web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Overriding group permi...
Power Automate
Unanswered

Overriding group permissions on a SharePoint list item

(0) ShareShare
ReportReport
Posted on by 84

I have a SharePoint list which all members of a specific group have 'Contribute' access to by default, i.e. they all need to be able to create new items.

 

One of the fields in the SharePoint list is a person/group field.  If a person's name is selected and the record is saved, then that person should no longer be able to edit that specific item, as it needs approval fields to be completed by another person in the group.

 

I'm trying to change the permissions on the item by using the action 'Stop sharing an item or file' and then 'Grant access to an item or folder'.  What I need to do is to give the group 'Contribute' permissions but override this for the named user above with 'Read' permissions only.   I have tried adding a second 'Grant access..' action targeted at the individual, but the 'Read' permission has no effect if they already have 'Contribute' permission via group membership.

 

I can't work out a way to get the individual permission to override the group permission.  Removing them from the group is not really an option as it is used elsewhere.

 

Is this even possible or will I need to approach this in a different way?  The forms have been customised in Powerapps, so a fall back option is to lock down the fields, but that is a very messy and time consuming approach given the number of fields in the form.

Categories:
I have the same question (0)
  • annajhaveri Profile Picture
    8,531 Most Valuable Professional on at

    @danbert1973  what you are trying to do is possible, to do this, first you need to break permission on that specific item so that i does not inherit permissions from its parent list, and then assign permission to group and user explicitly on the item, it can be better done using REST API from Send http request to SharePoint action. You can refer to this blog on how to do it https://www.annajhaveri.com/power-automate/set-unique-permissions-for-item-in-sharepoint-using-power-automate/ if you face any issues in this let me know.

  • danbert1973 Profile Picture
    84 on at

    Hi @annajhaveri 

     

    Many thanks for your response.  I think what you have given me is essentially an alternative method of breaking permissions and managing access, however I think the inbuilt functions in Power Automate are already achieving that for me.  What I need to achieve is to grant 'Contribute' permissions on a list item to a group, but restrict permissions for a specific member of that group to 'Read'.  I have a feeling that this may not be possible in SharePoint, but there is often a workaround lurking somewhere.

  • annajhaveri Profile Picture
    8,531 Most Valuable Professional on at

    @danbert1973  so if the user is added to the group and user is also provided a permission directly then highest permission will apply to the user, in this case user will have contribute access via group and read access directly, so contribute permissions will apply to the user.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 522 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 364 Moderator

#3
abm abm Profile Picture

abm abm 243 Most Valuable Professional

Last 30 days Overall leaderboard