How to Restrict Project Online Desktop Access by Department
Question details
Users need to ensure that project visibility is strictly limited by department in the Project Professional desktop application, matching the behavior already established in the web app.
- Product
- Project Online
- Device & OS
- not provided
- Scenario
- Administrators are trying to restrict users from viewing other departments' projects within the desktop client.
- Observed behavior
- Security categories, groups, views, and departments work correctly in Project Web App (PWA), but users can still see projects from other departments when connecting via Project Professional.
Verify that your Project Online environment is using Project Permission Mode rather than SharePoint Permission Mode, as advanced department-level security and granular desktop client restrictions require Project Permission Mode to function correctly.
Review Security Categories and Global Permissions
Verify that department-level restrictions are enforced at the database level via Security Categories, rather than just through PWA view filters.
Project Web App (PWA) views can sometimes filter what a user sees without restricting their actual access rights. If a user belongs to a group with global permissions that allow viewing all projects, the desktop application will bypass the PWA view filters and display everything.
Log in to Project Web App as an administrator, click the gear icon in the top right corner, and select 'PWA Settings'.
Under the Security section, click on 'Manage Groups'. Select the group assigned to the affected department users.
Review the Global Permissions for this group. Ensure that overriding permissions like 'View All Projects' or 'Open Project' are not enabled globally, as these will grant access to projects outside their department.
Return to PWA Settings and click 'Manage Categories'. Select the department's category and ensure the project list is strictly defined by the 'Department' attribute under the 'Projects' section.
Audit Desktop Connection Profiles
Ensure users are connecting to Project Professional using the correct PWA profile that enforces your configured permissions.
Need a Simpler Way to Manage Team Projects? Try WPS Office
While complex environments require Microsoft Project Online, many teams find that setting up intricate permission modes is overwhelming. WPS Office provides a free, lightweight alternative with powerful spreadsheet tools that make department-level project tracking easy and secure.
- 1. Download and Install: Download WPS Office for free and install it on your computer.
- 2. Create a Project Tracker: Open WPS Spreadsheet and use one of the many free built-in Gantt chart or project tracking templates.
- 3. Secure by Department: Go to the 'Menu' > 'Document Encryption' to set unique passwords for different department files, ensuring strict access control.

Frequently Asked Questions
Why do permissions work in Project Web App but not in Project Desktop?
Project Web App (PWA) views can filter what users see on the screen without removing their actual database access. If users have global 'Open Project' permissions, Project Professional connects directly to the database and allows them to open those projects, bypassing web-only view filters.
How do I switch to Project Permission Mode?
You can switch permission modes via the Microsoft 365 SharePoint Admin Center. Select the PWA site collection, click on 'Settings', and change the Permission Management setting to 'Project Permission Mode'. Note that switching modes will delete all existing security configurations.
Can I use SharePoint Permission Mode to restrict access by department?
SharePoint Permission Mode maps users to default SharePoint groups and is much simpler, but it lacks granular, attribute-based security. To dynamically restrict project visibility by specific department attributes across both PWA and Project Desktop, Project Permission Mode is required.




