Welcome back to another edition of Helpful Thursdays. At Anantek Solutions, we believe that the best technology is the kind you don’t have to think about, what we call "Invisible Infrastructure." But for that infrastructure to stay invisible and keep your business running smoothly, the foundation needs to be solid.
For many SMEs, SharePoint is that foundation. It’s where your documents live, where collaboration happens, and where your intellectual property is stored. However, we often see businesses treating SharePoint permissions like a game of "whack-a-mole", fixing one access issue only to create three more security holes.
Whether you’re a growing retailer or a fast-paced fit-out company, getting your permissions right is about more than just convenience; it’s about durability and security. We’ve managed complex structured cabling and Wi-Fi installs for high-end brands like Audemars Piguet (AP) and A. Lange & Söhne (ALS), and if there’s one thing those projects taught us, it’s that precision at the foundational level is non-negotiable.
Here are the 7 most common mistakes we see with SharePoint permissions and exactly how to fix them.
1. Granting Permissions to Individual Users
It starts innocently enough. "Hey, can you give Sarah access to the Marketing folder?" You go in, type Sarah’s name, click ‘Share,’ and move on.
The Mistake: Over time, you end up with a "spaghetti" map of permissions. When Sarah leaves the company or changes roles, you have to manually hunt down every single file and folder she had access to. This leads to "permission creep," where employees keep access to sensitive data they no longer need.
The Fix: The "Groups-Only" Rule
Stop adding individuals. Instead, create Microsoft 365 Groups or SharePoint Security Groups based on roles (e.g., "Finance Team," "Project Managers," "Site Surveyors").
- Create the Group: Go to your Microsoft 365 Admin Center and create a security group.
- Assign the Group: Add that group to the SharePoint site or library.
- Manage the People: When a new person joins, simply add them to the group. Their access to everything they need is instant and, more importantly, easily revoked.

2. Breaking Inheritance Every Time You Share a Folder
By default, everything in a SharePoint site inherits the permissions of the site itself. If someone can see the site, they can see the libraries and folders inside it.
The Mistake: Users often click "Stop Inheriting Permissions" on individual folders to hide them from others. Do this 50 times, and your site becomes a troubleshooting nightmare. You lose the "Invisible Infrastructure" vibe because suddenly, nobody knows who can see what.
The Fix: Use Security Boundaries
If a folder is so sensitive that only two people should see it, it shouldn't be a folder: it should probably be its own Document Library or even a separate Site.
- Step 1: Identify highly sensitive data (HR records, director-level finance).
- Step 2: Move that data to a dedicated site with restricted membership.
- Step 3: Re-inherit permissions on your main libraries to keep things clean and manageable.
3. The "Everyone is an Owner" Trap
We get it. It’s easier to just make everyone a "Site Owner" so they don't have to ask you for permission to do things.
The Mistake: Owners have the power to delete the entire site, change the site’s look, and: most dangerously: change the permissions for everyone else. Too many owners lead to accidental deletions and security configurations that you didn’t authorize.
The Fix: The Principle of Least Privilege
Apply the minimum level of access required for someone to do their job.
- Owners: Limit this to 2 or 3 trusted IT leads or department heads.
- Members (Edit): This is where most of your staff should be. They can add, edit, and delete files, but they can’t break the site settings.
- Visitors (Read): For staff who only need to consume information (like company handbooks).
For a deeper dive into why this matters for your overall security posture, check out our guide on Why You Need Managed IT Support Services.
4. Uncontrolled External Sharing
Collaboration is the heart of SharePoint, especially when working with "trusted electrical partners" on a fit-out project. But if you haven't configured your external sharing settings, you might be accidentally sharing your entire drive with the world.
The Mistake: Leaving the "Anyone" (anonymous) sharing link enabled. This allows anyone with the link to access your files without even logging in. It's a massive security risk that is often overlooked until it's too late.
The Fix: Restrict Sharing at the Admin Level
- Navigate to the SharePoint Admin Center.
- Under Policies > Sharing, set the external sharing level to "New and existing guests" (requires sign-in) rather than "Anyone."
- For specific sensitive sites, disable external sharing entirely.
5. Mixing Up SharePoint Groups and Microsoft 365 Groups
This is a technical hurdle that trips up many SMEs. Modern SharePoint sites are often "Group-connected," meaning they are tied to a Microsoft Team or an Outlook Group.
The Mistake: Adding someone to the SharePoint "Members" group but forgetting to add them to the Microsoft 365 group. This can lead to weird sync issues where they can see files in a browser but can't see them in Microsoft Teams.
The Fix: Manage from the Top Down
If your site is connected to a Team, always manage the membership through Microsoft Teams or the M365 Admin Center. This ensures that permissions sync across the entire ecosystem: including the SharePoint site, the Planner board, and the shared mailbox. Consistency is what makes for "Tech That Lasts."
6. The "Set and Forget" Mentality
Your business isn't static. People move, projects end, and roles evolve.
The Mistake: Many SMEs set up their permissions once and never look at them again. Two years later, your former intern still has "Full Control" over your client contract folder.
The Fix: The Quarterly Permission Audit
Schedule a recurring task every 90 days to review your site owners and external guests.
- Step 1: Go to Site Settings > Site Permissions.
- Step 2: Click on Advanced permissions settings.
- Step 3: Use the "Check Permissions" tool to verify what specific users can see.
- Step 4: Remove anyone who no longer requires access.

7. Using Permissions to Fix Bad Folder Structure
Sometimes, permissions are messy because the folder structure is messy. If you have a folder named "General" that contains "Accounting," "Marketing," and "Staff Parties," you’re going to have a hard time managing access.
The Mistake: Trying to use complex permission overrides to "patch" a confusing file structure. This creates a brittle system that breaks as soon as you try to move or rename a folder.
The Fix: Structure by Access Level
Don't organize by "topic" alone; organize by who needs to see it.
- Create a "Public" site for things everyone needs.
- Create "Department" sites for team-specific work.
- Create a "Restricted" site for leadership.
This architectural approach is exactly how we handle network modernization for our clients. By building the network around business outcomes rather than just "plugging things in," we ensure the system is both scalable and secure. Learn more about our approach to Managed Network Services.
Why "Invisible Infrastructure" Matters
At Anantek Solutions, we focus on IT Optimisation. We don't just want to fix your broken SharePoint links; we want to make your entire IT setup run smoother and more efficiently. Whether we are installing 360-degree CCTV for a luxury retail fit-out or managing the cloud infrastructure for a growing school, our goal is the same: durability and reliability.
When your SharePoint permissions are configured correctly, your team can collaborate without friction, your data stays protected, and you: the business owner: can focus on growth instead of troubleshooting access requests.

Need a SharePoint Health Check?
If your SharePoint feels like a digital jungle and you're worried about who might have access to your data, we can help. Our expert customer support responds fast (usually under a minute!) and we pride ourselves on resolving issues on the first touch.
Contact Anantek Solutions today for a tailored IT audit and let’s build tech that lasts.