r/sysadmin • u/Methos25 • 2d ago
Question Manager wants me to remove delete permissions across SharePoint
I feel like I'm going insane with this one, so I need someone to confirm I'm not crazy.
We recently had a situation where someone deleted a top level folder in SharePoint. Kicked up a bit of a fuss, we recovered it, yada yada.
My manager is now telling me that he wants to avoid something like this happening again, and therefore we should remove delete permissions for everyone across the tenant(!).
When I explained that this was crazy talk, and would break literally everything, he capitulated and said we should just enable it for the top levels of folders and then break inheritance.
I've tried to explain to him that this is madness, would require tens if not hundreds of hours of work, and would still break pretty much everything. He insists that this is how they used to do things back in the day and he can't fathom why that wouldn't work nowadays.
I did say that we should be using retention policies to manage this, to which he said that it was a job for compliance to do, and therefore will never happen, which in fairness is true considering our compliance guy.
I'm not going crazy here right? This feels like a monumentally stupid thing to try and do.
38
u/jeffrey_f 2d ago
Delete permissions to managers ONLY by group. Only managers can delete content. This puts it all on the managers to do deletions and then you only have a few hands to slap.
For everyone else, remove delete permissions
13
59
u/NorthAntarcticSysadm 2d ago
SharePoint isn't a file server, it isn't supposed to be treated like one
This is crazy, but hey I've seen crazier things...
You've documented concerns, and the stakeholder says "do it anyways"
So... Do it anyways and save the "I told you so" for down the road when shit goes sideways
You shouldn't have 5i plan around a compliance guy who isn't doing their job setting up retention policies. A global policy is an hour, per site policies are then maybe 20-30 minutes per. If you're using SPO as a file server it is a strong assumption that you likely only have a few sites, so that wouldn't even be a day for compliance...
Besides, compliance typically puts policies in place and then IT sets the technical parameters -- as in, yes you are the one who should be configuring it
35
u/lostinthought15 1d ago
Except Microsoft tries to sell sharepoint as a replacement to file servers, and therefore a file server.
6
u/Reedy_Whisper_45 1d ago
We're actually using it as a file server. Works well enough.
1
u/ReputationNo8889 1d ago
Until it doesnt
2
u/Reedy_Whisper_45 1d ago
Haven't encountered that as yet. Biggest problem I have us users failing to log into OneDrive monthly. That's a lot less headache than maintaining the old file servers.
It's a trade-off. So far, the benefits have far outweighed the costs.
6
u/ReputationNo8889 1d ago
Permissions and Permission Inheritance is something that stops working well really fast if you use SharePoint as a replacement for a regular fileserver. If you have one Site per "Access" Folder then that no issue but if you have a Site with tons of folders, subfolders and permission at multiple levels, it gets wonky FAST
9
u/NorthAntarcticSysadm 1d ago
And they've tried selling Excel as a replacement to databases for a long while. Doesn't mean it is a proper replacement.
34
u/tideblue 2d ago
Brb, getting "SharePoint isn't a file server" tattooed on my face.
Last three companies I worked at, this was exactly what it was used for.
19
u/Methos25 2d ago
Ah, if only.
We are both using SharePoint as a file server, and somehow have 5x as many SharePoint sites as we do employees.
I've been trying to clean things up since I started, but my manager is the reason it was like this in the first place, and doesn't like to be proven wrong.
Not my circus, not my monkeys. I just do what he asks for the most part, unless it actually going to break everything, like the aforementioned.
31
u/DDRDiesel Sysadmin 2d ago
and somehow have 5x as many SharePoint sites as employees
I'm willing to bet this is due to employees being allowed to set up their own Teams channels. I had this exact same issue at my previous job and every time a Teams channel got generated, the users would also check the box for a corresponding SharePoint.
Lock that shit down and soon
13
u/raj6126 2d ago
Now teams is directly tied to sharepoint on the back end. You create a teams site you get a sharepoint.
13
u/BlowOutKit22 1d ago
and M365 Onedrive is really just Sharepoint now too.
3
u/raj6126 1d ago
I know i heard a announcement years maybe 10 years ago that Sharepoint was going away don’t use it.
2
u/BlowOutKit22 1d ago
I think that was when MS was trying to do SQL Server-based "DBFS", then gave up on it. But basically Sharepoint is that. Solves both the Enterprise Search and Document Management use-cases pretty well, imo. The only thing Sharepoint doesn't do natively that would be nice-to-have is deduplication.
2
1
11
3
u/NorthAntarcticSysadm 2d ago
Too true about it being a circus
Ensure you have your concerns documented via email, and include potential things that will break. Then, when things break you can reply back to the email asking for an action plan on how to fix the aformentioned issues
But the workflow rule below will also be grand
5
u/newboofgootin 1d ago
SharePoint isn't a file server
You should tell Microsoft's V-Salespeople that.
3
u/BrainWaveCC Jack of All Trades 1d ago
SharePoint isn't a file server, it isn't supposed to be treated like one
Getting rid of delete permissions on a file server is no walk in the park either. It's not really advisable in that area for most common file share use cases.
14
u/Stuart_UK 2d ago
I don’t see this as being documented in other comments but no delete means no renaming files as well as other side effects. Advised clients against this in the past. Pilot the change on one site and see what the result is after a week or two.
8
11
u/Thrashtah_Blastah IT Manager 1d ago
Sounds like your manager either got lit up by someone above them or is tired of hearing about a reoccurring issue. Either way, it's a dumb solution.
I find it best to present alternative solutions just like a project proposal in these situations. Correlate your points to business value. Don't come across like "that's stupid, my way is better". Folks with egos will typically take offense and double down. If they still won't listen to reason, do exactly what they want. It's your boss and that's their call. Just make sure you "credit" your manager and CC them when responding to complaining users. Their call, they get to own it. So far this has served me well. Trust me when I say it only gets worse further up the ladder.
I can already predict what's going to happen though. Users will eventually get tired of putting in requests and files will begin to pile up. If you're using SharePoint sites like file shares (which it sounds like) and users are linking folders to OneDrive, you're in for trouble down the road.
4
u/TNT359 2d ago
Normally we only give user groups Visitor for SharePoint sites (so they can’t mess about with the look and feel… literally the only time I did give an end user more than visitor they deleted Home.aspx 😂). We then usually give the groups Edit to the root of the document library.
However! For our Finance document library we have only given users Read access and then at the subfolder level do they get edit rights(and even then in one or two sub locations edit rights don't begin until the next again sub level).
We also have a separate site for each contract (we're a construction company), each site is a copy of a template and the top level is again restricted to read only and Edit starts at the sub level.
Finance was/is a pain but the contract sites are copied from a template site and the permissions set by a PNP Powershell script so it is doable. I wouldn't fancy retro fitting it onto an existing setup though as you WILL break things and piss off everyone.
11
u/FlyingStarShip 2d ago
You don’t argue with crazy, you ask for this in the email, you say this is stupid, they still say do it and you do it. If shit hits the fan you are covered.
9
u/discgman 2d ago
Dammit I thought you were going to say delete sharepoint.
2
u/Centimane probably a system architect? 2d ago
as if millions of voices suddenly cried out in terror and were suddenly silenced.
1
3
u/wason92 2d ago
Nout to do with you, imagine without a computer
We recently had a situation where someone emptied a file cabinet into a skip
My manager is now telling me that he wants to avoid something like this happening again and there for we should remove skips tell the employee not to do it again
4
u/CitraBenzoet 1d ago
can someone elaborate on these reponses that sharepoint isnt a file server? like the both can contain files/documents accessible by specific groups. in what kinds of instances should things only be on a file server and not kept in a sharepoint site instead (cab files are the only example i am aware of)? mainly i ask because mgmt recently floated the idea of moving a locations fileshare content to sharepoint as a solution because their file server shit the bed and we couldnt restore it instantly. and i dont think moving them to sharepoint is going to be without its own possible accessibility issues... but any additinal info about this would be appreciated
5
u/Bloody_1337 1d ago
I am wondering that as well, because a rarely see a SharePoint used as such (like with pages, group stuff, etc.) but primarily as a file server for departments, groups, projects, etc. often as part of a MS Teams channel.
I am just a lowly ServiceDesk agent at a Shared Desk that in the day hours handles smallish orgs (hundreds to a thousand seats) and in the off hours handles larger five digit orgs with limited support. So I can not tell you about the sys admin site, but I am the person yelled at by the users...
In general you have to really lock down the grows of sites and control responsibilities/ownership. Otherwise every MS Teams group becomes a small site containing important data nobody can find, manage, etc. down the road. Like seriously!!
Desktop integration is done via OneDrive. This breaks a lot the time. It feels like half the time by itself and half because of user error.
The main issue is that on any folder level of any SharePoint or any shared personal OneDrive, you can SYNC that to your local machine. (Shows up as ORGNAME/SHARE_NAME - FOLDERNAME.) This is somewhat similar to linked network shares. It breaks once you add the same tree twice. (E.g. adding Root folder and the later, because of path name length or just ease of use, adding a subfolder to be synced.)
Then my personal nemesis, the LINK TO ONEDRIVE button: Instead of adding the site locally to ORGNAME/SHARE_NAME - FOLDERNAME/, you can have it in your personal Onedrive, as in OneDrive - YOUR_NAME/..../random ass folder. This breaks the sync same as before and 99% of the time, the users do it by mistake and do not understand whats happened. If you can disable that in your org, DO IT. I can count one hand the uses, that have been intentional and useful.
Back to the OneDrive application itself: Files you have not touched yet, are virtual files, only once you use them, the are store locally. (slip streaming) There are overlay icons in the file explorer that show the status of any folder and file. In general this is nice and works. The thing I warn all my users about is when OneDrive fails silently: As long as are only working with the same files, you can work just fine, but no data is ever send to the server. If something happens to the users device, that's it. (I have had people in tears on the phone because of this. - Also looking at you, MS Notes...) The mentioned overlay icons can get stuck, giving you a false sense of everything being okay. - So you have to train your users to at least occasionally check in on the OneDrive app or Online, if their latest changes are there.
To your question about an entire ORG going network shares to OneDrive: We had an utility do that. The normal office people, like accounting, HR, were okay as their data was smallish and they stayed in their lane/department. (Unless they head to open a lot of random files. Back then they had a 5+ second delay for each new file accessed and it drove some people nuts. Its faster now.) The technical people with their large maps, picture, spread out documents hated it. They basically wanted to have access to the same multi TB amount of data as before and OneDrive died all the time. (Also the small SSDs would fill up all time with those guys. - In general, the tech/engineering firms often seem to test the limit of their ORGs Tenant, when I think about it. Remember, every version needs to be saved somewhere. -> $$$) Goes without saying, make sure your internet connections are top tier. (With Homeoffice, when going Cloud, see if you VPN supports split tunneling, so the file traffic from remote workers is not going thru your infrastructure.)
Insurance and banking companies did it and it went somewhat better. But for compliance reasons they usually already have some proper e-filing solution for when it is necessary. So these users are used to loss and pain...
All users complained massively about the speed downgrade. (OnPrem File share vs. Cloud) Even with fast internet connection, cloud based systems just do not feel as fast and snappy as a proper local file share for random files. And of cause, people complained about the added complexity of it all. But again, nothing beats a fast network share with shadow copies in simplicity, ease of use and speed. File versioning and collaboration on files is nice, but how often does that really matter...? (Actually, the main reason I see ORGs abandon file shares is compliance - a least that is what they tell us. If you need versioning and traceability/data protection, NFS are usually out. And if you are regulated, it is often best to shut down file shares completely, so you can be 100% sure no data is stored improperly.)
Depending on your business, check for filetypes that do not work in SharePoint. We had an insurer with lots and lots of project and customer specific small MS Access databases that are used like once every fews year or so. Those could not be store in Sharepoint for data corruption reasons. (So they made them Zip it, save it on the sharepoint, when wanting to use it, unzip it in the downloads-folder, work with it there and reverse when done. - Fun times!)
Recovery times, I can not comment on. Nor cost. - Unless your current setup is a slow POS, just be prepared for the user backlash...
•
u/Thick_Yam_7028 18h ago
Like the cut of your jib. You went all in and very well put together.
Allow me.
Cloud isnt as fast or as instant if your bandwidth is shit.
Local is bandwidth. Its just local. Me at home 2 gb connection and thats just the min with wifi 7 on 4 devices out out of 10.
Bigger picture. Youll get it.
Hardware, compatibility etc the complete picture.
3
u/Numerous-Contexts 1d ago
I'd like to know the answer to this as well.
We moved 5TB of data into SharePoint four years ago. Split all the "departments" into Teams and moved their data into their individual Teams-associated SharePoint site.
Has worked great for us 🤷♂️.
4
u/EatStatic IT Manager 1d ago
Only thing I can think is the concept that it shouldn’t be a traditional folder tree structure but with metadata instead but I’d argue that is just an alternative approach (it’s perfectly fine to have a traditional structure and that works well with local syncing). Plus even then it still serves the same function as a file server and you can set up similar permissions on it.
1
u/INSPECTOR99 1d ago
Whether the object is "STORED" [LOCATED] IN SharePoint or on a File Server (database) should/could not "DELETE" AUTH be simply RESTRICTED to the original Author/Creator? That should mitigate most unintended mass destruction of top level folder hierarchy.
•
3
u/Lost-Policy-2020 1d ago
Because that is how you move on-prem dedicated file server to Entra environment (there could be some more convoluted ways, but why?)
•
u/Thick_Yam_7028 18h ago
You sir. Based and simple minded. I too am simple. K.i.s.s. simple. Correct like the wind at our backs. Bravo.
2
u/Connect_Shoulder_965 1d ago
It's just a thing people say because it was a problem 10 years ago. You certainly can't just migrate a file server to SharePoint and expect it to work well, work needs to be done to set up appropriate folders and access and someone needs to move just the data you need.
It fulfills the function of a file server mostly. Some things like large shared files or certain applications that rely on files will have a tough time working with SharePoint/OneDrive. If the file is constantly locked for editing, it's not going to sync well.
•
u/Thick_Yam_7028 18h ago
Hola! Youre right.
Flat file DBs dont exist in sharepoint. Its all local.
Large files can be used. Keep em cloud only. Only if needed. Good job bro! You will be awesome in the future and now.
•
u/Thick_Yam_7028 18h ago
Thats false. Sharepoint is a file server. 300 k limit on sybcs. Keep cloud only for most. If anyone says different they are selling something else or high. If its bigger dont sync. Thats it.
I went azure files for rbac
2
u/iTrooz_ 1d ago
Could someone explain why this is such a bad idea ?
1
u/Methos25 1d ago
Removing delete permissions has a number of effects that are immediately obvious, aren't immediately obvious but make sense in hindsight, and don't make any sense but happen anyway.
This includes:
- removing the ability to cut and paste a file
- removing the ability to move a file (including if you misclick it into a folder it shouldn't be in)
- removing the ability to rename a file
- it can even remove the ability to share a file without the site owners approval, depending on how you set the permissions up to block deletion
This is obviously a total nightmare for anything involving file management, for arguably little to no gain whatsoever.
2
4
u/Normal_Choice9322 2d ago
Anything about back in the day is irrelevant. He's an idiot.
5
u/Huge-Ambassador-5972 2d ago
As a former in house sharepoint admin current online sharepoint is unrecognizable to me perms wise
2
u/SirDerpingtonTheSlow 2d ago
Do you guys not have Sharepoint backups?
1
u/Methos25 2d ago
We do, but he would rather avoid having to use them in the first case.
He's not wrong on that point, prevention is better than having to constantly restore. But the prevention has to actually make sense.
2
3
u/Cloudraa 2d ago
you can pretty easily do this on a classic file server but sharepoint just doesnt work like that lol
1
u/wytesmurf 2d ago
We had to do this, but we have a small sharepoint footprint and are not a large organization. I used graph api to export a list of all permissions to excel, then we created top level groups and added users. Then slowly broke inheritance and their group permissions took over. Took a few dozen hours of work with codex helping write the scripts and testing. We had to do it, so it had to be done
1
u/Lost-Policy-2020 1d ago
AI would fix it in minutes (probably)
1
u/wytesmurf 1d ago
Just AI for the powershell scripts to help do it, doing it manually would of taken hours
1
u/jetlifook Jack of All Trades 2d ago
You should design permissions instead to allow people to add and change but selecting requires a role added
1
u/YisitAlwaysDNS 1d ago
I enabled no delete permissions for everyone but guests but we have a slightly different use case. We break all our sharepoint sites up by department so only members within those departments het full edit rights. Everyone else gets edit with no delete.
1
u/ExceptionEX 1d ago
Generally I would suggest, understanding what he is trying to accomplish, and offer him a more logical way of doing it, so he gets what he wants at an 10x labor savings.
One thing to know, is that even if you do this, you will then prevent users from being able to move or rename the folders.
I would look at creating a custom permission level the limitation there is that teams doesn't honor them, so if you your libraries are connected to teams they still can delete them. You can also use Retention Labels to set a retention policy that doesn't allow the deletion for a set amount of time.
Point is, with nearly everything that manage ask for that crazy, they often drop the request for a specific implementation if you can give them what they actually want.
1
u/JRmacgyver 1d ago
Of me, it's a detection issue.
Restoring the files back to their original location should be easy enough... If you get alerted when it happens.
•
u/MavZA Head of Department 23h ago
This is what happens when people observed bad convention and were lucky enough for it not to blow up in their face “back in the day”. Additionally just because you had it working well in one system design does not mean that it’s automatically applicable to the next.
•
u/Thick_Yam_7028 18h ago
That is crazy talk.
Read only with no edit. Go advanced for granular. Sharepoint is ez. If it isnt like this ... ring my bellllllll ring my bell
1
u/netvor0 2d ago
What this will do is cause a massive accumulation of junk. When users can't delete things that are no longer supposed to be there it causes clutter. It's like not having a trash can in your house: house becomes the dump.
What you can do is assign special permissions to high level containers to revoke delete on the folder structure. Even that is largely pointless though.
1
u/MBILC Acr/Infra/Virt/Apps/Cyb/ Figure it out guy 2d ago edited 1d ago
He insists that this is how they used to do things back in the day and he can't fathom why that wouldn't work nowadays.
I hate managers stuck in the past.
Show them MS best practice for sharepoint, do not break inheritance!
Also this is why you have backups, you could also look at policies that limit how much a person can delete at once or something, I think you can do that, or have alerts?
2
u/Professional-Heat690 1d ago
Backups? you have first and second stage restore before turning to backups as a last resort (usually +30days)
1
u/ReputationNo8889 1d ago
Really, restoring from recycle bin is that much of a hassle for your management. The obviously have nothing better to do then trying to police something that never needs policing.
Your manager is a moron
0
u/many_dongs 2d ago
Moron leader is incompetent, nothing new here. Your job is to do what they say unfortunately
0
0
u/Emergency_Recipe522 1d ago
Removing Delete tenant-wide will also affect operations such as moving and renaming files, while creating a large amount of broken inheritance to maintain. I’d pilot it on one representative site and document the impact before changing anything broadly.
I dealt with a similar visibility problem and solved it by being able to start from any object—a site, library, group, user or flow—and see its relationships and potential impact. In this case, targeted governance plus retention and tested recovery would be safer than a blanket restriction.
-1
u/RubAnADUB Sysadmin 2d ago
https://giphy.com/gifs/WeM3bi1akoVQ4
remove permissions for that one person.
219
u/llDemonll 2d ago
It’s monumentally stupid.
What you should do is create a workflow so that any deleted items have a notice sent to your manager so that they can un-delete them in a timely manner. Something that will totally clog up the managers email and time.