Home > SharePoint Security Management > Change Permissions Service
Export to PDFConfigure Change Permissions services to define the Change Permissions service request template for the business users. You can specify the users in a certain site collection whose permission you wish to change.
To create or manage services, click Service in the Request Management group within Settings.
On the interface for creating or editing a Change Permissions service, configure the following settings.
For information about common service settings that exist in all types of services, refer to Common Service Settings.
Scope – Expand the tree to select your desired nodes by selecting the corresponding checkboxes.
You can also choose to Use SharePoint Online context to automatically populate the service request scope. Select this checkbox to retrieve and use the SharePoint Online context in the service request scope. In the request triggered from the Site Information Card app part, the URL of the site where the Site Information Card resides will be retrieved. The site URL will be automatically used as the request scope. Choose one of the following options:
Allow Business User to Edit the URL – The site URL will be automatically filled into the text box, and the requester can edit it.
Show as Read-Only to Business User – The site URL will be displayed as read-only, and the requester cannot edit it.
Hide from Business User – The site URL will be hidden from the requester.
Select Users – Select the users for which you want to change the permissions. Choose from the following:
Allow any user/group – Select this option to allow the business user to change permissions of any SharePoint Online users and security groups of the selected scope.
Allow peers and direct or indirect reports (only supports SharePoint Online standard instance user) – Select this option to allow the business user to change permissions of users managed by the requester and the users of the same title as the requester.
Allow direct or indirect reports (only supports SharePoint Online standard instance user) – Select this option to allow the business user to change permissions of users managed by the requester.
Change Type – Choose to Remove Permissions from users/groups or Change Permissions of users/groups.
If you define this service as a Remove Permissions service, approvers will be required to review what permissions can be removed after users request to remove permissions. Therefore, when the approval process for this service is configured as Use approval stages and conditional automatic approval is enabled at the same time, the approvers will be asked to review the request. The request will not be automatically approved even though the conditions for automatic approval are met.
Choose whether to assign the selected change type to this service, or allow the business user to choose the change type when submitting a service request for this service. Choose from the following:
Assign by Business User – Allows the business user to choose the change type when submitting a service request for this service.
Assign by IT Admin – The selected change type will be applied to this service. Select either Show as Read-Only to Business User or Hide from Business User.
You can also choose whether to Exclude specified permission levels from the permission review task. If you enable this option, select one or more permission levels. Any user or group who has the selected permissions to the request scope will not be included in the report within the permission review task. When the requester changes users’ or groups’ permissions in the permission review task, the selected permission levels and groups with the permission levels will not be available to the requester.
The permission levels are retrieved from Settings > SharePoint Permission Level Management. If you have custom permission levels, add the permission levels in SharePoint Permission Level Management first.
In the Advanced settings, select an email template to send the notification email that notifies the requester to review or change permissions in the generated permission review task.
When you have finished configuring settings for this service, choose one of the following options:
Click the arrow on the left-hand side to go to the previous steps to review and modify your configurations.
Click Save to save all of the configurations and return to the Service Management interface.
Click Save and Activate to save all of the configurations and activate this service, which allows users to submit requests for this service.
Click Cancel to return to the Service Management interface without saving any configurations.