We recommend that you use Microsoft Entra (formerly AAD) domain groups to control access to you SuperOffice document site in SharePoint. All your user administration will be in the Microsoft Entra admin center, you will maintain group members there.
The Group type must be Microsoft 365 and not Security.
If you plan to use Visible for (or already using this in CRM):
Microsoft Entra groups is the only way to set permissions in SharePoint according to your SuperOffice user groups. We recommend (if not already) that you create corresponding groups in Microsoft Entra ID to your SuperOffice user groups.
If you plan NOT to use Visible for:
We recommend that you use Microsoft Entra domain groups and not the SharePoint groups. Then you will have one place to handle users and permissions, and by adding users to this group in Microsoft Entra ID when creating them - you will not have to add them again in SharePoint.
You need to set up permissions before you can configure Groups and access for your SharePoint documents in SuperOffice Online.
In SharePoint, you can give permission on site level or on document library level:
- Document libraries automatically inherits the permission from the site level.
- Document within the library will inherit the permission from the library itself.
SharePoint sharing settings required for Visible for
If you use Visible for to restrict access to confidential documents, the SharePoint site must allow users to share files and folders.Do not select Only site owners can share files, folders, and the site. With this setting enabled, SuperOffice cannot apply the document restrictions defined through Visible for.Documents are created successfully and appear in SharePoint, but the intended Visible for restriction is not applied. This can create the false impression that access has been restricted when it has not.As a result, documents can become available to a broader audience than intended, including users outside the selected Visible for groups.Before enabling Visible for, verify the SharePoint sharing settings are configured as described below.
Why is this required?
Visible for restricts access to SharePoint documents based on the SuperOffice user groups selected on an activity.
To apply these restrictions, SuperOffice updates document permissions in SharePoint on behalf of the signed-in user. If the site only allows site owners to share files and folders, SharePoint rejects that permission change and SuperOffice cannot apply the selected restriction.
Microsoft documents that site members and users with Edit permissions can grant access to files and folders unless sharing is restricted to site owners (Limit accidental sharing to specific security groups).
Required configuration
Configure the SharePoint site so that members, or users with Edit permissions, can share files and folders.
- Recommended: Site owners and members, and users with Edit permissions, can share files and folders, but only site owners can share the site.
- Also works: Site owners and members can share files, folders, and the site. People with Edit permissions can share files and folders.
- Not compatible with Visible for: Only site owners can share files, folders, and the site. This configuration prevents SuperOffice from applying Visible for restrictions.
This requirement is unrelated to external sharing settings. External and anonymous sharing can remain disabled in accordance with your organizationβs Microsoft 365 and SharePoint security policies.
Validate the configuration
- Create a test document.
- Select a restricted group in Visible for.
- Save the document.
- Confirm members of the selected group can access the document.
- Confirm a user outside the selected group cannot access the document.
Perform this validation before making Visible for available to end users.
If Visible for restrictions arenβt applied even after this configuration, see the troubleshooting guide.
SharePoint user groups
In SharePoint you can create and maintain SharePoint user groups, which gives direct access.
You canβt use SharePoint user groups to set permission on document level with SuperOffice SharePoint Documents. The integration needs to use Microsoft Entra domain groups. We will explain this later.
SharePoint site owner group
When you create a site in SharePoint, you automatically get an owner-group. Members of this owner group will have access to all documents within that site.
This access canβt be removed (neither programmatically nor manually).
For that reason, you need to use a ServiceAccount to create your SharePoint site for SuperOffice documents.
Microsoft Entra service account for SuperOffice documents
In Microsoft Entra ID, there are three types of service accounts: managed identities, service principals, and user accounts employed as service accounts. When you create service accounts for automated use, theyβre granted permissions to access resources in Azure and Microsoft Entra ID.
To use a Microsoft Entra service account for your SharePoint site for SuperOffice documents, a normal user account employed as service account is recommended:
We recommend that you use a βserviceβ account to create sites and libraries in SharePoint to avoid using personal accounts, since these will have unlimited access to all files in the site (Site-owner). If this service account has Global Administrator rights in Microsoft Entra ID, then this can be used to authorize our SuperOffice Document Library App. It will need a license to be able to access SharePoint.
Global administrator rights can of course be turned off and on for this account as needed.
If you plan to use Visible for, also see SharePoint sharing settings required for Visible for.