How to Restrict OneDrive Folder Access for Specific Users
Question details
An administrator needs to restrict access to individual work data folders, preventing unauthorized users from accessing, deleting, moving, or syncing data locally, while granting a manager full access.
- Product
- Microsoft OneDrive and SharePoint
- Device & OS
- not provided
- Scenario
- Setting up a secure file storage structure for a team where individuals have strictly isolated private folders and managers have full administrative oversight.
- Observed behavior
- Standard OneDrive folder sharing lacks granular permission controls and does not support individual folder passwords, making it unsuitable for this specific administrative requirement.
Ensure you have Microsoft 365 administrator or SharePoint site owner privileges, as advanced permission management requires configuring a SharePoint site rather than relying on personal OneDrive accounts.
Migrate to SharePoint for Granular Folder Permissions
Since personal OneDrive lacks advanced access control and folder password protection, creating a SharePoint site is the recommended approach for managing team folders with strict permission boundaries.
SharePoint is designed for centralized organizational storage and provides the robust permission architecture required for multi-user management, which OneDrive natively lacks.
Log in to the Microsoft 365 Admin Center and create a new SharePoint team site dedicated to the department or team.
Navigate to the 'Documents' library within the new SharePoint site and create separate folders for each individual user.
Select a user's folder, click the 'More options' (three dots) icon, and choose 'Manage access' from the dropdown menu.
Navigate to the advanced permissions settings, choose to stop inheriting permissions from the parent site, and then remove access for all users except the specific individual and the manager.
Grant the individual user 'Contribute' access so they can edit their files, and ensure the manager is assigned 'Full Control' or 'Site Owner' access to oversee all folders.
Create Custom Permission Levels to Restrict Deletion and Syncing
To prevent users from deleting files, moving them, or syncing them locally, you need to create and assign a custom permission level within SharePoint.
Looking for a Seamless Office Alternative?
While managing complex SharePoint permissions requires a Microsoft 365 administration account, you can still empower your team's daily document work with WPS Office. It is a free, lightweight, and fully compatible alternative that works seamlessly with standard Office formats.
- 1. Download WPS Office: Download and install WPS Office on your preferred device.
- 2. Sign In for Cloud Access: Log in to your WPS account to access free cloud storage and seamless file synchronization.
- 3. Open Office Files directly: Open your existing Microsoft Office files directly in WPS Office without any loss of formatting.

Frequently Asked Questions
Can I password protect a specific folder in OneDrive?
No, Microsoft OneDrive and SharePoint do not support password-protecting individual folders. Security is instead managed by assigning user-specific permissions to the folders and relying on the user's account login.
How do I stop users from syncing SharePoint folders to their local drives?
You can prevent local synchronization by creating a custom permission level in SharePoint. Uncheck the 'Use Client Integration Features' option within the advanced permissions settings and assign this restricted level to your users.
Why should I use SharePoint instead of OneDrive for managing team folders?
OneDrive is designed primarily for personal file storage and ad-hoc sharing. SharePoint is built for team collaboration and offers advanced access controls, custom permission levels, and centralized administration, making it necessary for strict multi-user access rules.




