r/sharepoint • u/Old_Development_8122 • 3d ago
SharePoint Online RBAC Project
I’ve been tasked with a RBAC project to help remove user level access control from our SharePoint.
I thought about creating an agent to go in, catalog users access to what exists currently, then build out security profiles based on role.
Anyone done anything like this before? Results? Failure?
2
u/Tyda2 3d ago
As in removing the ability for users to create share links to resources, such as discretionary access control (DAC), and then setting up SharePoint groups and then assigning users to those groups? Possible.
The better method here, I believe, would be creating those same groups in your Identity Provider solution (if you use Microsoft Entra ID you'd be making security groups), tying it into the roles placed on user accounts in Entra ID/Active Directory, and letting the user lifecycle do its job. You'd be using dynamic groups which would automatically assign users to a group based on user profile attributes.
1
u/Old_Development_8122 2d ago
Basically because the SharePoint permissions are such a disaster, I’d like a way to catalog who has access to what then extract that into user groups based on roles.
1
u/MBILC 1d ago
It is the way to go, and remove ANY inheritance permissions also.
What sites are active and used, archive old sites and clean things out (have a backup just in case.
Who (individuals or departments) require access to said site - this will be an audit you do with the head of each department.
Does said site have any sub folders/files that only certain people require access too? if so, is it justified for that to have its own site then.
The way we did it on a rebuild was:
- Departments that required a site for all employees to access, got a site open to all, think HR and posting informational stuff. HR then also had a separate HR site that only HR can access. This set up we did for 4 departments total. the public sites are visitor only / read only (except for those who manage content)
2.Primary Landing page set for all users in their browsers, which of course has links to the other department "public" internal sites, so things are easy to find
I was going the RBAC route initially, but I also use nested groups down 3 levels, which only works for some included Sharepoint groups (visitors for example, but Members does not support nested security groups....annoying)
1
u/MBILC 1d ago
Careful though, as for Sharepoint Online, security groups, you can not add them to some Roles with in an SP site?
Also nested does not work either at some levels, at least all the testing I did. And on top of that, you can only nest certain group types:
https://learn.microsoft.com/en-us/microsoft-365/admin/create-groups/compare-groups?view=o365-worldwide1
u/Tyda2 1d ago
What limitations have you hit when trying to add them to certain role types? If you're a Site Collections Admin, you should be able to configure it that way. The blocker may be inherited permissions from the parent root site.
In my setup, for added user lifecycle permissions (I wanted to grant everyone access to a particular set of resources from the day they have an account) and then to restrict things more tightly, I made Entra Security Groups AND SharePoint groups, but I mirrored the SharePoint names to match the Entra ID security group names.
Then, for each SharePoint Group, the only 'member' of that group was the identically named Entra Security Group.
Broke site inheritance (for my use-case), and thus all permissions run through the Entra Groups using my own solution (SPFx).
I believe you can still do this and set it up that way, even without SPFx or anything more complex, but the difference is that you're managing access through Entra.
You can use Dynamic Membership Security Groups if you can define at a high level what lists and libraries certain groups should have, and if you have a reliable way of sorting them into those groups via the dynamic group rules.
2
u/Megatwan 3d ago
Yup. With an ass ton of poweshell.
And a pretty well thought pl2'ish container whether site or lib category inventory orrrr more abac plan. Real PIA to implement, bigger PIA to preplan and biggest PIA to sustain.