#SPSSAN June 30, 2012 San Diego Convention Center BEST PRACTICES FOR MANAGING SHAREPOINT PERMISSION LEVELS SharePoint 2010 Tony Rockwell.

Slides:



Advertisements
Similar presentations
From the eyes of an Administrator A general overview of e-CFunds Administrative Site, including navigation and exploring the features of this powerful.
Advertisements

SharePoint 2013 Community Sites The Discussion Boards Extreme Makeover Marlene Lanphier Senior SharePoint Solutions Designer.
Philadelphia Area SharePoint User Group January 30, 2013 Chris Mann RJB Technical Consulting
JERRY GILES MNIS Unclassified Information Sharing Service PAUL HILTON.
Eric J. Oszakiewski MCTS: SharePoint Application Development SharePoint Configuration.
SP Business Suite Deployment Kick-off
Kentico CMS 5.5 R2 What’s New. Highlights Intranet Solution Document management package – WebDAV support – Project & task management – Document libraries.
SESSION TWO SECURITY AND GROUP PERMISSIONS Security and Group Permissions.
SharePoint 2010 Permissions Keith Tuomi. profile KEITH TUOMI SharePoint Consultant / Developer at itgroove Developing Online Systems since years.
1 of 6 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
1 of 4 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
1 of 5 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2006 Microsoft Corporation.
1 of 4 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
OFFICE 365 GROUPS Administrative look into Groups July 9, 2015.
December 1 st, SharePoint Lifecycle management With Project Server 2010.
Web FOCUS Integration with Microsoft Office SharePoint By: Kelvin Ruiz NASA – Kennedy Space Center.
My Site Collaborative Features. About Me Support Team Leader with Webteksolutions Primary.
Working with SharePoint Document Libraries. What are document libraries? Document libraries are collections of files that you can share with team members.
Sharepoint Portal Server Basics. Introduction Sharepoint server belongs to Microsoft family of servers Integrated suite of server capabilities Hosted.
INCOSE.ORG MIGRATION SharePoint 2013 Presented by Betty Morimoto.
Welcome to the Minnesota SharePoint User Group. Introductions / Overview Project Tracking / Management / Collaboration via SharePoint Multiple Audiences.
Wes Preston Agenda  Quick Intro  Overview  Site Details  Notes and Resources  Questions.
San Diego 2014 SharePoint Saturday San Diego November 15, 2014 UCSD Extension SharePoint Saturday San Diego November 15, 2014 UCSD Extension.
San Diego 2014 SharePoint Saturday San Diego November 15, 2014 UCSD Extension SharePoint Saturday San Diego November 15, 2014 UCSD Extension.
#SPSSAN June 30, 2012 San Diego Convention Center SHAREPOINT WORKSPACE Don
#SPSSAN June 30, 2012 San Diego Convention Center ENTERPRISE COLLABORATION AND THE CLOUD How to integrate cloud-based SharePoint into enterprise collaboration.
Helpful Practices Using SharePoint to Manage SharePoint.
San Diego 2014 SharePoint Saturday San Diego November 15, 2014 UCSD Extension SharePoint Saturday San Diego November 15, 2014 UCSD Extension.
SALESFORCE.COM SALESFORCE.COM
1 Getting Acquainted with SharePoint at Computershare in Shelton Carey Bates and Joan Thomas InfoDev, Shelton December 2005.
Introduction to eChalk For Students. What is eChalk? eChalk’s unique online learning environment provides your school with its own electronic “town square”
#SPSSAN June 30, 2012 San Diego Convention Center 10 FREE TOOLS YOU SHOULD HAVE IN YOUR SHAREPOINT TOOLBOX.
Welcome to the Delaware Valley SharePoint User Group Russ Basiura SharePoint Consultant RJB Technical Consulting
Using Content Types to Improve Discoverability IA260 Gary Lapointe, MOSS MVP.
Module 6 Securing Content. Module Overview Administering SharePoint Groups Implementing SharePoint Roles and Role Assignments Securing and Auditing SharePoint.
Using the Right Method to Collect Information IW233 Amanda Murphy.
Getting Started Managing a Collaboration Site Kendra Holly SharePoint Analyst June 13, 2015.
Managing Site and List Security Module 6. Overview  Understanding Security  Adding Users to Sites  Creating Custom SharePoint Groups  Creating Custom.
Efficient Admin with SharePoint 2010 Gareth Johns IT Skills Development Advisor 1.
Team Site Admin with SharePoint 2010 Gareth Johns IT Skills Development Advisor.
Inventory & Monitoring Program SharePoint Permissions Who has access? What can they do with the access? What is the easiest way to manage the permissions?
Copyright © 2006 Pilothouse Consulting Inc. All rights reserved. Security Overview Functional security – users, groups, and permissions for sites, lists,
Welcome to Minnesota’s eFolio St. Cloud Technical College June 2, 2003 Norman Baer Matt St. Martin.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
Token TOKEN User Groups Roles Claims Authentication Provider Identities STSUser Authentication Method UserGroup Role Assignment Permission Level FD.
Reduce, Reuse, Recycle. Housekeeping… Download EventBoard Mobile and remember to fill out session evaluations… Phasers set to stun, mobile devices set.
NET Development on Microsoft SharePoint Technology Part 4: Templates, Features, and Solution Deployment Mick Badran Breeze Training Consulting Trainer.
#SPSSAN June 30, 2012 San Diego Convention Center WRITING TESTABLE CODE In SharePoint.
JERRY GILES MNIS Unclassified Information Sharing Service PAUL HILTON.
Transportation Agenda 19. Transportation Your Role: Designer Designers organize SharePoint content and determine how to display that content Typical tasks.
Permission Management in SharePoint – Overview and best practices Toni Frankola Co-Founder & CEO, Acceleratio Ltd., Croatia.
San Diego 2014 SharePoint Saturday San Diego November 15, 2014 UCSD Extension SharePoint Saturday San Diego November 15, 2014 UCSD Extension.
The Ultimate SharePoint Admin Tool
SharePoint 101 – An Overview of SharePoint 2010, 2013 and Office 365
Max Fritz Senior Systems Consultant, Now Micro
APAN SharePoint Permissions
Get to know SQL Manager SQL Server administration done right 
About SharePoint Server 2007 My Sites
LMEvents SharePoint Portal How-to Guide
with Office 365 Small Business
APAN SharePoint Permissions
SharePoint Site Admin Training
SysKit Security Manager
Why (and How To) use Cross site publishing in SharePoint 2013
SharePoint 2013 Site Collection Administrators
SharePoint Foundation 2010
INSTRUCTOR NOTES/LINKS
Links Launch Outlook Launch Skype Place Skype on Do Not Disturb.
SysKit Security Manager
Presentation transcript:

#SPSSAN June 30, 2012 San Diego Convention Center BEST PRACTICES FOR MANAGING SHAREPOINT PERMISSION LEVELS SharePoint 2010 Tony Rockwell

#SPSSAN Who? Tony Rockwell About me: 20+ years in IT 5 years focused on SharePoint MCTS SharePoint 2010 Configuration SharePoint Administration Installation; Configuration; Upgrades Enable OOTB features Implement 3 rd party tools Founding Board Member of SANSPUG SPSSAN organizer Solution Specialist at EMP Live EPM Live is the global leader in SharePoint-based project, portfolio & work management solutions that help organizations increase productivity by improving visibility, execution and collaboration on all types of work. PortfolioEngine WorkEngine ProjectEngine

#SPSSAN House Keeping Thank our Sponsors! This is an Interactive Session Save questions – you choose Twitter hashtags: #PermissionLevels

#SPSSAN Agenda SharePoint Security Why Create custom permission levels? Inheritance & Scopes Best Practices Permission Level Scenario How-To using the SharePoint interface How-To using PowerShell References

#SPSSAN SharePoint Security Why create custom permission levels? Because security matters to you Ease security administration Enable refined security Terminology Farm Administrator Service Application Administrator Feature Administrator Site Collection Administrator Permission Levels Users Groups Securable Objects Inheritance & Scopes Permission Levels Users Groups Securable Objects Inheritance & Scopes

#SPSSAN Inheritance & Scopes Site Collection Web Object Document Library Object Folder Web Object Item Scope 2

#SPSSAN Best Practices SharePoint Permissions Use fine-grained permissions only when business case requires it Break permission inheritance infrequently as possible Use domain groups to assign permissions to sites when possible Assign permissions at the highest level possible Make use of appropriate SP roles

#SPSSAN Best Practices SharePoint Permission Levels & Scopes Don’t modify or delete a default permission level Copy a default permission level & modify it The maximum # of unique security scopes set for a list should not exceed 1,000 Use group membership rather than individual membership in your scopes

#SPSSAN Scenario The Company Each department owns a site Department site owner to manage site… but delegates permissions to someone else Delegate should not modify site, pages, etc. only add/remove (manage) users Delegate should also have standard “Contribute” access to site The Company Each department owns a site Department site owner to manage site… but delegates permissions to someone else Delegate should not modify site, pages, etc. only add/remove (manage) users Delegate should also have standard “Contribute” access to site

#SPSSAN Required Administrative Credentials

#SPSSAN 1. Navigate to top-level site 2. Site Actions > Site Permissions (or Site Settings for Publishing) 3. Click on Permission Levels in the Ribbon 4. Select the permission level to copy – Contribute 5. Scroll down & select Copy Permission Level How-to: SharePoint interface

#SPSSAN 6. Name the new permission level (User Manager) & enter a description (i.e. “ Use this permission to Manage Users”) 7. Select desired permissions Check Enumerate Permissions (Manage will auto-select, Deselect it) 8. Scroll down & click Create The custom permission level is ready to use! Create a SharePoint group for each department; i.e. “Accounting User Managers” Give the group the “User Manager” permission level Make the owner of this SP Group, the Site Owner or SCA Change the owner of the Member & Visitor groups How-to: SharePoint interface

#SPSSAN How-to: PowerShell PS > $spWeb = Get-SPWeb Create a new object PS > $plevel = New-Object Microsoft.SharePoint.SPRoleDefinition Add name and description PS > $plevel.Name = "Custom: User Manager" PS > $plevel.Description = “Enumerate Permissions" Set the base permissions PS > $plevel.BasePermissions = “EnumeratePermissions”

#SPSSAN How-to: PowerShell Add the permission level to your site PS > $spWeb.RoleDefinitions.Add($plevel) Clean up PS > $spWeb.Dispose() See base permissions that are available PS > [system.enum]::GetNames("Microsoft.SharePoint.SPBasePermissions") EmptyMask ViewListItems AddListItems EditListItems DeleteListItems ApproveItems OpenItems ViewVersions DeleteVersions CancelCheckout ManagePersonalViews ManageLists ViewFormPages Open ViewPages AddAndCustomizePages ApplyThemeAndBorder ApplyStyleSheets ViewUsageData CreateSSCSite ManageSubwebs CreateGroups ManagePermissions BrowseDirectories BrowseUserInfo AddDelPrivateWebParts UpdatePersonalWebParts ManageWeb UseClientIntegration UseRemoteAPIs ManageAlerts CreateAlerts EditMyUserInfo EnumeratePermissions FullMask

#SPSSAN Session wrap-up Questions Please complete a Session Survey Help me improve Help the organizers improve future events Win prizes!

#SPSSAN Contact Blog: LinkedIn: San Diego SharePoint Users Group: slideshare: REFERENCE : Technet - User Permissions and Permission Levels Spbasepermissions - definitions us/library/microsoft.sharepoint.spbasepermissions(v=office.12).aspx SP Permission Inheritance Best Practices for Fine-grained Permissions (White Paper) Best Practices Center for SharePoint

#SPSSAN The After-Party : SharePint Karl Strauss Brewing Company 1157 Columbia Street San Diego, CA Phone: Immediately following event closing & prize drawings pm) Directions (.9 miles): 1. Head northeast on 1st Ave 2. Turn left onto W. B St 3. Turn left onto Columbia St Karl Strauss will be on the left

#SPSSAN June 30, 2012 San Diego Convention Center THANK OUR SPONSORS Please be sure to fill out your session evaluation!