Validating File Attachments in Sharepoint list(people and group)

Posted on 2011-04-19
Last Modified: 2012-05-11
I have following need.

1)In People and group list in Sharepoint i am able to upload .txt files with malicious attachments.

Login > Site Actions > Site Settings > People and Groups > Click on any user > Click Edit Item > Click Attach File > Click Ok

2)To prevent it i need to either

  a)Completly disable the attchments in the User Information list.In that case none of the user including Admin will be able to upload files.
 b)Allow attachments to some perticular users by assigning permissions or something but not to other normal users.

  Is it possible to create any permission levels or something in User information list allowing  File attchments only for couple of users as opposed to disabling it for all users.

3)To mention i have no access to code and i am required to do tis only in Browser in form of configuration and settings.

Question by:sukeshjh
    LVL 2

    Expert Comment

    Well, What if only specific user/group can download the attachmnet? Will that work for you?
    We can do that easily.


    Author Comment

    Hi AmitKB,
    It is not about downloading attachments.I have to disable attaching malicious files to list item.Even if Sharepoint prevents users attaching files of extensions .exe but still there is chance for malicious users attaching text files which have  executables.

      Except a few admin users nobody else should have permissions  to attach files to People and group.

    As People and group(User information list) is a list.If you can find me a general solution for doing the same for sharepoint list in Admin side i think the same will go fine with User information list.
    LVL 2

    Accepted Solution

    You can attach a workflow using SharePoint designer to that list for new item created and updated.
    Whenever those two events occurs you can delete the attachment or do the rollback.

    I don't know how to get "People and Group" list to attach the workflow.

    Author Closing Comment

    Partial Solution.Did not provide correct details to approach.trobleshoot the problem and solving while staying within the constraint.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Pimping Sharepoint 2007 without Server-Side Code Part 1 One of my biggest frustrations with Sharepoint 2007 in the corporate world is that while good-intentioned managers lock down the more interesting capabilities of Sharepoint programming in…
    On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    7 Experts available now in Live!

    Get 1:1 Help Now