User accounts inherit SharePoint Online permissions through SharePoint Online roles and SharePoint Online groups. SharePoint Online groups are always defined for one site collection in this way. SharePoint Online roles are defined for sites. They are assigned to groups, and the user accounts that are members of these groups inherit SharePoint Online permissions through them. SharePoint Online roles can also be assigned directly to user accounts. User account permissions on individual sites in a site collection are restricted through the SharePoint Online roles that are assigned to it.
In SharePoint Online, the users can have different entitlements that are mapped in One Identity Manager as follows:
-
Entitlement for the use of SharePoint Online groups (O3SGroup table)
-
Entitlement for the use of SharePoint Online roles (O3SRLAsgn)
Terms
-
A SharePoint Online Role is the permission level linked to a fixed site.
-
The assignment of user account or groups to a SharePoint Online role is called a role assignment.
-
Entitlement assignments refer to the assignment of the various entitlements to user accounts. These include:
-
Group assignments to user accounts (O3SUserInGroup table)
-
Role assignments to user accounts (O3SUserHasRLAsgn table)
-