizing and Finding Files, Information, Shared Folders and Offline Folders powered by dj.
IOS110 Introduction to Operating Systems using Windows Session 8 1.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
Chapter 9: SHARING FILE SYSTEM RESOURCES1 CHAPTER OVERVIEW  Create and manage file system shares and work with share permissions.  Use NTFS file system.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Module 6 Securing Content. Module Overview Administering SharePoint Groups Implementing SharePoint Roles and Role Assignments Securing and Auditing SharePoint.
Getting Started Managing a Collaboration Site Kendra Holly SharePoint Analyst June 13, 2015.
Roles 1. Your Role: End User End Users use Inside NCDOT and Connect NCDOT for basic browsing and reading Typical tasks can include: Open or download files.
What is Web Site Administration Tool ? WAT Allow you to Configure Web Site With Simple Interface –Manage Users –Manage Roles –Manage Access Rules.
Module 3: Configuring File Access and Printers on Windows 7 Clients
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 11: Managing Access to File System Resources.
Windows SharePoint Services Managing users and rights.
Team Site Admin with SharePoint 2010 Gareth Johns IT Skills Development Advisor.
Information explosion 1.4X 44X Empower the UserEnable the Compliance Officer In Place and Extensible Easy for IT Exchange, SharePoint, Windows Outlook,
MEMBERSHIP AND IDENTITY Active server pages (ASP.NET) 1 Chapter-4.
Inventory & Monitoring Program SharePoint Permissions Who has access? What can they do with the access? What is the easiest way to manage the permissions?
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Copyright © 2006 Pilothouse Consulting Inc. All rights reserved. Security Overview Functional security – users, groups, and permissions for sites, lists,
Guide to MCSE , Second Edition, Enhanced 1 Managing NTFS Permissions NTFS Only file system supported by Windows XP that offers file- level security.
Lecture 6 File, Folder and Share Security. Objectives Managing file and folder security.
1 © Xchanging 2010 no part of this document may be circulated, quoted or reproduced without prior written approval of Xchanging. MOSS Training – UI customization.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
Copyright © 2007, Oracle. All rights reserved. Using Document Management and Collaboration Appendix B.
JERRY GILES MNIS Unclassified Information Sharing Service PAUL HILTON.
Microsoft Virtual Academy Chris Oakman | Managing Partner Infrastructure Team | Eastridge Technology Curtis Sawin | Technical Solutions Professional |
HR Development Division PA Office of Administration Room 511 Finance Building Harrisburg PA Enterprise Portal Community Management Overview Click.
Windows Vista Configuration MCTS : NTFS Security Features and File Sharing.
11 SUPPORTING WINDOWS XP FILE AND FOLDER ACCESS Chapter 5.
Transportation Agenda 19. Transportation Your Role: Designer Designers organize SharePoint content and determine how to display that content Typical tasks.
Permission Management in SharePoint – Overview and best practices Toni Frankola Co-Founder & CEO, Acceleratio Ltd., Croatia.
SharePoint 101 – An Overview of SharePoint 2010, 2013 and Office 365
Stop Those Prying Eyes Getting to Your Data
APAN SharePoint Permissions
About SharePoint Server 2007 My Sites
APAN SharePoint Permissions
What Is Sharepoint? Mohsen Ashkboos
Team Site Admin with SharePoint 2010
Manage your Interest Group
SysKit Security Manager
SharePoint 2010 – SharePoint 101
SharePoint Foundation 2010
INSTRUCTOR NOTES/LINKS
Links Launch Outlook Launch Skype Place Skype on Do Not Disturb.
SysKit Security Manager
Presentation transcript:

SharePoint 2010 Permissions Keith Tuomi

profile KEITH TUOMI SharePoint Consultant / Developer at itgroove Developing Online Systems since years as dedicated.NET/Microsoft Developer 110% SharePoint focused for 7 months, with no looking back Blog TwitterWeb

- Permissions - single units of access that represent specific tasks that can be performed at the list, site, or personalization level - permission levels are made up of sets of permissions - SharePoint ships with a core list of permissions that cannot be edited, added to or deleted - Users - smallest value to which access can be granted - value corresponds to an account in Active Directory or another host application for user accounts - Groups - a set of users who will have identical access needs - Securable objects - levels within SharePoint 2010 that can be “ locked down,” or secured, by setting specific user access - Inheritance - used to describe how user access is created by default within SharePoint - Security Trimming & Indexing - SharePoint will only show you search results for content you have access to, and for which SharePoint understands the security - Audiences - Used to target content to specific sets of users - Defined in the User Profile Service Application in Central Admin - NOT a security setting but simply a way to display pertinent content to specific users Access Management Terminology

Topology Web Application

- Permission Levels are collections of permissions - level of access that users with the assigned permission have is based on the permissions that make up the permission level. - Defined at the site collection - Managed by Site Collection Administrators - Customize an existing permission level - Copy an existing permissions level and edit the copy - Create a new permission level “ from scratch” Permission Levels

Default Permission Collection Permission LevelDescription Full Control -Contains all permissions. -Assigned to the Owners SharePoint group, by default - cannot be customized or deleted. Design - Can create lists and document libraries, edit pages and apply themes, borders, and style - Not assigned to any SharePoint group, by default. Contribute - Can add, edit, and delete items in existing lists and document libraries. - Assigned to the Members SharePoint group, by default. Read - Read-only access to the Web site - Assigned to the Visitors SharePoint group, by default. Limited Access - Designed to be combined with fine-grained permissions to give users access to a specific list, document library, item, or document, without giving them access to the entire site. - To access a list or library a user must have permission to open the parent Web site and read shared data such as the theme and navigation bars of the Web site. - Cannot be customized or deleted. - You cannot assign this permission level to users or SharePoint groups, instead, SharePoint automatically assigns this permission level to users and SharePoint groups when you grant them access to an object on your site that requires that they have access to a higher level object on which they do not have permissions. F or example, if you grant users access to an item in a list and they do not have access to the list itself, SharePoint automatically grants them Limited Access on the list, and also the site, if needed.

- Central Administration > Manage Web Applications - Configures policy-based access to all content in a web application - Allow and Deny - Deny overrides any allow permissions - SharePoint 2010 allows you to define policies for any available permission Web Application Policy

- Site Actions > Site Permissions - Groups are established at the site collection - Can be given permissions at the site level - Permission inherits down from there - When you create a group you do not have to assign a permission - A group without a permission at the site can still be assigned permissions to another securable object - Create a sub-site - Unique or Inherited Permissions Site Security

- Owners: Full Control - Visitors: Read - Members: Contribute - Features add more groups (Designers, etc.) - The Members group is the “ default members groups” Default Groups

- Enable hierarchical membership management - Create a group named Site Managers > owned by site collection administrators > membership managed by owner (site collection administrators) - Site members (and other groups) > Owned by Site managers > Membership managed by owner (Site Managers) - Enable Access Requests - Add link to request page for the group - Optionally enable auto-accept of access requests - Control Member Visibility SharePoint Groups

- Active Directory - Technical user interface (AD Users & Computers) - No provisioning (requests, workflows) - Difficult delegation of membership management - Centralized security (group membership) management - SharePoint - Non-technical user interface - Easy delegation of group membership management - Optional provisioning of membership requests - Unified view of SharePoint groups & users - Only applies to SharePoint Group Management Comparison

- Assigning permissions directly to AD groups - Possible but not recommended > Assumes that content will always be hosted in a web application using AD as its authentication provider - Nest Active Directory groups in SharePoint groups - Add to a SharePoint group and give permissions (recommended) > user > Active Directory group > SharePoint group - Must be a security group (not a distribution group) > Distribution groups are expanded and then must be kept in sync - Distribution groups can be used to create audiences Using Active Directory Groups

Users > Active Directory Group > SharePoint group - Ideal world: Synchronization of membership between Active Directory and SharePoint groups -“ Intranet” sites: AD groups  SP groups to define access - Add site to users ’ My Sites with personalization site links - Support easy management of access - Add site to users ’ My Sites with personalization site links - “ Collab” sites: Add users directly to SP groups - Provide My Site visibility - Provide visibility of user in user information list - Provide visibility to site owners and members - Support collaboration To Nest or Not to Nest

- List > List Settings / Library > Library Settings - Stop Inheriting Permissions - Copies inherited permissions as initial explicit permissions - Can reset with Inherit Permissions button - Ribbon Actions for Selected Group(s)/user(s) - Grant Permissions - Remove User (or group) Permissions - Edit User (or group) Permissions - Check permissions: Resultant set of permissions - Anonymous Access List & Library Permissions

Items & Documents will be referred to in this presentation as “ Items” unless specific difference needs to be highlighted - Change permissions on a folder or item - Item > Arrow > Manage Permissions - When viewing the item properties in SharePoint > Edit Permissions Folder & Item/Document Security

- Permissions (role assignments) are inherited from the parent object - Inheritance can be broken - All permissions are explicit - Any changes to parent do not affect the child object - Inheritance can be reinstated - All customizations (explicit permissions) are lost - Use inheritance wherever possible - Simplicity, coherence, maintainability Inheritance

- SharePoint access is based on a per URI (web address) basis - The permission to the URI is all that matters - These kids are wild: no need to ask the parents permission - No equivalent to NTFS (Windows folder security) Traverse Folder permission - Explicit Inherited - One or the other - Different than NTFS (inherited + explicit) - Check Effective Permissions button - Shows you the actual effective permission level Effective Permissions

- The SharePoint interface and search results are security-trimmed - User don ’ t see what they do not have permission to read - Item-level permissions on pages in a Page Library - Problem: A Web Part displays items > Users don ’ t see items they don ’ t have access to > The crawler sees all items in the web part and indexes them - When inheritance is stopped within a site, all Web Part content on ASPX pages is not indexed by default - Site Settings > Search and Offline Availability > Indexing ASPX Page Content Security Trimming & Indexing

Permission Levels Publishing Feature Collection - Available only with Publishing Features turned on Publishing Feature Manage Hierarchy Restricted Read Approve

- Columns can not be secured uniquely (out of the box) - Performance - Conditional formatting - Related Lists - Third party solutions - Audiences - Make content visible to users - Effect can be close to security, but it is not security SharePoint Security Notes

- In-place records management - New in SharePoint Record library still supported for dedicated record libraries - Enable the feature at the site collection level - Declare records management attributes - Site Collection - F older - Content type - Supports security at the document level without permissions - Information rights policies - Relies on Active Directory Rights Management Services Information Management Policies

- Remember: limited access is for SharePoint to manage unique permissions. It neither means someone is limited to access something, nor does it mean they have limited access to something. Ignore it - Permissions can be defined at creation of a site (more options) but can ’ t be during creation of a new list or library (in the GUI at least) - When in doubt, check effective permissions - Help your users, set a valid account for ‘ manage access requests ’ - Finally, build sites based on a ‘ team ’ of people. Setting individual permissions shouldn ’ t be something you do all the time, it should be in the ‘ odd times needed ’ not the goto action Conclusion