ServiceDeskSimulator
AI coaching on Start

Knowledge base

Sharing and least privilege

Reference: Contoso IT security standard SEC-02 · Microsoft Learn — SharePoint sharing overview

← All articles
securitysharepointexchangegovernance

Every access ticket has a wide answer that closes it quickly and a narrow answer

that closes it correctly. The wide answer is almost always still there two years

later, and nobody remembers who asked for it.

The rule

Grant the narrowest scope, at the lowest permission level, for the

shortest time, to a group rather than a person, and record why.

Narrowest scope

Somebody who needs one folder should be given that folder, not the library, and

certainly not the site. Scope creep in the grant is how a single request becomes a

permanent exposure.

Lowest level

Read before Edit; Edit before Full Control. In Exchange, Send on Behalf is

usually what someone actually needs when they ask for Send As — it preserves

attribution, which protects both parties.

Shortest time

Cover work, secondments and audits end. Access granted for them rarely does. If the

platform supports an expiring grant or access review, use it. If it does not, put a

review date in the ticket and mean it.

To a group, not a person

Group-based grants survive reorganisations, leavers, and the next person who breaks

permission inheritance. Eleven individual grants do not, and they are invisible when

someone later asks "who can see this?"

Record why

"Requested by the user" is not a justification. "Requested by R. Osei, approved by

the data owner, for the Northgate bid until 2026-09-30" is. When someone reviews

access next year, that sentence is the difference between a confident removal and an

indefinite extension "just in case".

Shortcuts that are worse than the ticket

ShortcutWhat it actually does
Granting Everyone except external usersMakes the content org-wide, permanently, invisibly
Making the requester a site collection adminGrants far more than the request, with no expiry
Adding a domain to the external collaboration allow listOpens the tenant to every user at that domain
Excluding a user from a Conditional Access policyRemoves a security control to close a ticket
Anonymous "anyone with the link" sharingPuts the content on the open internet if the link leaks
Granting Full Access to a mailbox for a one-offStanding access to somebody's correspondence

Each of these is a governance change with an owner. If one is genuinely required,

escalate it as a change request with a justification and an expiry — do not make it

yourself to clear a queue.

When you have to say no

Say what you cannot do, why, who decides, and what you have raised on their behalf.

A user with a deadline can work with "it needs the identity team's approval and I've

raised it with the justification, expect an answer today." They cannot work with

"it's with another team."

Related