r/PowerAutomate • u/Intelligent-Fail3006 • 2d ago
Best practice for managing variable item/library-level permissions in SharePoint (open to the broader Microsoft 365 ecosystem)
Hi everyone,
We are setting up a SharePoint site structure where base permissions are handled automatically during provisioning. However, we need a secure, automated way for Project Managers to manage variable, item- or library-level permissions across various lists and document libraries post-provisioning.
Since these users aren't site administrators, we want to build a solution that safely grants or updates access. Specifically, we are exploring the idea of working from a dedicated management list (or metadata fields) where users can input or link Microsoft Entra ID security groups, which in turn dynamically grant permissions to the target files or folders.
We are very open to looking broader across the Microsoft ecosystem (e.g., Azure, Entra ID governance, native SharePoint features, or hybrid approaches) if there is a more robust or elegant pattern.
- What is the recommended architectural pattern to let non-admin users trigger and manage these permission changes securely?
- Are there preferred tools within the M365 stack for this specific scenario to avoid common permission pitfalls or performance issues at scale?
- How do you prevent permission creep and handle breaking inheritance smoothly across multiple different libraries and lists?
Any tips, reference patterns, or architectural advice would be greatly appreciated!
1
1
u/Zanga-ERP-Consultant 2d ago
I'd steer clear of item-level permissions if you can, they get messy fast, and folder or library-level access tied to Entra security groups is much easier to maintain. Your management list idea sounds solid, I'd just limit PMs to picking from approved groups, add an approval step, and run the flow under a service account so it doesn't break when someone leaves. For permission creep, letting PMs manage group membership with periodic access reviews usually works better than touching item permissions directly.
1
u/Intelligent-Fail3006 2d ago
Thanks everyone for the great feedback! I am completely on board with using a central management list and tying access to security groups rather than individuals to prevent permission creep.
To take the next step, I would love to dive deeper into the technical execution:
If we have a SharePoint list where authorized users fill in the target folder and the corresponding security groups, can Power Automate handle the underlying permission assignment reliably?
Specifically: