What is the check effective rights tool in Project Online?
Understanding why a user can or cannot perform an action in Project Online can be challenging, especially in environments with complex permission structures. Microsoft Project Online uses a group-based security model that combines global permissions, category permissions, and security groups. When a user reports that they’ve lost access to a project, resource, or view, or if their permissions don’t seem to align with expectations – it’s not always clear where the problem lies.
This is where the check effective rights feature becomes essential. It’s designed to provide project administrators and PMO leads with a detailed overview of what access a user actually has, and through which group or category those rights are granted. Instead of manually combing through group assignments or second-guessing permissions, this tool gives a centralised view of effective access across global and category scopes.
Where to find check effective rights in Project Web App (PWA)
To use this feature, you’ll need to be working in Project Permission Mode, as SharePoint Permission Mode does not support this functionality.
To access the check effective rights tool:
-
Go to PWA Settings
-
Click on Manage Users
-
Select the individual user you want to check (note: only one user can be selected at a time)
-
Click the Check Effective Rights button in the ribbon
This will open a dedicated page where you can view the user’s rights across global and category levels.
How global permissions are displayed and interpreted
Global permissions define what actions a user can take across the entire PWA environment. These permissions are assigned at the group or individual user level and affect areas such as project creation, resource management, view access, and administrative functions.
On the effective rights page:
- The global permissions tab will be shown by default
- Permissions are organised by function (such as Project, Resources, Timesheets, Status Reports)
- Each permission will indicate whether the user has it, and if so, through which security group it is granted
Clicking on a group name will open its full details, allowing you to see the complete list of permissions assigned to that group. If a user is a member of multiple groups with overlapping permissions, you’ll see duplicates listed under each group.
This view can also be collapsed by section for easier navigation, particularly when reviewing a long list of permissions.
How category permissions differ and why they matter
Unlike global permissions, category permissions are context-specific. They control access to individual projects, resources, and views — meaning a user may have permissions in one context but not another, depending on their group membership and the categories linked to those groups.
Category permissions are divided into three views within the effective rights tool:
Project category permissions
To view project-specific access:
-
Select Category Permission – Project from the dropdown
-
Choose a project from the available list
-
The page will then display a list of permissions the user has for that project, and the categories through which those rights are granted
This is especially useful if a user can access some projects but not others, or if their editing rights vary between projects.
Resource category permissions
To check access to enterprise resources:
-
Select Category Permission – Resource
-
Pick a resource from the list
-
The tool will display what the user can do with that resource (e.g., view assignments, modify details, approve timesheets)
If you’re troubleshooting why a user can’t see or interact with resource information, this is the view to use.
View category permissions
This section helps identify whether a user has access to particular views in areas like the project center or resource center.
-
Select Category Permission – View
-
Choose a view type from the dropdown (such as Project Center View or Resource Center View)
-
You’ll see the list of available views, whether the user has access to each, and through which security category
This is helpful when views are restricted based on business units, project types, or custom reporting needs.
Why users should not be assigned directly to security categories
Project Online operates most effectively when permissions are structured through groups and categories, not direct assignments. Microsoft recommends that users are assigned only to security groups, and groups are then associated with security categories. This layered model allows for scalable and maintainable access control.
Assigning users directly to categories bypasses this structure and can lead to fragmented access, troubleshooting difficulties, and policy violations. Instead, always assign users to well-named security groups that map to defined roles (such as project manager, team member, portfolio viewer).
Examples of how to use check effective rights during troubleshooting
Here are a few common scenarios where check effective rights proves invaluable:
- A team member reports they can no longer access their project in the project center
- A project manager can’t edit their own project schedule
- A user with multiple roles has inconsistent access between projects
- Views disappear after a user’s group membership is updated
- New hires aren’t able to see expected views or reports
Rather than guessing which group or category is responsible, check effective rights shows you exactly where the permission is or isn’t coming from. It also highlights when there’s a mismatch between expected access and group configuration.
Best practices for managing permissions in Project Online
While the check effective rights tool is helpful, it’s even better to avoid permissions confusion altogether by following a few best practices:
-
Minimise group overlaps — avoid assigning users to multiple groups with similar roles
-
Use descriptive and purpose-driven group names (e.g., “PM_ReadOnly” or “ResourceManager_Edit”)
-
Document your permission model, especially for complex portfolios
-
Audit access regularly, particularly during onboarding, role changes, or offboarding
-
Align your group and category strategy with business structure, not personal preference
Modernising permission management
If your team frequently runs into permission management challenges, or you’re planning a digital transformation, consider adopting a more modern solution for governance and access control.
Solutions like Wellingtone Accelerator+, built on the Microsoft Power Platform, offer:
-
improved user role management with custom templates
-
permission automation across project lifecycle stages
-
streamlined group assignments
-
full integration with Microsoft Teams and Azure AD groups
-
advanced reporting through Power BI for permission audits
You can learn more about this approach at Wellingtone Accelerator+



















