Skip to content
English
  • There are no suggestions because the search field is empty.

Documents – Managing Folder Permissions

Manage Access Rights for Folders and Files Using Security Groups

Documents – Managing Folder Permissions

Overview

Access to folders and files within the document repository is controlled via security groups.

These security groups are managed in Microsoft Entra ID (Azure) and are subsequently available within big as well.

Prerequisite:

An integrated SharePoint document repository with user-delegated app registration.

Important to Note:

  • Security groups are managed in Microsoft Entra ID.

  • This management is not project-specific.

  • Project-specific security groups must therefore be defined by an administrator in the project configuration.

Only the groups defined there can subsequently be used for access control within the big document repository.


Who can view documents?

Which users can view documents and folders is controlled by the configured security groups.

This means:

  • Users can only view the folders and files for which their security group has permission.

  • Permissions are not assigned directly to individual users in big, but are controlled through the assigned groups.

  • Only security groups that have been defined in the project configuration can be used in the document repository.

Important:

  • The security groups themselves are managed in Microsoft Entra ID (Azure).

  • In big, the groups available for use in the project are selected via the project configuration.

  • If read or write permissions are assigned to a folder for a group, this also applies to the files and subfolders contained within it.

This ensures that users can only view and edit the documents to which they have been granted access in the project.


Prerequisites

Only users with the appropriate roles and permissions can adjust folder permissions within big.

If you encounter problems or error messages while using this feature, it is often due to a lack of permissions within the document repository.

In this case, please contact:

  • Your project administrator

  • or Support


Set Up Folder Permissions

Within the document repository, you can view and adjust permissions on a per-folder basis.

  1. Select the desired folder.

2. Click the corresponding icon to open the folder permissions.

Depending on your access rights, you can view or edit the permissions there.

After clicking the icon, the current access rights are displayed by group.


Add Group Permissions

You can use “Add Group” to add additional security groups to the selected folder.

The permissions apply to:

  • the selected folder

  • all files it contains

  • all subfolders at subsequent levels

There are two permission levels:

Read

Users can open and download documents.

Write

Users can edit, upload, or modify documents.

Note:

In SharePoint, the “Contribute” permission level corresponds to the “Write” permission level.


Permissions for the Root Folder

Permissions for the root folder of the document repository can also be customized.

This is done at the top level using the “Manage Access” button next to the “Documents” entry.

This feature allows you to manage permissions for the entire document structure.


Export Permissions Matrix

A report on the currently configured permissions can also be downloaded by clicking the “Manage Access” button next to the “Documents” entry.

This report presents a permissions matrix and shows:

  • which groups have access

  • to which folders the permissions apply

  • which permission level has been assigned

The export is particularly useful for:

  • Project management

  • Permissions audits

  • Documentation of access rights



Frequently Asked Questions (FAQ)

Who can change folder permissions?

Only users with the appropriate roles and permissions within the project.

Why can’t I select a group?

The group was likely not defined in the project configuration.

Where are security groups managed?

They are managed in Microsoft Entra ID (Azure).

Do permissions also apply to subfolders?

Yes. By default, permissions apply to the folder and all subfolders and files it contains.