Fix SharePoint Users Losing Site Access After Changing Group Permissions
Question details
Users lose access to a SharePoint site and are prompted to request permissions after their group permission level is changed from Read to Restricted.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Modifying SharePoint group permissions in an attempt to restrict certain user actions on a site.
- Observed behavior
- Users are completely locked out of the SharePoint site and prompted to request access, rather than just experiencing restricted capabilities on the site.
Ensure you have Site Owner or Full Control permissions in SharePoint before attempting to modify group permission levels and inheritance settings.
Adjust Site-Level Permissions and Use Custom Permission Levels
Revert overly restrictive permissions at the site level and create custom permission levels to maintain basic site access while restricting specific actions.
Default restrictive permissions like 'Restricted View' or 'Restricted Read' can be too strict when applied at the top site level, often blocking users from loading necessary site components. To fix this, access should be restored, and restrictions should be applied more granularly.
Navigate to Site Settings > Site permissions to check if 'Restricted View' or 'Restricted Read' is currently applied to the affected SharePoint group.
Temporarily change the affected group's permission back to 'Read' so users can immediately regain basic site access without encountering the access request prompt.
Go to Site permissions > Advanced permissions settings > Permission Levels. Create a new custom level based on 'Read' but uncheck specific actions (such as downloading or printing) according to your security needs.
Instead of restricting the entire site, apply default restrictive permission levels only to specific document libraries or individual files by breaking their permission inheritance.
If users continue to experience access failures after restoring 'Read' permissions, contact your Microsoft 365 administrator to review potential conditional access policies.
Looking for a Hassle-Free Office Suite? Try WPS Office
While SharePoint and Microsoft 365 handle complex enterprise permissions, you might just need a fast, reliable, and straightforward office suite for everyday document editing. WPS Office offers a lightweight, completely free alternative with a highly familiar user interface, meaning zero learning curve for Microsoft Office users while ensuring seamless migration.
- 1. Download the installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the on-screen instructions to complete the fast installation process.
- 3. Open your documents: Launch WPS Office and instantly open your existing Microsoft Office files without worrying about formatting issues.

Frequently Asked Questions
What is the difference between Restricted Read and Restricted View in SharePoint?
Restricted Read allows users to view pages and documents but prevents them from downloading documents or viewing historical versions. Restricted View allows users to view documents in the browser but prevents them from downloading or printing, which typically requires specific server features.
Why does restricting permissions at the site level break user access entirely?
Site-level permissions control access to foundational elements of the SharePoint site, including navigation menus and master pages. Highly restrictive default levels block access to these essential background components, causing users to be completely locked out.
How do I break permission inheritance for a specific SharePoint document library?
Navigate to the specific library, click the Settings (gear) icon > Library settings > More library settings > Permissions for this document library. Click 'Stop Inheriting Permissions' in the top ribbon to apply unique permissions without affecting the entire site.
Can I test SharePoint permissions before applying them to a large group?
Yes, you can use the 'Check Permissions' button located in the Advanced permissions settings ribbon. This tool allows you to verify exactly what access a specific user or group will have on that site or library before finalizing your configuration.




