How to Let Users View OneDrive File Listings Without Opening Files
Question details
The user needs to grant access so others can see a list of folders and files in OneDrive or SharePoint, but wants to strictly prevent those users from opening, viewing, or downloading the actual file contents.

- Product
- OneDrive / SharePoint
- Device & OS
- not provided
- Scenario
- Configuring advanced folder sharing and access controls to expose directory structures without compromising file content security.
- Observed behavior
- Standard SharePoint and OneDrive permissions do not offer a built-in standard role that allows listing folders while completely blocking the opening and downloading of files.
Ensure you have Site Owner or SharePoint Administrator privileges, as creating and modifying custom permission levels requires administrative access to the site collection settings.
Create a Custom SharePoint Permission Level
Duplicate an existing permission level and modify it to grant directory browsing while removing the ability to view, open, or download items.
Since OneDrive is built on SharePoint, you can use SharePoint's advanced permissions settings to create a specialized access level. This method allows users to see what files exist without granting them access to the file contents.
Navigate to your SharePoint site (or the SharePoint backend of your OneDrive). Click the gear icon for 'Settings', select 'Site permissions', and then click on 'Advanced permissions settings'.
Click on 'Permission Levels' in the top ribbon. Click on the 'Read' permission level to open its details, scroll to the bottom of the page, and click 'Copy Permission Level'.
Provide a name for the new permission level, such as 'List Directory Only'. In the List Permissions section, uncheck the boxes for 'Open Items', 'View Items', and 'Download'.
Scroll down and ensure that 'Browse Directories' and 'View Application Pages' remain checked so users can successfully load and navigate the folder structure.
Click 'Create' to save the custom permission level. Return to the specific folder or library you want to share, click 'Manage Access', stop inheriting permissions if necessary, and assign this new permission level to your target users.

Looking for a Simpler Document Solution? Try WPS Office
Managing complex SharePoint and OneDrive permissions can be a hassle for everyday tasks. If you need a free, lightweight, and user-friendly alternative to Microsoft Office for creating and managing your team's documents, WPS Office offers excellent compatibility and built-in sharing features without the steep learning curve.
- 1. Download the Software: Visit the official WPS Office website and click the 'Download WPS Office Free' button.
- 2. Install WPS Office: Run the downloaded installer file and follow the straightforward on-screen instructions.
- 3. Start Creating and Sharing: Open WPS Office, sign in to activate your free cloud storage, and effortlessly share your documents with simple view or edit links.

Frequently Asked Questions
Why doesn't OneDrive have a default 'List Folder' permission?
OneDrive is designed primarily for simple sharing scenarios, offering default 'View' or 'Edit' links. For advanced, granular access control such as listing folder contents without viewing, you must utilize the underlying SharePoint advanced permissions framework.
Will this custom permission prevent users from seeing file metadata?
No. Allowing 'Browse Directories' inherently exposes metadata. Users will still be able to see the file names, creation dates, modified dates, and file sizes, even though they cannot open the actual documents.
Can I apply this custom permission to external guest users?
Yes, once the custom permission level is created at the site collection level, it can be assigned to Azure AD guest users just like internal users, provided that external sharing is enabled for your site.
What if a user tries to bypass the folder restrictions?
While the custom permission restricts standard UI access, it might not block every possible API call. For strict security, use Microsoft Purview Information Protection (sensitivity labels) to encrypt the files, ensuring that only authorized users can read the contents regardless of directory permissions.




