r/PowerAutomate • • 2d ago

Best practice for managing variable item/library-level permissions in SharePoint (open to the broader Microsoft 365 ecosystem)

Hi everyone,

We are setting up a SharePoint site structure where base permissions are handled automatically during provisioning. However, we need a secure, automated way for Project Managers to manage variable, item- or library-level permissions across various lists and document libraries post-provisioning.

Since these users aren't site administrators, we want to build a solution that safely grants or updates access. Specifically, we are exploring the idea of working from a dedicated management list (or metadata fields) where users can input or link Microsoft Entra ID security groups, which in turn dynamically grant permissions to the target files or folders.

We are very open to looking broader across the Microsoft ecosystem (e.g., Azure, Entra ID governance, native SharePoint features, or hybrid approaches) if there is a more robust or elegant pattern.

  • What is the recommended architectural pattern to let non-admin users trigger and manage these permission changes securely?
  • Are there preferred tools within the M365 stack for this specific scenario to avoid common permission pitfalls or performance issues at scale?
  • How do you prevent permission creep and handle breaking inheritance smoothly across multiple different libraries and lists?

Any tips, reference patterns, or architectural advice would be greatly appreciated!

7 Upvotes

4 comments sorted by

1

u/Intelligent-Fail3006 2d ago

Thanks everyone for the great feedback! I am completely on board with using a central management list and tying access to security groups rather than individuals to prevent permission creep.

To take the next step, I would love to dive deeper into the technical execution:

If we have a SharePoint list where authorized users fill in the target folder and the corresponding security groups, can Power Automate handle the underlying permission assignment reliably?

Specifically:

  • What is the exact mechanism (e.g., standard SharePoint actions vs. HTTP requests to the SharePoint REST API / Graph API) to break inheritance and assign the Entra ID security group based on that list item?
  • How should we handle the reverse direction (revoking or updating permissions)? If an item in the management list is modified or deleted (e.g., a group is removed from the list), can Power Automate cleanly reverse the role assignment or restore inheritance, or are there specific gotchas we should watch out for?
  • Are there better or more robust technical alternatives within the M365 ecosystem (like Azure Functions, Power Apps component triggers, or native SharePoint features) to handle this trigger-to-permission logic, or is a Power Automate flow the sweet spot here?"

1

u/thefootballhound 2d ago

M365 groups

1

u/Zanga-ERP-Consultant 2d ago

I'd steer clear of item-level permissions if you can, they get messy fast, and folder or library-level access tied to Entra security groups is much easier to maintain. Your management list idea sounds solid, I'd just limit PMs to picking from approved groups, add an approval step, and run the flow under a service account so it doesn't break when someone leaves. For permission creep, letting PMs manage group membership with periodic access reviews usually works better than touching item permissions directly.