Microsoft SharePoint: The Best Practice Guide to SharePoint Administration
Without SharePoint, there is no Microsoft Cloud: SharePoint serves as the foundation for virtually all collaboration and file sharing features in Microsoft 365. Even for organizations that do not use SharePoint directly, understanding and correctly administering SharePoint is essential to a secure and productive cloud environment. In this guide, you will learn how to best manage Microsoft SharePoint and which mistakes and common problems to look out for.
What Is SharePoint?
SharePoint is a collaboration platform for businesses that can be operated on-premise or through Microsoft 365. SharePoint allows organizations to host and provide access to content. It supports use cases like sharing documents with others, organizing and managing projects or setting up internal wikis and intranets. Behind the scenes, SharePoint also serves as the document library and file sharing platform for Microsoft Teams and is closely connected to the cloud storage service OneDrive.
SharePoint Structure: Sites, Pages & Web Parts
SharePoint is a flexible and highly customizable platform that supports a variety of use cases. Organizations can structure SharePoint in a way that best enables them to achieve their specific goals. To use SharePoint successfully, however, it’s important to understand the basic building blocks that make up the platform.
SharePoint is divided into:
Sites: Sites are the main component of SharePoint. By creating sites and adding content to them, organizations can make information available to specific users and allow them to work together. There are two types of sites: team sites for collaboration in small groups and communication sites that allow a small group of editors to publish information for a wide audience. Each new site is added to its own site collection, which can contain different subsites below the top-level site. You can also add sites to a hub site to enable shared navigation and cross-site search.
Pages: Sites can be split into different pages to add structure and divide them up for easier navigation. Splitting a site into different pages does not affect who can access the information (by default). The main use of pages is to group information together logically. However, admins can assign different permissions to individual pages if necessary.
Web Parts: Web parts are components like lists, calendars or forms that Microsoft provides to help you design your sites. Site owners and admins can use a visual, WYSIWYG editor to add and rearrange web parts, change settings and templates, embed documents or import data from different applications. There are many different web parts that allow SharePoint users to model different use cases. For example, a list could be adapted to serve as a task board for tracking progress on a project.
SharePoint Online vs. SharePoint Server
SharePoint was initially developed as an on-premise application, but since the launch of Office 365 in 2011, it is also an important part of the Microsoft Cloud. Businesses can choose between the two versions: SharePoint Server or SharePoint Online.
The main difference between SharePoint Server and SharePoint Online is the fact that an enterprise running SharePoint Server needs to manage their own infrastructure, whereas SharePoint Online is managed by Microsoft. As a result, SharePoint Server offers businesses slightly more control, but at the price of setting up, patching and maintaining their own servers. Nowadays, SharePoint Online is the far more popular option. Because of Microsoft’s cloud first strategy, SharePoint Online also often receives new features first.
SharePoint & Microsoft Teams
While SharePoint exists as its own app in Microsoft 365, it also serves as the backend for many other cloud services. For example, teams and channels in Microsoft Teams are created as SharePoint sites and subsites in the background. Uploading and sharing files through Teams channels relies on SharePoint, while files shared in chats are stored in the user’s OneDrive.
Want to know more about the differences between M365 apps? Read our Teams, SharePoint & OneDrive comparison to find out!
By default, each new SharePoint site comes with three groups that users can be added to:
Site owners are given the Full Control permission and can change site settings, add or remove users and view, edit or delete items.
Site members have the Edit permission, meaning they can view, edit or delete items.
Site visitors have Read access to the site, they can view items but not edit or delete them. This group is often used for guests and external accounts.
Additionally, Microsoft 365 includes the SharePoint admin role, which allows members to edit any SharePoint site as well as global settings. If organizations need to provide users with different levels of access, they can create custom SharePoint groups and assign them different permissions and permission levels.
SharePoint Permission Levels
|Allows users to view pages, objects and files on a site, but prevents downloading of documents that can be rendered in the browser.
|Restricted Read (Communication Site Only)
|Provides read access to pages and documents, but not their version history or sharing settings.
|Manage Hierarchy (Communication Site Only)
|Allows users to create sites and edit pages, list items and documents.
|Approve (Communication Site Only)
|Users can approve sites, list items and documents.
|Enables users to navigate to an object that has been shared with them. Assigned automatically when accounts are given access to a specific item on a site.
|Limited Access (Web Only)
|Like Limited Access, but only allows access to the web object.
|Allows users to view pages and documents, including downloading files. The default setting for the Site Visitor group.
|Users can view, add, edit or delete items, but not create new lists or libraries.
|Users can view, add, edit and delete lists, list items and documents. The default setting for the Site Members group.
|Enables users to create lists and libraries as well as apply designs, templates and style sheets.
|Allows users to view, add, edit and delete content, add or remove users and groups as well as edit site settings. The default setting for the Site Owner group.
Access Management in M365: Best Practice Guide
Everything you need to know to manage cloud privileges in Microsoft 365 – from built-in tools to essential best practices!
SharePoint Permission Inheritance
Perhaps the biggest challenge in managing SharePoint permissions is the fact that any explicit permission on an object automatically breaks inheritance. When this happens, SharePoint maintains all current permissions the object inherits by turning them into explicit permissions as well. So users keep their current level of access, but the object no longer inherits new permissions.
Example: Your HR department has a team website which includes all members of the HR group. To plan the holiday party, the site owner creates a project folder and shares it with people outside the site – permission inheritance is now broken. Members of the HR group continue to have access, but if an admin were to add a new user to the site, they would not inherit access to that folder.
Admins are faced with two problems when it comes to permission inheritance in SharePoint: First, it’s easy to miss – especially when explicit permissions are set on deep levels of the file/folder structure. Second, it’s easy to make mistakes because SharePoint permissions behave differently than admins are used to from share permissions and NTFS permissions on the file server.
On file servers, you can add a group to a specific folder and still rely on inheritance to propagate permissions to its child objects. But in SharePoint admins need to think carefully about when and if to use explicite permissions to avoid creating problems in the future.
SharePoint Best Practices: 15 Tips & Tricks for Admins!
To use SharePoint safely and effectively, there are a few important points that admins need to pay attention to – from the proper information architecture to using the right security settings and tips for efficient administration. We’ve collected some of the most important best practices for SharePoint in this list.
SharePoint Information Architecture Best Practices
Maintain a Flat Structure
In the early days of SharePoint, organizations modeled their SharePoints after the hierarchical structure of their file servers, with many layers of nested sites and objects. However, this approach has since fallen out of favor and it has become normal to use a flat hierarchy for SharePoint’s information architecture. What this means is that in almost all cases, it’s better to create a new site instead of adding a subsite to an existing one.
Sticking to a flat structure has multiple advantages: On the one hand, avoiding nested sites and folders helps admins dodge the problem of broken permission inheritance. Creating separate sites also makes it easier to delete sites when they are no longer needed, without first checking which subsites are attached to it. Lastly, if you use too many levels in SharePoint, the character limit on a file’s path can lead to problems with file names.
Group Sites Into Hubs
To bring structure to your SharePoint without the use of subsites, organizations should use hubs to group sites together. For example, you could create one hub site for each department and add separate sites for different teams and projects. This way, you can use shared navigation and document search across the hub. Another advantage of hubs is that sites can easily be attached to a different hub if the need arises. Sites that are attached to a hub still remain separate and do not inherit permissions from the hub site.
Block Subsite Creation
Whether users should be allowed to create new sites depends on how your organization uses SharePoint. But you should definitely stop users from creating subsites to preserve the flat hierarchy you have created. You can find this setting in the SharePoint admin center under site creation and the classic settings page. More on managing site creation.
Use Tags and Metadata
To make SharePoint easier to navigate, organizations can add different kinds of metadata to documents. Site owners can either choose specific types of data to add as a column in a list or libarary or allow users to add their own tags to a document using enterprise keywords. The metadata used in your organization can be accessed through SharePoint’s term store.
Using metadata effectively requires some thought and preparation, but tagging documents is a great way to help users keep track of their purpose, contents and current status. More on the use of metadata.
Follow a Naming Convention
A consistent approach to naming sites, pages and documents makes it a lot easier to browse and administer SharePoint – especially in large organizations with multiple admins. To make sure that everyone is on the same page when it comes to naming conventions, it’s important to educate site owners and users on this topic and make the proper naming scheme easily accessible for reference.
SharePoint Security Best Practices
Implement Least Privilege Access
As with any other part of the your IT infrastructure, access to sensitive data in SharePoint must be restricted to only those users who genuinely need it. Following the principle of least privilege helps organizations prevent cyberattacks, leaks and data theft.
In order to enforce least privilege access, admins must assign users to the right sites and SharePoint groups, make sure that permissions on every list, folder and library are configured correctly and regularly audit internal and external access through user access reviews.
Enable Security Features
Microsoft 365 comes with a broad set of security features: To protect SharePoint Online and other apps in the Microsoft Cloud, it’s important for admins to enable and configure the included security features according to their specific needs and requirements.
Some features that organizations should definitely make use of are multi-factor authentication and conditional access in Azure AD, blocking legacy authentication and setting an automatic sign-out for idle sessions. You can find these last two settings in the SharePoint admin center under the tab access control.
Restrict File Sharing
Sharing access to documents is one of the main purposes of SharePoint – both within organizations and with external accounts. To prevent the wrong persons from gaining or retaining access to sensitive information, SharePoint offers a few tools to help you restrict file sharing.
For example, admins can disable Anyone links to prevent anonymous sharing. You can also disable sharing for certain domains, only enable it for specific groups or add an expiration date for guest access. More on how to manage sharing settings in SharePoint.
While Microsoft 365 allows you to place some restrictions on document sharing, it does not allow you to keep track of which files your users are sharing and with whom. For a detailed breakdown of shared files, organizations depend on third-party tools like tenfold. You can learn more in our webinar on secure file-sharing in Microsoft 365!
Behind the Scenes of Teams & OneDrive: The Secret Life of Shared Data
Block Automatic Syncing Based On File Type
Automatic syncing of local files to SharePoint or OneDrive can lead to users accidentally uploading confidential or very large files that do not belong in the cloud. In addition, ransomware often exploits automatic syncing to access cloud storage and backups.
To prevent accidental or malicious uploads, you can disable automatic synchronization for certain file types. This setting is available in the SharePoint admin center under OneDrive Sync. Here, you can enter the file endings you want to block from being synced. You can set even more detailed rules through the group policy object slash Intune template EnableODIgnoreListFromGPO, which allows you to block files if their name contains certain words like budget, salaries or employee data.
Audit Events & Changes
Logging and auditing events plays a crucial role in fixing problems and identifying potential attacks. In SharePoint Server, site audits need to be manually configured. In SharePoint Online, they are enabled by default as part of Microsoft 365’s unified audit log, which can be found in the compliance center a.k.a. Microsoft Purview. Unfortunately, events are only logged for 90 days by default. A longer retention period requires the Microsoft 365 E5 license. More information on premium audits.
Since Microsoft 365 tracks a huge number of different events, it’s no easy task to pick out relevant information through filters and searches. This is another area where third-party tools can be a big help in keeping track of important events and responding to them quickly.
SharePoint Administration Best Practices
Just like on file servers, it’s much more convenient to manage access to SharePoint sites through groups than to add users individually. Instead of adding one account after another, you make a security group with the users you want to give access (“Sales Staff” for example) and add that security group to the site members. By using dynamic groups, you can even ensure that new accounts are automatically assigned to the correct groups, giving them access to the right resources.
Using groups saves time and makes it easier to track access, especially when it comes to making changes and adjustments down the line. Note: It’s important to understand the difference between Azure AD groups like security groups, distribution groups and Microsoft 365 groups on the one hand and SharePoint groups like site owners and site members on the other.
Avoid Item Level Permissions
Admins and site owners should avoid setting item level permissions in SharePoint sites as much as possible. Because explicit permissions on individual objects break inheritance and are difficult to keep track of, they make managing permission management in SharePoint extremely tedious and annoying. Ideally, you always want to manage access at the highest level possible, i.e. by creating new sites, libraries or folders to address specific needs.
Set Retention Policies
Retention policies allow you to ensure that data stored in SharePoint and other parts of Microsoft 365 is stored as long as necessary and deleted at the right time. This feature enables you to meet legal and compliance requirements regarding record keeping or the deletion of employee data. M365 differentiates between retention policies and retention labels, which are applied at the site vs. document level respectively.
Configuring retention policies takes some time and effort, but is a great way to prevent the accidental deletion of important data and ensure that records are properly stored and saved.
Use A Seperate Site for External Sharing
Organizations that want to be extra careful with external sharing can block sharing on all sites and create a dedicated site for external file sharing. By managing outside access through one specific site, admins can more easily keep track of who has access to which document.
Centralize Your User and Permission Management
Organizations that want to structure and manage their SharePoint following best practices need to invest quite a bit of time. In particular considering that SharePoint is only one part of the Microsoft 365 ecosystem. The easiest, fastest and most accurate way to administer users and permissions in the Microsoft Cloud is through the use of automated tools.
This is especially true for hybrid environments, where automated solutions enable you to manage local and cloud systems through a single application. As one such identity and access management solution, tenfold allows you to manage cloud data and identities through a central, automated platform. But beyond that, it also provides essential new features like clear and detailed permission reporting and the ability to regularly audit privileges through user access reviews.
tenfold: Your All-In-One Solution for Microsoft Environments
Managing accounts in your own network and the Microsoft Cloud through a single app while keeping track of access to unstructured data on your file servers and in SharePoint? It’s easier than you think! With tenfold, you can automate user and permission management across your entire IT!
The best part? Thanks to out-of-the-box support for most systems and no-code configuration for our wide range of plugins, tenfold can be set up in record time. While other IAM solutions would have you writing scripts and programming custom interfaces for months or years, tenfold is fully operational in just a few weeks. See for yourself and put tenfold to the test with a free trial! We’ll show you just how easy access management can be.
Our No-Code Solution Makes IAM Easy. Sign Up Now and Test It Yourself!