Considering the following scenario : - create a SharePoint site collection - create a new security permission level "Test", with "Manage permissions" checked. - create a new Group, with "Contribute", and "Test" checked for its permissions.
Now, if a member of this group goes to "_layouts/user.aspx", he can modify his group permissions, and check "Full Control". Now he is site admin.
Is there a way to prevent this behaviour ?