How to Prevent SharePoint Users from Moving, Deleting, or Renaming Files
Question details
The user needs to configure SharePoint access so that users have the ability to upload new files, but are entirely restricted from moving, deleting, or renaming those files once uploaded.
- Product
- SharePoint
- Device & OS
- not provided
- Scenario
- Managing document library permissions to ensure data retention and protect the folder structure from accidental or unauthorized modifications.
- Observed behavior
- Default SharePoint contribution permissions allow users to upload files, but simultaneously grant them the rights to edit, rename, move, and delete documents, which violates the desired strict retention policy.
Ensure you have Site Owner or Full Control administrator privileges in your SharePoint environment, as creating custom permission levels and breaking inheritance requires high-level access.
Create and Assign a Custom Permission Level
Create a specialized SharePoint permission level that includes 'Add Items' and 'View Items' but explicitly excludes 'Delete Items' and 'Delete Versions'.
In SharePoint, renaming or moving a file requires 'Delete' permissions, because the system effectively creates a new instance and deletes the old one. By stripping away deletion rights from a custom permission level, you simultaneously prevent moving and renaming.
Click the gear icon (Settings) in the top right corner of your SharePoint site, select 'Site permissions', and then click on 'Advanced permissions settings'.
Click on 'Permission Levels' in the top ribbon. Click on the 'View Only' or 'Read' permission level, scroll to the bottom, and click 'Copy Permission Level'. Name this new level something descriptive, like 'Upload Only - No Delete'.
In the permissions list for your new level, check the boxes for 'Add Items' and 'View Items'. Ensure that 'Delete Items', 'Delete Versions', and 'Edit Items' (if you don't want them editing content) are completely unchecked. Click 'Create' to save.
Navigate to the specific document library or folder you want to restrict. Click the gear icon, go to 'Library settings' (or 'Manage Access' > 'Advanced' for folders), and click 'Stop Inheriting Permissions'.
Select the target user group, click 'Edit User Permissions', remove their current standard permission (like Contribute or Edit), and check the box for your newly created 'Upload Only - No Delete' permission level. Click 'OK'.
Looking for a Simpler Way to Manage Document Collaboration?
While SharePoint offers deep enterprise controls, configuring custom permission levels and managing inheritance can be overly complex for standard teams. If you want a lightweight, secure, and user-friendly way to create, edit, and share documents with easy permission controls, try WPS Office.
- 1. Download and Install WPS Office: Get the free WPS Office suite from the official website and install it on your device.
- 2. Save to WPS Cloud: Create your document and seamlessly save it to the built-in WPS Cloud for secure storage.
- 3. Share with Simple Permissions: Click the 'Share' button and instantly set your link to 'View Only' or 'Editable' without dealing with complex site-level inheritance settings.

Frequently Asked Questions
Why can users still delete files after I applied the custom SharePoint permission?
Users may belong to multiple SharePoint groups (such as Site Members or Owners) that grant overlapping permissions. SharePoint combines permissions, so if they have 'Edit' rights from another group, it will override your restricted custom level. Remove them from those higher-level groups.
Does disabling the 'Delete Items' permission automatically block renaming?
Yes. In the architecture of SharePoint, renaming a file is treated as a deletion of the original file name and creation of a new one. Therefore, revoking deletion rights natively revokes renaming capabilities.
Can I apply this custom permission to a single folder instead of the entire document library?
Absolutely. You can navigate to the specific folder, open its properties, select 'Manage Access', click 'Advanced', and choose 'Stop Inheriting Permissions'. Then, apply your custom permission level to that folder only, leaving the rest of the library unaffected.




