56
BEST PRACTICES CONFERENCE SHAREPOINT Clarity. Direction. Confidence. @veroniquepalme r #BPC11 TEAM SITE SECURITY FOR END USERS Veronique Palmer SharePoint MVP March 2011

Team Site Security for Site Owners - BPC11 - March 2011

Embed Size (px)

DESCRIPTION

Presented at SharePoint Best Practices Conference in LaJolla.

Citation preview

Page 1: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

Clarity. Direction. Confidence.

@veroniquepalmer #BPC11

TEAM SITE SECURITY FOR END USERS

Veronique PalmerSharePoint MVP

March 2011

Page 2: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Page 3: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Page 4: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

PLAN!PLAN!PLAN!

3 Words

Page 5: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Confusing Terms

Page 6: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Hierarchy

SCA’s

Site Owners

Site Members

Site Visitors

Page 7: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Site Level

List / Library Level

Item Level

Options

Page 8: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Site Owner Tools

Page 9: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Version Comparison

BUILT IN REPORTING!

Page 10: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

SharePoint 2007 Management

Page 11: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

SharePoint 2007 Management

Page 12: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

2007 Essentials

DOCUMENT!

Page 13: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

SharePoint 2010 Management

Page 14: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

SharePoint 2010 Management

Page 15: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

2010 Essentials

Page 16: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

2010 Limits

50 000 ceiling on limited access per list / library

10 000 user groups per site collection

5 000 users per Active Directory group

5 000 groups each user can belong to

Page 17: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

ARCHITECTINGYOUR SITE

Page 18: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Everyone Just YouYour Team

Who Needs to See the Info?

Team Site My SiteIntranet

Who Are WeWhat We DoContact Us

EditRead

No Access

Shared DocsPersonal Docs

Not Ops

Inherited You DecideUnique

Page 19: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Inherited vs Unique SitesHR Top level site

Unique Permissions

HR Members,

Owners, Visitors

Policies Top Level Site

Unique Permissions

Policies Members,

Owners, Visitors

Operational Subsite

Inherited Permissions

Policies Members,

Owners, Visitors

Training Subsite

Inherited Permissions

HR Members,

Owners Visitors

Vendors Top Level Site

Unique Permissions

Vendors Members,

Owners, Visitors

Courses Top Level Site

Unique Permissions

Courses Members,

Owners, Visitors

Discipl Top Level Site

Unique Permissions

Discipl Members,

Owners, Visitors

Dismissed Top Level Site

Unique Permissions

Dismissed Members,

Owners, Visitors

Court Cases Subsite

Inherited Permissions

Dismissed Members,

Owners, Visitors

Recruitment Subsite

Inherited Permissions

HR Members,

Owners, Visitors

Int Placements Subsite

Inherited Permissions

HR Members,

Owners, Visitors

Ext Placements Subsite

Inherited Permissions

HR Members,

Owners, VisitorsInheritance is broken, what you do here will not affect the site above it.

What you do on the site below affects the site above and vice versa!

Page 20: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

AD vs SharePoint Groups

Page 21: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Active Directory Groups

Company Structure Accurate

Security Groups

Channels to Edit

Intranet Sites

Pros

Page 22: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Cons

Active Directory Groups

Rules Confusion

Site Not on My Sites

Can’t See Users

Team Sites

Page 23: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

NEW GROUPMANAGEMENT

Page 24: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management Both

Page 25: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management Both

Page 26: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management 2007

Page 27: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management 2010

Page 28: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management 2010

Page 29: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management Both

Page 30: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

New Group Management Both

Page 31: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

DELETERIGHTS

Page 32: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Delete Rights on Members

Page 33: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Delete Rights on Members

Governance

Page 34: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Delete Rights in Foundation

Page 35: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

View All Users in Foundation

Page 36: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

LIMITED ACCESSCHAOS

Page 37: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Chaos

Page 38: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Chaos

Page 39: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Chaos

Page 40: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Chaos

Page 41: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Less Chaos

LIBRARYLEVEL

x ??

Page 42: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Less Chaos

Page 43: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2007 Less Chaos

Page 44: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Limited Access 2010 Better!

Page 45: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

UNIQUEPERMISSION SITES

Page 46: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Unique Permission Sites Both

Page 47: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

GOTCHASSUMMARY

Page 48: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Management in 2007

Foundation 2010

Limited access chaos

AD group challenges

Inherited site implications

New group governance

Delete rights governance

Teaching beginnersETC!!

Page 49: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Worst Practices

• Permissions on doc level

• Adding users outside groups

• Inheriting on team sites

Best Practices

• Use default groups

• Add URL to new group

descriptions

• Get proper training at the

right time

33

Page 50: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

THING

Document!

Plan and

etc

There is no undo button!

Page 51: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Page 52: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Site Hierarchy Poster

http://www.letscollaborate.co.za/Resource-Centre/LCs%20Documents/Poster%20-%20SharePoint%202007%20-%20Site%20Permissions%20for%20End%20Users%20v1.1.pdf

Site Collection Administrator and Farm Administrator Duties

http://office.microsoft.com/en-us/sharepoint-server-help/permissions-for-site-collection-administrators-HA101943260.aspx?CTT=1

More Info for Site Collection Administrators

http://office.microsoft.com/en-us/sharepoint-server-help/control-user-access-with-permissions-HA101794487.aspx?CTT=5&origin=HA101794118

SharePoint 2010 Groups and Permissions Reference Chart

http://office.microsoft.com/en-us/templates/results.aspx?qu=SharePoint&origin=HA101943260&CTT=5#ai:TC101977256|

Control Access to a Specific Piece of Content

http://office.microsoft.com/en-us/sharepoint-server-help/control-access-for-a-specific-piece-of-content-HA101805400.aspx?CTT=5&origin=HA101794118

Resources 1

Page 53: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

All SharePoint Permissions articles from Microsoft

http://office.microsoft.com/en-us/sharepoint-server-help/results.aspx?qu=sharepoint%20permissions&origin=HA010379092&queryid=6da473d6a2754ac1ad638d36e08e6640

Configure Permissions for a Blog in SharePoint 2007

http://office.microsoft.com/en-us/sharepoint-server-help/configure-permissions-for-a-blog-HA010021567.aspx?CTT=1

Online Course to Learn Excel Services Permissions in SharePoint 2007

http://office.microsoft.com/en-us/sharepoint-server-help/excel-services-ii-requirements-recommendations-and-permissions-RZ010285649.aspx?CTT=1

Resolving Conflicts in SharePoint Workspaces 2010

http://office.microsoft.com/en-us/sharepoint-workspace-help/resolving-conflicts-and-errors-in-sharepoint-workspace-HA010382158.aspx?CTT=1

Working with Permission Levels

http://office.microsoft.com/en-us/sharepoint-server-help/edit-create-and-delete-permission-levels-HA101805381.aspx?CTT=5&origin=HA101794118

Choosing a Security Group

http://technet.microsoft.com/en-us/library/cc261972.aspx

Resources 2

Page 54: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

@veroniquepalmer #BPC11

Resources 3Manage Memberships of SharePoint 2010 Groups

http://office.microsoft.com/en-us/sharepoint-server-help/manage-membership-of-security-groups-HA101794106.aspx?CTT=5&origin=HA101794118

Setting Permissions on Views

http://www.sharepoint911.com/blogs/laura/Lists/Posts/Post.aspx?ID=76

Allowing Anonymous Users to Comment on Blogs

http://www.sharepointedutech.com/2011/01/20/how-to-allow-anonymous-users-to-comment-on-a-sharepoint-2010-blog/

TechNet Article on How Permissions Work (Level 300)

http://technet.microsoft.com/en-us/library/cc262690.aspx

Restricting Access for Search Purposes

http://office.microsoft.com/en-us/sharepoint-server-help/enable-content-to-be-searchable-HA010379092.aspx

SharePoint Security Issues

http://community.bamboosolutions.com/blogs/sharepoint-2010/archive/2010/06/09/teched-2010-sharepoint-security-permissions-identities-amp-objects-including-a-gotcha-that-breaks-security-trimming.aspx

Page 56: Team Site Security for Site Owners - BPC11 - March 2011

BEST PRACTICES CONFERENCE SHAREPOINT

Clarity. Direction. Confidence.

@veroniquepalmer #BPC11

Please be sure to fill out your session evaluation!

[email protected]

www.letscollaborate.co.za

THANK YOUFOR YOUR TIME

SAN DIEGO