How can I customize Sharepoint permissions to allow employees to create, edit, and access within their employee folders but disallow them from deleting the entire employee folder?

Anonymous
2024-08-15T23:46:36+00:00

In our organization, we have shared folders with access for everyone, we have a general "Employee" folder, where each employee has a folder under their name this is where all their documents get saved or created under. I want to change the settings so that the employee cannot delete their employee folder where they have been creating all of their work.

I have already attempted customizing the settings and unselecting all the options that say "delete" but allowing creating, editing, and access within the folder and this is not functioning as desired (employees can still delete their employee folder).

How do we do this?

Microsoft 365 and Office | SharePoint | For business | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

4 answers

Sort by: Most helpful
  1. Anonymous
    2024-08-19T04:29:50+00:00

    Dear Charlotte,

    Thanks for writing back and updating with us. Apologies for the delay in the response.

    As per the further updates, I believe the users should be having higher permission level as well assigned to their Office 365 account because when the user is assigned with the two different permission levels, the SharePoint Online will consider the higher-level permission.

    So, I request you to check the permission of the user who is assigned with no delete permission but still able to delete option via below steps:

    Open the SharePoint Online site> Settings> Site Permissions> Advanced Permission Settings> Check Permissions> Enter the user email address> Check Now> Take a complete screenshot and share it with us.

    If the user is assigned with the Edit permission or Contribute permission, please go to the Permission Levels> Click on the Permission> Take a screenshot and share it with us.

    Appreciate your patience with us and have a wonderful day!!

    Best Regards,

    Sophia

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2024-08-16T17:27:41+00:00

    Thank you for your replies. Unfortunately - the settings are set to reflect the same permissions as shown below and we are not seeing the output to be what you sent.

    What could be the cause of this?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-08-16T04:37:00+00:00

    Dear Charlotte,

    Good day!!

    Apologies for the inconvenience caused and please don’t worry, let’s work together on your concern and move towards a resolution path.

    I understand your concern and to my knowledge, I would like to convey that we can prevent the users from the deleting the content in the SharePoint Online site by removing the following List level permissions:

    Manage Lists - Create and delete lists, add or remove columns in a list, and add or remove public views of a list.

    Delete Items - Delete items from a list and documents from a document library.

    Delete Versions - Delete past versions of a list item or document.

    Output at the users end:

    They don’t have option to delete the folders or files inside the document library.

    In this situation, I request you to customize the settings are per the above screenshot and see whether the users are not seeing the delete option.

    If still the users are able to see the delete option, it seems the users are having the higher level permission assigned to them and I would like to request you to share the screenshot of the Check Permissions for one of the problematic user with us:

    Open the SharePoint Online site> Settings> Site Permissions> Advanced Permission Settings> Check Permissions> Enter the user email address who are able to delete option> Check Now> Take a screenshot and share it with us.

    In addition, please share the screenshot of the permission level assigned to them via:

    Open the SharePoint Online site> Settings> Site Permissions> Advanced Permission Settings> Permission Levels> Click on the assigned permission level> Take the screenshots and share it with us.

    Our sincere apologies for not resolving the problem in the first reply but answers to the above queries will help us to better understand your situation and guide you in the right direction.

    Appreciate your patience and understanding. Have a great day!!

    Best Regards,

    Sophia

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2024-08-16T03:09:32+00:00

    Dear charlotte.dub,

    To achieve the desired permission settings in SharePoint, where employees can create, edit, and access content within their employee folders but cannot delete their entire folder, you need to fine-tune the permission levels at a more granular level. Here’s how you can do it:

    Step 1: Create a Custom Permission Level

    1. Go to Site Settings:
      • Click on the gear icon (⚙️) in the top right corner of your SharePoint site and select Site Settings.
    2. Create a New Permission Level:
      • Under the Users and Permissions section, click on Site permissions.
      • In the ribbon, click on Permission Levels.
      • At the bottom of the Permission Levels page, click Add a Permission Level.
    3. Define the Custom Permissions:
      • Give your new permission level a name (e.g., "Contribute without Delete Folder").
      • Start by copying the settings of the "Contribute" permission level (which allows users to add, edit, and delete items).
      • Uncheck the Delete Items and Delete Versions options, but make sure Add Items, Edit Items, View Items, and other necessary options are checked.
      • Leave the Manage Lists option unchecked (this prevents users from deleting the list or folder).
    4. Save the Custom Permission Level.

    Step 2: Assign the Custom Permission Level to Employee Folders

    1. Navigate to the "Employee" Folder:
      • Go to your "Employee" folder where all the employee-specific folders are located.
    2. Break Inheritance for Employee Folders:
      • Select one employee’s folder, click on the ellipsis (…) or right-click to access the folder's settings, and then select Manage Permissions.
      • In the permissions window, click on Stop Inheriting Permissions to break the inheritance from the parent folder.
    3. Assign the Custom Permission Level:
      • Select the group or individual employee you want to apply the custom permission to (e.g., an AD group containing all employees).
      • Click on Edit User Permissions.
      • Apply the new custom permission level (e.g., "Contribute without Delete Folder").
      • Repeat this process for each employee’s folder.

    Step 3: Test the Configuration

    1. Test with an Employee Account:
      • Log in as a user with the new custom permission level applied.
      • Verify that the user can create, edit, and access documents within their folder but cannot delete the entire folder.

    Additional Notes:

    • Subfolders and Items: If you have subfolders or specific items that need different permissions, you may need to adjust those separately.
    • User Experience: Ensure users are aware of the new restrictions to prevent confusion or frustration.
    • Monitoring: Regularly check the permissions to ensure they are applied correctly and functioning as expected.

    This approach should prevent employees from deleting their entire folder while still allowing them to manage the content within it.

    Best,

    Yuki N

    Was this answer helpful?

    0 comments No comments