Home > Appendices > Table of Policy Enforcer Rules

    Export to PDF

    Table of Policy Enforcer Rules

    Refer to the tables below for all Policy Enforcer rules by their event types.

    Event Type - Scan Site Collection Level Condition

    Rule NameRule Description
    Active Directory Group RestrictionRestrict the addition of any AD groups into SharePoint sites.
    Custom Script SettingsControl custom script settings on SharePoint sites (except for OneDrive).
    Default Sharing Link Type SettingsControl the default sharing link type settings of SharePoint sites.
    External Sharing SettingsControl the sharing settings of SharePoint site collections and OneDrive.
    Property BagControl the presence and integrity of values held within a Site Collection property bag.
    Scan External UsersScan all external users in the site collections where external sharing is disabled.
    SharePoint Designer SettingsControl the SharePoint Designer Settings for sites within a site collection.
    Site Collection Administrators CountEnforce the number of site collection administrators in each site collection where this rule is applied.
    Site Collection Administrators RestrictionControl the addition of users/groups into the Site Collection Administrators group where this rule is applied.
    Site Collection FeatureControl the activation or deactivation of any SharePoint feature at the site collection level.
    Site Collection NavigationControl the navigation settings of a site collection.

    Event Type - Scan Site Level Condition

    Rule NameRule Description
    Access Requests SettingsControl Access Requests Settings within a site to simplify the process of managing who has access to a site.
    Master PageControl master page settings for sites.
    Regional SettingsControl regional settings for sites.
    Restricted Subsite TemplateRestrict which templates can be applied to subsites below where this rule is applied.
    Site Column Type DeploymentControl the site column type deployment where this rule is applied.
    Site Content Type DeploymentControl the site content type deployment where this rule is applied.
    Site FeatureControl the activation or deactivation of any SharePoint feature at the site level.
    Site Owner RestrictionControl the users or groups that are allowed to be added into the owner groups of SharePoint sites.
    Site ThemeControl the site theme applied to a site.
    User Permission EnforcementEnforce that users with specific Microsoft Entra ID properties must be in defined SharePoint groups or have certain permission.

    Event Type - Create Site

    Rule NameRule Description
    Site DepthControl the number of sites that can be created under the site collections where this rule is applied.
    Site TemplateControl the site template applied to a site.

    Event Type - Scan List Level Condition

    Rule NameRule Description
    Information Rights Management (IRM) SharePoint 2013Control IRM settings for list/libraries with a SharePoint 2013 experience version.
    Library Versioning SettingsControl Library versioning settings within a site.
    List Column Type DeploymentControl the list column type deployment where this rule is applied.
    List Content Type DeploymentControl the list content type deployment where this rule is applied.
    List Versioning SettingsControl List versioning settings within a site.
    List/Library TemplateControl the list/library template applied to a list/library.

    Event Type - Create Item

    Rule NameRule Description
    Content Creation/Content UploadRestrict or allow the uploading and/or creation of content based on individual user or group, size of content, content type, or file type.

    Event Type - Copy

    Rule NameRule Description
    CopyRestrict or allow individual users or groups to copy SharePoint objects.

    Event Type - Delete

    Rule NameRule Description
    DeleteRestrict or allow individual users or groups to delete items, files, lists, or libraries.

    Event Type - Move

    Rule NameRule Description
    MoveRestrict or allow individual users or groups to move SharePoint objects.

    Event Type - Add Group Member

    Rule NameRule Description
    SharePoint Group Member Count EnforcementEnforce the number of members in the defined SharePoint groups in each site collection where this rule is applied.

    Event Type - Break Permission Inheritance

    Rule NameRule Description
    Break Inheritance ProtectionProtect the permission inheritance from being broken at specific SharePoint object levels.

    Event Type - Inherit Permission Settings

    Rule NameRule Description
    Restore Inheritance RestrictionKeep track of SharePoint objects that had previously broken inheritance and implemented unique permissions, but have now reverted to inherited permissions.

    Event Type - Change Permission

    Rule NameRule Description
    Microfeed Permissions EnforcementLock and protect the Microfeed Lists’ unique permissions from modification.

    Event Type - Add Group Member; Delete Group Member; Change Permission

    Rule NameRule Description
    Grant, Revoke, and/or Modify Permission PrivilegeRestrict or allow individual users or groups to modify User and Group Permission with SharePoint.
    Permission Modification ProtectionSpecify Microsoft Entra users/groups and SharePoint groups whose permissions are locked and protected from modification.

    Event Type - Add Group Member; Change Permission; Scan Site Collection Level Condition

    Rule NameRule Description
    User/Group RestrictionAllow or restrict the addition of users or groups into SharePoint sites where this rule is applied.