Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
shared/team/folders/access/controls [2019_10_29 17:54] – steven | shared:team:folders:access:controls [2024_03_19 22:16] (current) – [Shared Team Folder Access Controls] steven | ||
---|---|---|---|
Line 1: | Line 1: | ||
#Shared Team Folder Access Controls | #Shared Team Folder Access Controls | ||
- | {{ youtube> | + | #### Last updated: Aug. 17, 2022 |
- | ####Last updated: March 7, 2019 | + | The Access Anywhere |
- | The org. admin can manage access to any Shared Team Folder. | + | |
- | Any org.member who has been assigned a role that has the “manage Team Folders” permission can manage access to any Shared Team Folder, and can grant access | + | Any organization |
- | An org. member to whom the “Manage Permissions” privilege has been assigned for a Shared Team Folder, either directly or because the org. member has been assigned a role that has this privilege, can manage access to that folder. | + | An organization |
- | Access to each Shared Team Folder can be granted to individual | + | Access to each Shared Team Folder can be granted to individual |
- | 1. Access privileges granted to the individual | + | 1. Access privileges granted to the individual |
+ | \\ \\ | ||
+ | 2. When an organization | ||
- | 2. When an org. member has been assigned two or more roles and the roles have different access privileges for a folder, the most permissive access level prevails. | + | Each folder also has a default access level. This is the access level that is applied to organization |
- | + | ||
- | Each folder also has a default access level. This is the access level that is applied to org. members to whom no other access level has been assigned either directly or through a role. | + | |
##Inherited Permissions and Managed Folders | ##Inherited Permissions and Managed Folders | ||
- | When a Shared Team Folder is created, either as a new folder or by converting an existing folder, any folders beneath that folder in the directory tree inherit whatever permissions are applied to that folder (but not necessarily the permission modifiers, which are discussed later in these notes). | + | When a Shared Team Folder is created, either as a new folder or by converting an existing folder, any folders beneath that folder in the directory tree inherit whatever permissions are applied to that folder (but not necessarily the permission modifiers, which are discussed later in these notes). |
+ | |||
+ | Unlike other solution permissions can be broken within the sub hierarchy of the tree. Permissions can be changed by a user with the appropriate authority on folders that are beneath a Shared Team Folder in the directory tree. When this happens, the folder on which permissions were changed becomes what we term as a ' | ||
+ | |||
+ | A new ' | ||
+ | // // | ||
+ | |||
+ | ## | ||
+ | |||
+ | Permission modifiers provide more granular control over permitted operations. This table summarizes how the permissions modifiers are used: | ||
+ | | **Modifier** | ||
+ | | Create subfolder | ||
+ | | Upload files | Read/ | ||
+ | | Rename files| Read/ | ||
+ | | Move files| Read/ | ||
+ | | Delete files| Read/ | ||
+ | | Modify Structure | Read/ | ||
+ | | Manage Trash | Read/ | ||
+ | | Create shared links | Read/ | ||
+ | | Web View Only | Read/ | ||
+ | | List Folders | Read/ | ||
+ | |||
+ | This table summarizes what they do: | ||
+ | | **Modifier** | **Meaning** | | ||
+ | |Create subfolder|If this is enabled then user can create subfolders in the shared folder.| | ||
+ | |Upload files|If this is enabled then the user can upload files to the shared folder.| | ||
+ | |Rename files|If this is enabled then the user can rename files in the shared folder.| | ||
+ | |Move files|If this is enabled then the user can move files to or from the shared folder.| | ||
+ | |Delete files|If this is enabled then user can delete files from the shared folder.| | ||
+ | |Modify structure|If this is enabled then user can, rename and delete descendant folders and the shared folder itself.| | ||
+ | |Manage Trash|If this is enabled then the user can view, restore and destroy the contents of Trash for the shared folder.| | ||
+ | |Create shared links|If this is enabled then the user can create shared links for the shared folder or any of its contents, consistent with organization policy.| | ||
+ | |Web View Only|If this is enabled then the user can only view the shared folder' | ||
+ | |List Folders|If this is enabled then the user can list and access the folders in the shared folder (consistent with permissions on those folders) but cannot list the files in the shared folder.| | ||
+ | |||
+ | Some modifiers are mutually exclusive: | ||
+ | * //Create Shared Links// and //Web View Only// cannot be used together | ||
+ | * Neither //Create Shared Links// nor //Web View Only// can be used with //List Folders//. | ||
+ | |||
+ | Please note that as of v2106.00, the Read/ | ||
+ | |||
+ | The //Modify Structure// permission modifier is also new in version v2106.00. | ||
+ | \\ \\ | ||
+ | |||
+ | ## Subfolder Access within Private Folder | ||
+ | |||
+ | As an advanced example, how can we grant a user or group access to specific subfolders within a private subfolder? | ||
+ | |||
+ | First, grant the use "List Folders" | ||
+ | |||
+ | {{ :: | ||
+ | |||
+ | Then grant access as desired for each of the subfolders. Note that any inherited permissions will be lost when the subfolder permission is added. If still needed they can be explicitly added to the subfolder as well. | ||
+ | |||
+ | {{ :: | ||
- | Permissions | + | You can also disable "List Folders" |
- | These permission modifiers are inherited by unmanaged subfolders: | + | {{ :: |
- | * List Only | + | \\ \\ |
- | * Web View Only | + | |
- | * Can Share Files | + | |
- | These permission modifiers are not inherited | + | ## Special Behaviour for Members With Certain Roles |
- | * Subfolder create disabled | + | Org. members who have been assigned the Admin role or a role that allows both managing Shared Team Folders and managing Team Clouds will see Shared Team Folders that were created |
- | * Upload disabled | + | // // |
- | * File rename disabled | + | ## Web View Only / DLP Access permissions |
- | * File move disabled | + | |
- | A new Managed Folder allows no access | + | A combination of Web View only access |
+ | ## Shared Team Folders Permissions Report | ||
+ | Org. admins can create [[shared/ |