You are currently reviewing an older revision of this page.
[toc]
APAN uses the SharePoint out-of-the-box (OOTB) security model. SharePoint security groups are SharePoint objects that have “users” as members and come with their own settings. These settings can be things like who the owner of the group is and who can add or remove users from these groups. The table below represents an overview and description of the various out-of-the-box security groups and permission levels.
Security Group
Permission Level
Authority
Site Owners
Full Control
Can add/edit/delete content, delete sites, and set up permissions for a given site
Site Members
Contribute
Can add/edit/delete content on a site
Site Visitors
Read
Can only read and download content
Additional SharePoint security groups can be created at the discretion of a Site Owner or a Site Collection Administrator (SCA); however, this practice is discouraged and is not an APAN best practice.
APAN’s existing global security groups for APAN SharePoint Farm are:
Group Name
Description
All Users (windows)
All users that authenticate with windows authentication
NT Authority\Authenticated Users
All users regardless of authentication type used (same as All Users)
Style Resource Readers
Style Resource Readers should have read permission to "Master Page Gallery" and restricted read permission to the "Style Library" at the site collection level.
In some cases, your site may contain content only meant for certain users or groups. For example, you may create a new library for a special project, and want to ensure that only people who work on that project can access the library.
Access can be granted or restricted. To restrict access, you have to break permissions inheritance, and then change the permissions for the list or library on a uniquely defined permissions page. Read below to learn more.
As an owner, you can Approve and Disapprove membership.
NOTE: As the owner of your site, YOU are responsible for identifying if an APAN user should have access to your site.
APAN BEST PRACTICE: If you have several owners in your community who are not aware of these permissions, this could cause issues for other owners to manage permissions and who has access to what. It may be simple to create a subgroup and manage permissions this way. Or, designate no more than 2 Owners as your site’s access gate-keepers.