How to Manage Microsoft Lists Permissions for Internal and External Items
Question details
The user needs a way to restrict visibility in Microsoft Lists so that internal employees can view all records, while external clients can only see items specifically marked as External.

- Product
- Microsoft Lists
- Device & OS
- not provided
- Scenario
- Sharing project trackers or databases with both internal staff and external clients without exposing confidential internal records.
- Observed behavior
- Microsoft Lists does not support field-based item permissions. Additionally, filtered views do not create a security boundary, meaning users can bypass views to see hidden items.
Ensure you have Site Owner or Full Control permissions on your SharePoint site or Microsoft Lists environment to create new lists and manage sharing permissions.
Use Separate Lists for Internal and External Data
Because Microsoft Lists does not support conditional field-based security, maintaining separate lists is the only secure method to isolate internal data from external clients.
Microsoft Lists currently operates permissions at the site, list, folder, or individual item level. It cannot restrict access dynamically based on a column's value (such as a 'Visibility' field set to 'External').
To properly secure your data, you must physically separate the records into two different lists with distinct access controls.
Create your primary Microsoft List that contains all records. Do not share this list with any external clients. Only grant access to your internal employees.
Create a second list with a duplicate structure (columns and formats) specifically for client-facing data. You can do this easily by selecting 'From existing list' when creating a new list.
Go to the newly created External List. Click on 'Settings' (gear icon), select 'List settings', and then 'Permissions for this list'. Stop inheriting permissions and grant access only to the external clients.
Manually add external-facing items to the External List, or use Power Automate to automatically copy items from the Internal List to the External List when a specific 'External' flag is triggered.

Avoid Using Filtered Views for Security Boundaries
It is crucial to understand why using filtered views or visibility columns is not a viable security solution in Microsoft Lists.
Looking for a Free, Lightweight Office Suite? Try WPS Office
While you manage your data structures in Microsoft Lists, you might also need a reliable suite for your documents, spreadsheets, and presentations. WPS Office is a powerful, free alternative to Microsoft Office that is fully compatible with your existing files.

Frequently Asked Questions
Can I use filtered views to restrict access in Microsoft Lists?
No. Filtered views do not act as security boundaries. Anyone who has permission to view the list can bypass the filter by creating their own view or accessing the list via SharePoint APIs to see all items.
Does Microsoft Lists support field-based item permissions?
Currently, Microsoft Lists does not support dynamically restricting access based on a specific field or column value (e.g., hiding items unless marked 'External'). Permissions can only be managed at the site, list, folder, or item level.
How do I share a Microsoft List with external users safely?
The safest method is to create a dedicated list solely for external data. Go to 'List settings' > 'Permissions for this list', break the permission inheritance, and explicitly invite the external users using their email addresses.




