locked
SharePoint 2010 application is accessible for the user not added in Site Permission, How to restrict it? RRS feed

  • Question

  • Hi All,

    I have enable FBA authentication to the SharePoint 2010 application. The newly created users are inserted into aspnetdb. 

    In my scenario, the SharePoint application is accessible for the newly created user. I did not add the user explicitly to "Site Permission". How is it possible? 

    Please suggest me on it.

    Aspnetdb user directly can access the SharePoint site without adding the user into Site Permission. I want to restrict it. 

    Note: The user can access to see and change the site collection administrator settings. It should not be. 

    Thanks & Regards

    Suresh



    Wednesday, June 10, 2020 10:16 AM

All replies

  • check the permissions at Site Level and Site Collection Admin Level by checking from the top ribbon in Site Permissions called "Check Permissions" and see what permissions he has and try to remove the access from there where it shows.

    Thanks & Regards,


    sharath aluri

    Wednesday, June 10, 2020 11:30 PM
  • Hi Suresh,

    How did you inserted the users to aspnetdb and what roles did you assign to them?

    You can refer to the link below and check if you have added the users to the right group and given them the corresponding privilege.

    Step by Step – Configure SharePoint 2010 Forms Based Authentication with SQL.

    See the section “Add SQL Users and Roles for FBA” and “Configure the SharePoint Authorization and Verify the Access for the both AD (Windows) and SQL(Forms Based) Users”.

    You can also check if there are unnecessary permissions to SQL user/groups via Central Administration > Application Management > Manage web applications > select the web application > User Policy.

    Disclaimer: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.

    Best regards,

    Chelsea Wu


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    SharePoint Server 2019 has been released, you can click here to download it.
    Click here to learn new features. Visit the dedicated forum to share, explore and talk to experts about SharePoint Server 2019.

    Thursday, June 11, 2020 2:17 AM
  • Hi Sharath,

    For your kind information. I did not add the user into SharePoint portal. The user not in any user group. I have created user and its available in aspnetdb. 

    The user Just in aspnetdb but the user is having full access in the site.

    Thanks & Regards

    Poomani Sankaran

    Thursday, June 11, 2020 4:49 AM
  • Hi Suresh,

    Does my reply help you in any way?

    Please double check the roles assigned to users when adding them to the aspnetdb database.

    You can add a new user using MembershipSeeder tool and see if you can reproduce this issue.

    Best regards,

    Chelsea Wu


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    SharePoint Server 2019 has been released, you can click here to download it.
    Click here to learn new features. Visit the dedicated forum to share, explore and talk to experts about SharePoint Server 2019.

    Friday, June 12, 2020 1:48 AM