SharePoint Use Cases

23 Sep, 2008

Taming SharePoint Security

Posted by: Toni Frankola In: SharePoint  Bookmark and Share

I currently have 4 domain accounts in our company domain. I use one of them as my primary account and the other three when testing security of our SharePoint 2007 based intranet. If you are deploying SharePoint for a customer or as an internal solution, you should always have an end user account for testing. (Mark Miller has posted a little more details about that. He is also currently running series of short best practices articles on his blog. Check it out).

I am doing it in the following way, using:

  • Internet Explorer 7 (logged in as admin)
  • Firefox (logged in as enduser1)
  • Google Chrome (logged in as enduser2) – OT: I am quite pleased with Chrome, it works nicely with SharePoint

in order to test if SharePoint is configured correctly.

When setting permission, avoid setting permission to an individual user. Always use AD or SharePoint groups. SharePoint groups are easier to setup and maintain but they are limited:

  • Can only be used outside SharePoint (i.e. Outlook)
  • Cannot be nested

Here are the some ways to configure security (the best is listed at the top).

  1. Configure security at site collection level (use SharePoint groups to do it)
  2. Configure security at site level
  3. Configure security at list level
  4. Configure security as list per item-level permission policies (List Settings > Advanced Settings > Item-level Permissions)
  5. Configure security via workflow
  6. Configure security at item level

For a large site you will probably end up with a mixture of all 6 ways. Because of that, you will need some dummy users to test if security is configured correctly. If you are having a really complex site, you might be willing to consider Universal SharePoint Manager 2007 by iDevFactory. This tool allows SharePoint administrators to monitor security for a server farm without using dummy users. It can be quite helpful when it comes to SharePoint security.

Tags:


Documentation Toolkit for SharePoint

Comments

2 | Logging in as another user in sharepoint Drija

May 28th, 2011 at 12:14 am

Avatar

[...] Some of approaches you might wanna try are described in this article. [...]

Comment Form


About

Real-life use case and opinions about collaboration, CRM and web technologies and stuff by Toni Frankola. More...

Toni Frankola - SharePoint MVP Profile

All postings on this blog are provided "AS IS" with no warranties, and confer no rights. All entries in this blog are my opinion and don't necessarily reflect the opinion of my employer.

Page optimized by WP Minify WordPress Plugin