How to restrict Purview permissions to a particular Sharepoint site?

Jacqui Chan 0 Reputation points
2026-02-04T07:21:50.1833333+00:00

A staff member needs to examine files within a Sharepoint site to download file properties / metadata for a project and requested Purview permissions. How can we restrict his access to a particular site so as not to expose sensitive sites and libraries on our tenant?

Microsoft 365 and Office | SharePoint | For education | Windows
0 comments No comments

2 answers

Sort by: Most helpful
  1. Liora D 18,915 Reputation points Microsoft External Staff Moderator
    2026-02-04T08:04:48.3+00:00

    Dear @Jacqui Chan,

    Welcome to Microsoft Q&A. 

    Based on your description, I understand that you want a staff member to be able to examine files including properties and metadata inside a specific SharePoint site, but you do not want to expose other sensitive sites, libraries, or tenant‑wide content through Microsoft Purview permissions.

    From Microsoft’s side, it’s important to clarify that Purview roles cannot be restricted to a single SharePoint site or library. Purview compliance roles such as Content Explorer, Content Viewer, eDiscovery Manager, etc., always operate tenant‑wide, and Microsoft currently does not provide a mechanism to scope these roles down to one SharePoint location. These permissions are designed for organizational compliance, auditing, and eDiscovery needs not for operational access to a specific site. (Official Purview documentation confirms these roles are global in scope.)

    Instead of Purview roles, you may want to consider a safer and more practical alternative:

    To let your staff member view file properties, metadata, and content only inside the intended SharePoint site, the recommended approach is to use standard SharePoint site permissions.

    Here is the setup you can use:

    1. Add the staff member directly to the SharePoint site

    Depending on the level of access needed: Open SharePoint site > Left menu selects Settings > Site permissions

    • Site Visitors (Read): Can open files, view details, see metadata.
    • Site Members (Edit): Can upload/update, manage lists or libraries.

    User's image

    This keeps access strictly limited to that one site and does not expose sensitive libraries anywhere else in the tenant.

    1. Ensure the library shows metadata

    Your staff member will automatically be able to: Open the Details pane, View file properties, View columns/metadata, Export metadata using "Export to Excel" and Filter or sort columns in list/library views

    All of this works fully with only SharePoint permissions, Purview is not required.

    1. Optional: Use a dedicated metadata view

    You can create a custom library view that shows: Custom metadata columns, File type, Modified by, Sensitivity labels (if applied), Any project‑specific fields

    Then grant the user read access to that view only.

    SharePoint site permissions are scoped to the exact site you choose. This method protects all other sensitive sites/libraries while giving the staff member everything they need within the project site.

    I hope this information helps clarify the difference between Purview and SharePoint permissions and gives you a safe and workable alternative. If you run into any issues while trying the steps, or if something still doesn’t feel quite right, please don’t hesitate to reach out again. I’ll do my best to support you however I can.  

    Looking forward to hearing back from you with any updates or additional details. 

    Warm regards, 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.   

    Was this answer helpful?


  2. AI answer

    2026-02-04T07:22:28.06+00:00

    To restrict Purview permissions to a particular SharePoint site, you can use the restricted access control policy available in SharePoint. This allows you to designate access to specific users or groups, ensuring that only those specified can access the site and its content. Here are the steps you can follow:

    1. Set Up Restricted Access Control: As a SharePoint Admin, you can create a restricted access control policy that limits access to the site to only the users or groups you specify. This means that any sensitive sites and libraries will not be accessible to users outside of this group.
    2. Apply the Policy: You can apply this policy to Microsoft 365 group-connected, Teams-connected, and non-group connected sites. Users not in the specified group will be unable to access the site or its content, even if they had prior permissions or a shared link.
    3. Monitor Access: Utilize data access governance reports to monitor who has access to the site and ensure compliance with your organization's data governance policies.

    By implementing these steps, you can effectively restrict access to sensitive sites and libraries while allowing the staff member to access the necessary files for their project.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.