How to Configure Different User Access Levels for SharePoint Lists
Question details
Two user groups require distinct access levels to SharePoint information: one needs full editing access, while the other only needs to view items, add attachments, and comment without editing existing fields.

- Product
- Microsoft SharePoint / Power Apps / Power Automate
- Device & OS
- not provided
- Scenario
- Designing a secure data environment where different teams collaborate on shared information without compromising data integrity or unauthorized editing.
- Observed behavior
- Attempting to solve the issue using separate synchronized SharePoint lists has resulted in infinite synchronization loops and duplicate items.
Ensure you have Site Owner or Full Control permissions on the SharePoint site and the appropriate Microsoft 365 or Power Apps licensing to customize list forms.
Use a Single SharePoint List with a Customized Power Apps Canvas App
The most robust approach is to maintain a single source of truth (one list) and control the user interface dynamically through Power Apps based on user group membership.
By customizing the SharePoint list form with Power Apps, you can evaluate the current user's security group and adjust the DisplayMode of specific fields. This allows restricted users to view data and add attachments while preventing them from editing core information.
Create distinct Microsoft 365 Groups or security groups in your admin center for the 'Full Access' users and the 'Restricted' users.
Navigate to your SharePoint list, click 'Integrate' in the top menu, select 'Power Apps', and then choose 'Customize forms'.
In Power Apps, add the 'Office 365 Groups' data connection so the app can verify the current user's group membership.
Select the data cards you want to protect. Change their 'DisplayMode' property to a conditional formula that checks the user's group. For example: If(IsFullAccessUser, DisplayMode.Edit, DisplayMode.View).
Save and publish the customized form back to SharePoint so it becomes the default experience for users interacting with list items.

Configure Separate Lists with One-Way Power Automate Synchronization
If strict separation of data is required, use distinct lists synced by a carefully designed one-way Power Automate flow to prevent synchronization loops.
Looking for a Lightweight Office Solution? Try WPS Office
While SharePoint and Power Apps handle complex data workflows, everyday document creation and team collaboration shouldn't be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for your word processing, spreadsheet, and presentation needs.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your Windows, Mac, or Linux operating system.
- 2. Install WPS Office: Run the downloaded setup file and follow the quick on-screen instructions to complete the installation.
- 3. Open and Edit Your Documents: Launch WPS Office to instantly open your existing Microsoft Office files and start collaborating without formatting issues.

Frequently Asked Questions
Can I use filtered views in SharePoint to secure data from certain users?
No, filtered views only hide data in the user interface and are not a security boundary. Users with list access can still view all items by creating their own views or accessing the data via the SharePoint API.
Why is my Power Automate flow creating duplicate items in synchronized lists?
This typically occurs when two-way synchronization is configured without proper loop-prevention logic or unique identifiers. The flow triggers an update in List B, which in turn triggers a flow to update List A, creating an infinite loop.
How do I check a user's security group in Power Apps?
You can use the Office 365 Groups connector in Power Apps. By evaluating if the current user's email exists in the specific group, you can dynamically adjust the DisplayMode settings of your form controls.
Can users add attachments to a SharePoint list without editing the main fields?
Yes. By customizing the list form with Power Apps, you can set the primary data fields to 'View' mode while keeping the attachments control in 'Edit' mode, allowing users to upload files without modifying core data.




