The steps and interface descriptions in this guide reflect Microsoft 365 as it works at KAUST today. Microsoft updates these tools regularly, so the screens you see may look slightly different over time. The underlying concepts and permissions model described here remain consistent.
OneDrive, SharePoint, Microsoft Teams, and Microsoft Planner are not four separate products. They are four different interfaces built on top of a shared membership layer called a Microsoft 365 Group. Understanding how they connect is the most important thing in this guide.
The Microsoft 365 Group: the invisible backbone
When a Team, a SharePoint team site, or a Planner board is created, Microsoft quietly creates a Microsoft 365 Group underneath it. The Group holds the membership list. The SharePoint site, Teams workspace, Planner board, and shared Outlook mailbox all look at that same list to decide who gets access.
Add someone to the Group or Team and they get access to the SharePoint site, Planner board, and Teams workspace all at once. This is the most common source of accidental oversharing at KAUST.
OneDrive is your personal work storage at KAUST. Think of it as your digital desk: what lives there is yours until you deliberately share it. Every KAUST account holder, regardless of whether they are staff, faculty, a researcher, or a student, gets OneDrive automatically the moment their account is created.
Key fact: OneDrive is provisioned automatically. You do not need to request it. You receive 50 GB by default, accessible at onedrive.com or through the Microsoft 365 portal at m365.cloud.microsoft.
Use OneDrive for
Draft documents still in progress. Personal notes and working files. Temporary collaboration with one or two colleagues. Files that belong to you as an individual.
Do not use OneDrive for
Department files that others need long-term. Research group shared content. Team documents that should survive your departure. Anything that genuinely belongs to a group, not a person.
If files only live in your OneDrive and you leave KAUST, your colleagues have a 60-day window to retrieve them before Microsoft permanently deletes them. Team content belongs in SharePoint.
Files shared weeks or months ago often quietly stay shared long after they need to be. Two tools help you keep on top of this.
The Shared by Me view
Shows everything you have actively shared, and who it is shared with. Start here for a broad overview.
Open OneDrive on the web.
Select Shared from the left navigation.
Select the Shared by Me tab.
If anything on that list surprises you, it is worth reviewing.
Manage Access (for a specific file or folder)
Shows the sharing links created for that item AND any individuals with direct access. Use this for a detailed view.
Locate the file or folder in OneDrive on the web.
Right-click it and select Manage Access, or select it and choose Manage Access from the toolbar.
Review both the Links section and the People section.
When sharing from OneDrive, you make two decisions: who can access the file, and what they can do with it.
Who can access
Anyone
No sign-in. Forwardable. 90-day max expiry. Public content only.
People in KAUST
Requires KAUST account and sign-in. Suitable for broad internal content.
Specific People
Named individuals only. Wrong person gets the link? It will not work for them.
Direct Access
No link. Add via Manage Access only. Most controlled. Best for Restricted content.
What they can do
| Permission | What they can do | Note |
|---|---|---|
| Can edit | Open, change, save, delete | Edits affect the original file |
| Can review | Comment and suggest edits only | Word, Excel, PowerPoint only. Not folders or PDFs. |
| Can view | Read only. Can still download. | Add block download separately if needed |
| View, no download | Browser view only. No download, print, or sync. | Screen captures are always possible |
Temporary sharing has a way of becoming permanent. A contractor reviews a document. The work ends. The access stays. Set an expiry date at the point of sharing, not as an afterthought. If the person needs access for longer, they can ask, which is a much healthier dynamic.
When creating a new link
Select Share on the file or folder.
Select the Link Settings icon (gear icon) in the sharing dialog before copying the link.
Under Expiration Date, choose a date that reflects how long access is genuinely needed.
Save settings and share the link.
Updating an existing link's expiry
Open Manage Access for the file or folder.
Under Links, find the link you want to update.
Select the three dots next to it and choose Change Expiration Date.
Set the new date and save.
Microsoft enforces a maximum 90-day expiry on Anyone links across all Microsoft 365 tenants. Even so, 90 days is still a long time for an open, sign-in-free link to exist. Delete it as soon as it is no longer needed.
Good practice is to review your shared files periodically. The Shared by Me view takes less time to check than most people expect. Here is how to remove access when you find something that should not still be shared.
Remove a specific person
Open Manage Access for the file or folder.
Under People, find the person.
Select their permission level (Can Edit or Can View).
Choose Remove Access and confirm.
Access is revoked immediately. The person is not notified.
Delete a sharing link
Open Manage Access for the file or folder.
Under Links, find the link you want to remove.
Select the X next to it and confirm.
Deleting a link ends access for everyone who had it. Anyone links cannot be revoked for individual recipients.
When a KAUST account is removed from Active Directory, Microsoft preserves that person's OneDrive for 60 days. During that window, their manager or a designated delegate receives an automated notification and can access and move the files. After 60 days, the OneDrive and everything in it is permanently deleted.
Files stored only in a personal OneDrive are at risk. If important team or department files live in one person's OneDrive and that account is removed, the 60-day window is easy to miss. Team content belongs in SharePoint.
Before leaving KAUST
Move team or department files to the correct SharePoint site. Confirm with your manager which files need to remain accessible. Complete moves before your final working day.
For managers and team leads
When a team member moves on, review their Shared by Me view during the 60-day window. Copy required files into the appropriate SharePoint site. Make sure ongoing team content is not stranded in personal storage.
SharePoint is Microsoft 365's platform for content that belongs to a team, department, or project, and needs to remain accessible regardless of who comes and goes. All SharePoint sites at KAUST include 100 GB of storage by default.
Key fact: SharePoint sites at KAUST must be requested through KAUST IT. They are not self-service. This is a deliberate governance decision.
Team Site
Connected to a Microsoft 365 Group. Designed for active collaboration. When a Teams workspace is created, a team site is automatically created behind it. Comes with a document library, Planner board, shared mailbox, and OneNote, all tied to the same group membership.
Communication Site
Not connected to a Group. Designed for one-to-many publishing such as news, guidance, and policies. No associated Planner or Teams space. Permissions managed directly in SharePoint, not through group membership.
All new SharePoint sites must be requested through KAUST IT at it.kaust.edu.sa/about/contact-us. Before you contact IT, have the following information ready.
| Item | What to provide | Example |
|---|---|---|
| Site name | Clear, durable name | Graduate Funding Portal |
| Preferred URL | kaust.sharepoint.com/sites/Name | kaust.sharepoint.com/sites/GradFunding |
| Purpose | What the site is for | Shared workspace for funding documents |
| Site owners | At least two KAUST email addresses | name@kaust.edu.sa |
| Members and access | Who needs access and at what level | Team A: Member; Team B: Visitor |
| External sharing | Any external domains needed | aramco.com or None |
Every site should have at least two owners from the start. If one owner leaves or changes role, the other can continue to manage the site without it going unmanaged.
Every SharePoint site comes with three built-in permission groups. For most sites, these three groups are all you need.
Owners
Full Control. Manage settings, people, libraries, and permissions. The site is their responsibility.
Keep this list small and intentional. Too many owners = no clear owner.
Members
Edit permissions. Upload, change, and delete content. Regular contributors.
Cannot manage site settings or other people's access.
Visitors
Read only. View files and pages without making any changes.
Right for audiences who need access to information but not to contribute.
Permission levels behind each group: Owners get Full Control (everything), Members get Edit (add/change/delete content), Visitors get Read (view only). Custom permission levels exist but for most sites the defaults are cleaner and easier to maintain.
How you add members depends on whether your site is connected to a Microsoft 365 Group (most team sites) or standalone (communication sites).
Group-connected team sites (recommended approach)
Manage access through the Group. Adding or removing someone from the Group updates their SharePoint, Teams, and Planner access simultaneously.
Open the SharePoint site.
Select the Settings gear, then Site permissions.
Select Add members and enter their name or KAUST email.
Choose Owner or Member. For read-only Visitor access, add them directly to the Visitors group instead.
Adding as Visitor directly (not through the Group) gives SharePoint access only. They will not appear as a Team member and will not get Planner access. This is intentional for read-only audiences.
Communication sites
Not connected to a Group, so all access is managed directly through SharePoint groups. Add the person to the Owners, Members, or Visitors group as appropriate through Site permissions.
Removing someone: Go to Site permissions, find the person, and remove them. For a Group-connected site, removing through the Group removes their SharePoint, Teams, and Planner access all at once.
By default, permissions flow from the top of a site down to everything below it. You set access in one place and it cascades everywhere.
Change the site permissions and it cascades down through everything that inherits.
Key fact: Breaking inheritance on a library means it stops following the site's permissions and manages its own. Changes at the site level no longer affect it. You must manage it independently from that point.
Good reasons to break inheritance
One library has content that only a smaller group should see. A library should be read-only while the rest of the site is editable. Leadership, HR, or financial documents in a shared general site.
Avoid breaking inheritance on
Individual scattered files and folders. Items where a separate library would work better. Anything creating a permissions map nobody can maintain.
How to break inheritance on a library
Open the document library.
Open Settings, then go to Permissions for this document library.
Select Stop inheriting permissions and confirm.
The library now has its own independent permissions. Review and adjust access before anyone relies on it.
A document library is the primary container for files on a SharePoint site. Every site has at least one default library, usually called Documents. You can create additional libraries for different purposes.
Good uses for separate libraries
Financial or HR documents with tighter access. Published reference materials that should be read-only. A specific project with its own membership.
What each library can have
Its own permissions (break inheritance). Its own column structure and views. Its own versioning settings. A clearly named access group.
Best practice for sensitive content: Create a dedicated library, break inheritance on it, assign access to a clearly named group, and keep the number of permission exceptions low. Do not scatter sensitive files across a general library and try to protect individual items individually.
Restoring inheritance
To return a library to following the site-level permissions, open its Permissions page and select Delete unique permissions. This removes any custom permissions you set on that library and everything inside it will revert to the site defaults.
The Check Permissions tool lets you verify exactly what a specific person can access on a SharePoint site, and where that access comes from.
Go to Site permissions from the Settings gear.
Select Check Permissions.
Enter the person's name or email address.
SharePoint will show every permission level they have and whether it comes from a Group, a direct SharePoint assignment, or inheritance.
This is the most reliable way to audit access for one specific person without manually checking every group and library. Use it whenever you need to confirm or dispute what someone can see.
Scenario where this is useful
A colleague says they cannot access a library you thought they had access to. Run Check Permissions on their account to see exactly what they have, and identify whether the gap is at the site level, the library level, or from a broken inheritance chain.
By default, SharePoint sites at KAUST do not allow external access. The platform is configured for internal collaboration unless IT specifically enables external access for a site.
Do not attempt to share a SharePoint site externally without contacting IT first. External access must be enabled and scoped to specific approved domains before any external sharing works.
Collaborating with external partners
Contact KAUST IT and specify the domains you need access for, for example aramco.com or kfupm.edu.sa. IT will enable access scoped only to those domains. Not opened broadly.
Anyone access on SharePoint
Technically available but requires a strong academic or business justification. Subject to review by IT and Information Security. Approach with caution and only when genuinely necessary.
IT provides the platform and manages the sharing settings. Site owners are responsible for what is uploaded to their sites and how it is shared once external access is enabled.
A Team is a collaboration workspace for chat, meetings, files, and channels. But there is something important running underneath every Team that most people never see.
Key fact: Every Team is backed by a Microsoft 365 Group. The Group is the shared membership layer. It controls access to the Team, the connected SharePoint site, the Planner board, and the shared Outlook mailbox, all at once.
What you get when you add someone to a Team
The most common source of accidental oversharing at KAUST: someone is added to a Team so they can attend one meeting. They now have full access to every file in the connected SharePoint site. If that content includes Restricted data, this is a real problem. Adding someone to a meeting does not require adding them to a Team. Send them a meeting link directly instead.
Teams at KAUST are not self-service. All new Teams must be requested through KAUST IT at it.kaust.edu.sa/about/contact-us. This is a deliberate governance decision to prevent unchecked sprawl and orphaned workspaces.
| Information needed | What to provide |
|---|---|
| Team name | A clear and purposeful name |
| Purpose | What the Team will be used for |
| Owners | At least two people always. If one leaves, the other keeps things running. |
| Initial members | Who should be added at launch |
| External access | Whether external collaborators are needed and who |
Create a new Team when
The group has fundamentally different membership from any existing Team. The collaboration is long-term. The group genuinely needs its own separate space.
Create a new channel instead when
Same people, new topic or sub-project. The discussion fits within the scope of the existing Team. A new Team would create unnecessary sprawl.
Standard channels are visible to every member of the Team. They are where most day-to-day collaboration should happen and where most files should live.
Key fact: Files uploaded to a standard channel are stored in the Team's connected SharePoint site, in the Documents library, in a folder named after the channel. A channel called Research Data stores files in a SharePoint folder called Research Data.
Visibility
All Team members can see all standard channels and their content.
File storage
Files go to the Team's main SharePoint site. Accessible directly in SharePoint by any Team member.
Limits
Up to 1,000 standard channels over the lifetime of a Team.
Apps supported
Planner, Forms, Stream, OneNote tabs, and many third-party apps.
For most Teams and most teams of people, standard channels are all that is needed. Private and shared channels introduce significant complexity and should be used only when there is a genuine reason for them.
Private channels are for conversations and collaboration that should not be visible to the entire Team. Only the people specifically invited can see the channel or know it exists.
Critical: Every private channel gets its own completely separate SharePoint site collection. Not a folder in the Team's main SharePoint. A completely separate site. Being a Team owner does NOT give you access to a private channel's SharePoint site unless you are also a channel member.
How private channel storage actually works
Team's main SharePoint site
Standard channel files. Accessible to all Team members.
Private channel SharePoint site
Completely separate site. Only channel members can access. Even Team owners are excluded unless added.
Good uses for private channels
Leadership or management discussions. Sensitive workstreams for a subset of the Team. Confidential coordination that should not be visible to the wider group.
Limitations to know
Guests cannot create private channels. Planner, Forms, and Stream tabs are not supported. Cannot be converted to a standard channel. Maximum 30 per Team.
Shared channels let you collaborate with people from outside KAUST without making them full guests in your KAUST tenant. Like private channels, every shared channel gets its own separate SharePoint site.
Key fact: External participants in a shared channel appear with their own organisation's accounts, not guest accounts in KAUST's tenant. They only see the shared channel. Nothing else in the Team or the KAUST environment is visible to them.
| Feature | Guest access (standard channel) | Shared channel |
|---|---|---|
| How they appear | Guest account in KAUST tenant | Own organisation's account |
| Visibility | Sees all standard channels they are in | Only sees the shared channel |
| File storage | Team's main SharePoint site | Shared channel's own separate SharePoint site |
| Permissions | Managed in Teams | Cannot be managed independently in SharePoint. Teams controls it. |
For an ongoing, structured collaboration with an external organisation, shared channels are generally cleaner than guest access. For a one-time meeting with external people, send a meeting link. They can join without being added to the Team at all.
One of the most important things to understand in Teams, and one of the most frequently misunderstood: where your files actually go depends entirely on where you share them.
| Where you share | File stored in | Who can access |
|---|---|---|
| Standard channel | Team SharePoint site | All Team members |
| Private channel | Private channel's own SharePoint site | Channel members only |
| Shared channel | Shared channel's own SharePoint site | Channel members only |
| 1:1 or group chat | Sender's OneDrive for Business | Chat participants only |
| Channel meeting recording | Channel's SharePoint site | All channel members |
| Personal meeting recording | Organiser's OneDrive | Organiser manages sharing |
Files shared in a 1:1 or group chat live in the sender's OneDrive. If that person leaves KAUST, those files enter the 60-day deletion window. For files the team needs to keep, upload them to a channel instead of sharing them in a chat.
Because Teams, SharePoint, and Planner share the same Group membership, how you manage membership matters as much as who you add.
Manage membership through Teams, not directly in SharePoint. Adding someone directly to the SharePoint Members or Owners group without going through Teams can cause sync issues. They may end up with SharePoint access but not appear as a Team member.
Adding a member
Open the Team.
Select the three dots next to the Team name.
Select Manage team or Add member.
Enter the person's name or KAUST email, then choose Member or Owner.
Removing a member
Open the Team and select Manage team.
Find the person and select Remove.
Removing someone from a Team does NOT remove them from private channels. Private channel membership must be managed separately within each private channel.
| Role | What they can do |
|---|---|
| Owner | Add and remove members, create and delete channels, manage Team settings, delete the Team. Every Team must have at least two owners at all times. |
| Member | Post in channels, upload files, attend meetings. Can create private channels if the owner permits. |
Teams supports several models for working with people outside KAUST. Choosing the right one matters both for usability and for keeping data appropriately contained.
Adding external guests to a KAUST Team
A guest is a named individual from outside KAUST invited into the Team. They get access to standard channels and, as a consequence of being in the Team, access to the connected SharePoint site. Review what is in the SharePoint site before adding guests. Restricted content should be in a library with separate permissions before any guest arrives. Guests cannot create private channels.
KAUST people in an external Team
When a KAUST person is invited as a guest into a Team hosted by another organisation, they use their KAUST credentials. They can only access the channels they are invited to. Files they access live in that organisation's SharePoint, not in KAUST's environment. Files they share from their KAUST OneDrive remain in their KAUST OneDrive.
Shared channels across organisations
External participants in a shared channel use their own organisation's accounts. They only see the shared channel. No visibility into the rest of the Team or KAUST's environment. Permissions cannot be managed independently in SharePoint: Teams controls access entirely. Removing someone from the shared channel removes their access to the channel's SharePoint site.
For a one-time meeting with external attendees: Send a Teams meeting link. They join as external participants without being added to the Team. No SharePoint access implications at all.
Things that work well
Use channels for anything the whole team might need to find later. Channel content is searchable and persistent.
Make sure at least one Team owner is a member of each private channel to maintain governance visibility.
Keep at least two owners on every Team and review membership when people change roles.
For one-time meetings with external people, send a meeting link rather than adding them to the Team.
Things to avoid
Adding someone to a Team just so they can attend one meeting. Send a meeting link instead.
Storing important files only in chat. Files in 1:1 and group chats go to the sender's OneDrive and are at risk if that person leaves.
Creating a new Team for every project. Ask whether a channel inside an existing Team would work just as well.
Assuming auditing a Team's content means checking only the main SharePoint site. Private and shared channels each have their own separate sites.
Microsoft Planner is a visual task management tool that lets you create tasks, assign them to people, set due dates, and track progress using a drag-and-drop board. It is built for lightweight project and task coordination.
Key fact: Planner Basic is available to every KAUST account holder through Microsoft 365. No request and no additional license is needed. Access it at planner.cloud.microsoft or directly inside Teams by adding a Planner tab to a channel.
What you can do with Planner Basic
Create and assign tasks, set due dates, drag-and-drop board view, file attachments, comments, and integration with Teams, Outlook, and Microsoft To Do.
When Planner fits well
Team to-do lists, simple group project tracking, personal work organization, task coordination alongside a Teams channel.
This is the most important thing to understand about Planner. Every Planner board is connected to a Microsoft 365 Group, and that connection has real access implications.
At KAUST, standalone Planner boards are not permitted. All Planner boards must live within an existing Group. You cannot create a Planner board without a Group behind it.
The cross-grant access chain
Adding someone to a Team also gives them Planner access. Adding them to Planner also gives them SharePoint access. The three tools share one membership layer.
Files attached to Planner tasks
Files attached to Planner tasks are stored in the linked Group's SharePoint document library, in a folder called Planner. Accessing them in SharePoint requires the same level of access as the rest of the site.
Being added directly to a SharePoint site without being in the underlying Group does not automatically grant Planner access. Planner access comes from Group membership. This is a common source of confusion when people can see a SharePoint site but cannot access the Planner board linked to it.
| Feature | Basic | Premium |
|---|---|---|
| Task creation and assignment | Yes | Yes |
| Board view | Yes | Yes |
| Teams and Outlook integration | Yes | Yes |
| Timeline (Gantt) view | No | Yes |
| Task dependencies | No | Yes |
| Custom fields and labels | No | Yes |
| Visual progress dashboards | No | Yes |
| License required | Included | Project Plan 5 |
To request Planner Premium: go to m365requests.kaust.edu.sa and request the Planner and Project Plan 5 license. Include a short explanation of how it will support your work. The request routes to your line manager for approval.
Because all Planner boards must live within an existing Group, you have two routes depending on your situation.
Route 1: A Team or SharePoint site already exists
Ask the Team owner to add a Planner tab to a channel. This creates a Planner board inside the existing Group. No IT request is needed.
Open the Team and go to the relevant channel.
Select the + (Add a tab) in the channel tabs.
Search for Tasks by Planner and To Do and add it.
Choose to create a new plan or attach an existing one.
Route 2: No existing Group yet
Submit a request through VITA at vita.kaust.edu.sa. KAUST IT will set up the Group and Planner board together.
Include in your request:
Name and purpose of the board
Who should be the owner
Who should be members
Good data governance across OneDrive, SharePoint, Teams, and Planner comes down to consistent habits applied at the right moments.
When someone joins your team
Add them through Teams, not directly through SharePoint. Adding through Teams updates their access to SharePoint, Planner, and the Teams workspace simultaneously. If they only need read-only access to a site without full Team membership, add them to the SharePoint Visitors group directly.
When someone changes role or moves to a new team
Their access from their previous role does not update automatically. Review what they had access to and remove or adjust anything that no longer fits. For private channels they were in, remove them separately. For SharePoint sites added directly, check and update those too.
When a project ends
Take five minutes to review the Team and SharePoint site membership. Remove anyone involved on a temporary basis. Check whether the Team is still actively needed or should be archived. Teams that sit unused with active membership and open permissions are a governance risk.
When adding external collaborators
Before adding a guest to a Team, review what is in the connected SharePoint site. Restricted content needs to be in a library with separate permissions before the guest arrives. For one-time meetings, send a meeting link rather than adding the person to the Team.
When deciding where to store files
Ask whether the file belongs to you as an individual or to the team. Personal drafts go in OneDrive. Team-owned, long-term content goes in SharePoint or a Teams channel. Files shared in a chat stay in the sender's OneDrive and are at risk if that person leaves.
When reviewing permissions
Use Check Permissions in SharePoint to verify what a specific person can access. Use the Shared by Me view in OneDrive to see everything you have actively shared. Do both periodically, not only when something goes wrong.
When content is sensitive or Restricted
Keep Restricted content out of general document libraries. Create a dedicated library, break inheritance so it has its own separate permissions, and assign access only to the people who genuinely need it. Do not scatter sensitive files across a general library and try to protect them individually. If external sharing of Restricted content is ever needed, consult IT first.
The general principle
Use the most restrictive option that still lets the work get done. If Specific People works, use it instead of People in KAUST. If a channel post works, use it instead of a chat. If read-only works, use it instead of edit. Access should reflect genuine need, not convenience at the point of granting it.