Why Can a SharePoint Visitor Delete Documents with Read Permissions?
Question details
A user with Read and Limited Access permissions is unexpectedly able to delete documents in SharePoint.

- Product
- SharePoint
- Device & OS
- not provided
- Scenario
- A site administrator or owner notices that a file was deleted by a visitor who seemingly only had read-only access to the environment.
- Observed behavior
- The SharePoint visitor successfully deleted a document, bypassing the expected restrictions of their assigned Read and Limited Access permissions.
Ensure you have Site Collection Administrator privileges or are a Microsoft 365 Global Administrator to check detailed permission reports and access compliance audit logs.
Verify Effective Permissions and Sharing Links
Check if the user was inadvertently granted higher permissions through a direct sharing link, overlapping SharePoint groups, or inherited folder permissions.
SharePoint permission structures can be highly layered. Even if a user is assigned to a 'Visitors' group with strictly Read access, they might have higher permissions granted directly to the specific file or folder via a sharing link (e.g., 'Anyone with the link can edit').
Open the SharePoint site and navigate to the document library where the deleted file originally resided.
Click the gear icon (Settings), select 'Site permissions', and choose 'Advanced permissions settings'. Click 'Check Permissions' in the top ribbon, enter the specific user's name, and click 'Check Now' to reveal their true accumulated permission level.
Select the parent folder or a similar file, click the vertical ellipsis, choose 'Manage Access', and review the 'Links' tab for any 'Edit' links that the user might have utilized.

Review the Microsoft 365 Audit Log
Use the Microsoft Purview audit log to identify the exact application context and timestamp of the document deletion.
Open a Microsoft Support Request
If effective permissions are correct and the behavior cannot be reproduced, escalate the issue to Microsoft Support for backend investigation.
Experience Secure and Simple Document Management with WPS Office
If complex permissions in Microsoft 365 are slowing down your workflow, consider switching to WPS Office. It provides a lightweight, highly compatible, and user-friendly alternative to Microsoft Office, featuring intuitive cloud sharing with clear, straightforward access controls.
- 1. Download and Install: Download WPS Office for free from the official website and install it on your PC or mobile device.
- 2. Open Your Office Files: Easily open your existing DOCX, XLSX, and PPTX files directly in WPS Office without formatting loss.
- 3. Share Securely: Utilize WPS Cloud to generate secure sharing links with precise, easy-to-understand viewing or editing permissions.

Frequently Asked Questions
What does the 'Limited Access' permission level mean in SharePoint?
The 'Limited Access' permission level is automatically generated by SharePoint when a user is given access to a specific item (like a single document) inside a library, but not the entire library itself. It allows the user to bypass the library gateway to navigate to their specific item, but it does not inherently grant them permission to edit or delete anything.
Can an 'Anyone with the link' sharing URL override a user's Read permissions?
Yes. If a user utilizes an 'Anyone with the link can edit' URL to access a file, they interact with the document using the elevated permissions granted by that specific link. This allows them to edit or even delete the document, bypassing their standard group-based Read restrictions.
Why would a user be able to delete a file they created if they only have Read access to the SharePoint folder?
In certain customized setups, or if the list/library has specific item-level permissions configured to 'Create items and edit items that were created by the user', users may retain Full Control over their own creations. This allows them to delete their own files despite having severely restricted access to the rest of the library.




