{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/sharepoint-onedrive-external-sharing-governance/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
        "slug": "sharepoint-onedrive-external-sharing-governance",
        "url": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/sharepoint-onedrive-external-sharing-governance/"
        },
        "title": "SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration",
        "summary": "SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T19:04:22+00:00",
        "modified_at": "2026-07-19T19:04:22+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 3,
        "word_count": 465,
        "potentially_affected": "Microsoft 365 organizations whose users share files, folders, sites, Teams-connected content, or OneDrive data with customers, vendors, partners, or other external people.",
        "dse_recommendation": "Inventory existing sharing, confirm tenant and site limits, classify collaboration use cases, tighten default links, assign site owners, and test guest access and revocation before changing broad settings.",
        "primary_source": {
            "name": "Microsoft Learn: External sharing in SharePoint and OneDrive",
            "url": "https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>External sharing is controlled in layers</h2>\n<p>SharePoint and OneDrive can support secure collaboration with people outside an organization, but no single switch describes the effective result. Sharing is influenced by the organization-level SharePoint setting, each site&#8217;s setting, default link choices, site and group membership, Microsoft Entra external collaboration restrictions, and the permissions on the content itself.</p>\n<p>Microsoft applies the most restrictive combination of the organization and site sharing levels. A site cannot be made more permissive than the tenant allows. Teams and Microsoft 365 Groups add another layer because guest membership and connected SharePoint sites must both permit the intended access. Allowed or blocked domain settings in Entra can also affect sharing.</p>\n<h2>Separate collaboration by purpose</h2>\n<p>Use dedicated sites for distinct external projects instead of exposing a broad internal site and trying to isolate individual folders. Give every site at least two accountable owners, identify its information sensitivity, and document which partner organizations are expected. For OneDrive, use purpose-specific folders rather than sharing an entire personal work area.</p>\n<ul>\n<li>Prefer authenticated, named guests for ongoing or sensitive collaboration.</li>\n<li>Use Anyone links only when the business case accepts that the link can be forwarded and the tenant permits them.</li>\n<li>Set conservative default link types and permissions; users can make an intentional broader choice only when policy allows it.</li>\n<li>Consider domain restrictions, expiration, reauthentication, sensitivity labels, and access reviews where the required subscriptions support them.</li>\n<li>Train owners to distinguish site membership, folder permissions, and sharing links.</li>\n</ul>\n<h2>Inspect before tightening</h2>\n<p>Abruptly reducing a tenant or site sharing level can break legitimate customer workflows without removing every copy already synchronized or downloaded. Inventory active sites, owners, guests, Anyone links, externally shared content, Teams-connected sites, and stale collaborations. Identify anonymous links and broad guest groups that need remediation. Communicate the target model and provide a supported replacement path before revoking access.</p>\n<p>Test representative scenarios with an external account: invitation, redemption, multifactor requirements, browser access, synchronization, link forwarding, expiration, and removal. Microsoft notes that synchronized content can remain on an external user&#8217;s computer after permissions are removed. Access revocation controls future service access; it cannot recall every downloaded copy.</p>\n<h2>Review the surrounding controls</h2>\n<p>Entra B2B settings determine who may invite guests and can restrict collaboration domains. Conditional Access can add requirements, but it needs suitable licensing and careful guest testing. Purview sensitivity, data-loss-prevention, retention, and audit capabilities vary by subscription and configuration. Do not claim that a label or sharing setting protects data unless its actual enforcement behavior has been verified.</p>\n<p>Establish recurring review for site ownership, guests, links, dormant sites, and high-risk content. Remove access when a project ends, but preserve records according to legal and business retention requirements. The objective is not to eliminate external sharing; it is to make the audience, owner, duration, and information boundary visible and reviewable.</p>",
        "content_text": "External sharing is controlled in layers\nSharePoint and OneDrive can support secure collaboration with people outside an organization, but no single switch describes the effective result. Sharing is influenced by the organization-level SharePoint setting, each site’s setting, default link choices, site and group membership, Microsoft Entra external collaboration restrictions, and the permissions on the content itself.\nMicrosoft applies the most restrictive combination of the organization and site sharing levels. A site cannot be made more permissive than the tenant allows. Teams and Microsoft 365 Groups add another layer because guest membership and connected SharePoint sites must both permit the intended access. Allowed or blocked domain settings in Entra can also affect sharing.\nSeparate collaboration by purpose\nUse dedicated sites for distinct external projects instead of exposing a broad internal site and trying to isolate individual folders. Give every site at least two accountable owners, identify its information sensitivity, and document which partner organizations are expected. For OneDrive, use purpose-specific folders rather than sharing an entire personal work area.\n\nPrefer authenticated, named guests for ongoing or sensitive collaboration.\nUse Anyone links only when the business case accepts that the link can be forwarded and the tenant permits them.\nSet conservative default link types and permissions; users can make an intentional broader choice only when policy allows it.\nConsider domain restrictions, expiration, reauthentication, sensitivity labels, and access reviews where the required subscriptions support them.\nTrain owners to distinguish site membership, folder permissions, and sharing links.\n\nInspect before tightening\nAbruptly reducing a tenant or site sharing level can break legitimate customer workflows without removing every copy already synchronized or downloaded. Inventory active sites, owners, guests, Anyone links, externally shared content, Teams-connected sites, and stale collaborations. Identify anonymous links and broad guest groups that need remediation. Communicate the target model and provide a supported replacement path before revoking access.\nTest representative scenarios with an external account: invitation, redemption, multifactor requirements, browser access, synchronization, link forwarding, expiration, and removal. Microsoft notes that synchronized content can remain on an external user’s computer after permissions are removed. Access revocation controls future service access; it cannot recall every downloaded copy.\nReview the surrounding controls\nEntra B2B settings determine who may invite guests and can restrict collaboration domains. Conditional Access can add requirements, but it needs suitable licensing and careful guest testing. Purview sensitivity, data-loss-prevention, retention, and audit capabilities vary by subscription and configuration. Do not claim that a label or sharing setting protects data unless its actual enforcement behavior has been verified.\nEstablish recurring review for site ownership, guests, links, dormant sites, and high-risk content. Remove access when a project ends, but preserve records according to legal and business retention requirements. The objective is not to eliminate external sharing; it is to make the audience, owner, duration, and information boundary visible and reviewable.",
        "content_markdown": "## External sharing is controlled in layers\n\nSharePoint and OneDrive can support secure collaboration with people outside an organization, but no single switch describes the effective result. Sharing is influenced by the organization-level SharePoint setting, each site’s setting, default link choices, site and group membership, Microsoft Entra external collaboration restrictions, and the permissions on the content itself.\n\nMicrosoft applies the most restrictive combination of the organization and site sharing levels. A site cannot be made more permissive than the tenant allows. Teams and Microsoft 365 Groups add another layer because guest membership and connected SharePoint sites must both permit the intended access. Allowed or blocked domain settings in Entra can also affect sharing.\n\n## Separate collaboration by purpose\n\nUse dedicated sites for distinct external projects instead of exposing a broad internal site and trying to isolate individual folders. Give every site at least two accountable owners, identify its information sensitivity, and document which partner organizations are expected. For OneDrive, use purpose-specific folders rather than sharing an entire personal work area.\n\n- Prefer authenticated, named guests for ongoing or sensitive collaboration.\n\n- Use Anyone links only when the business case accepts that the link can be forwarded and the tenant permits them.\n\n- Set conservative default link types and permissions; users can make an intentional broader choice only when policy allows it.\n\n- Consider domain restrictions, expiration, reauthentication, sensitivity labels, and access reviews where the required subscriptions support them.\n\n- Train owners to distinguish site membership, folder permissions, and sharing links.\n\n## Inspect before tightening\n\nAbruptly reducing a tenant or site sharing level can break legitimate customer workflows without removing every copy already synchronized or downloaded. Inventory active sites, owners, guests, Anyone links, externally shared content, Teams-connected sites, and stale collaborations. Identify anonymous links and broad guest groups that need remediation. Communicate the target model and provide a supported replacement path before revoking access.\n\nTest representative scenarios with an external account: invitation, redemption, multifactor requirements, browser access, synchronization, link forwarding, expiration, and removal. Microsoft notes that synchronized content can remain on an external user’s computer after permissions are removed. Access revocation controls future service access; it cannot recall every downloaded copy.\n\n## Review the surrounding controls\n\nEntra B2B settings determine who may invite guests and can restrict collaboration domains. Conditional Access can add requirements, but it needs suitable licensing and careful guest testing. Purview sensitivity, data-loss-prevention, retention, and audit capabilities vary by subscription and configuration. Do not claim that a label or sharing setting protects data unless its actual enforcement behavior has been verified.\n\nEstablish recurring review for site ownership, guests, links, dormant sites, and high-risk content. Remove access when a project ends, but preserve records according to legal and business retention requirements. The objective is not to eliminate external sharing; it is to make the audience, owner, duration, and information boundary visible and reviewable."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
                "url": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration",
                        "item": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/#article",
                "identifier": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
                "url": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/",
                "headline": "SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration",
                "description": "SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration…",
                "abstract": "SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.",
                "articleBody": "External sharing is controlled in layers\nSharePoint and OneDrive can support secure collaboration with people outside an organization, but no single switch describes the effective result. Sharing is influenced by the organization-level SharePoint setting, each site’s setting, default link choices, site and group membership, Microsoft Entra external collaboration restrictions, and the permissions on the content itself.\nMicrosoft applies the most restrictive combination of the organization and site sharing levels. A site cannot be made more permissive than the tenant allows. Teams and Microsoft 365 Groups add another layer because guest membership and connected SharePoint sites must both permit the intended access. Allowed or blocked domain settings in Entra can also affect sharing.\nSeparate collaboration by purpose\nUse dedicated sites for distinct external projects instead of exposing a broad internal site and trying to isolate individual folders. Give every site at least two accountable owners, identify its information sensitivity, and document which partner organizations are expected. For OneDrive, use purpose-specific folders rather than sharing an entire personal work area.\n\nPrefer authenticated, named guests for ongoing or sensitive collaboration.\nUse Anyone links only when the business case accepts that the link can be forwarded and the tenant permits them.\nSet conservative default link types and permissions; users can make an intentional broader choice only when policy allows it.\nConsider domain restrictions, expiration, reauthentication, sensitivity labels, and access reviews where the required subscriptions support them.\nTrain owners to distinguish site membership, folder permissions, and sharing links.\n\nInspect before tightening\nAbruptly reducing a tenant or site sharing level can break legitimate customer workflows without removing every copy already synchronized or downloaded. Inventory active sites, owners, guests, Anyone links, externally shared content, Teams-connected sites, and stale collaborations. Identify anonymous links and broad guest groups that need remediation. Communicate the target model and provide a supported replacement path before revoking access.\nTest representative scenarios with an external account: invitation, redemption, multifactor requirements, browser access, synchronization, link forwarding, expiration, and removal. Microsoft notes that synchronized content can remain on an external user’s computer after permissions are removed. Access revocation controls future service access; it cannot recall every downloaded copy.\nReview the surrounding controls\nEntra B2B settings determine who may invite guests and can restrict collaboration domains. Conditional Access can add requirements, but it needs suitable licensing and careful guest testing. Purview sensitivity, data-loss-prevention, retention, and audit capabilities vary by subscription and configuration. Do not claim that a label or sharing setting protects data unless its actual enforcement behavior has been verified.\nEstablish recurring review for site ownership, guests, links, dormant sites, and high-risk content. Remove access when a project ends, but preserve records according to legal and business retention requirements. The objective is not to eliminate external sharing; it is to make the audience, owner, duration, and information boundary visible and reviewable.",
                "datePublished": "2026-07-19T19:04:22+00:00",
                "dateModified": "2026-07-19T19:04:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/sharepoint-onedrive-external-sharing-governance/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 465,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Learn: External sharing in SharePoint and OneDrive",
                    "url": "https://learn.microsoft.com/en-us/sharepoint/external-sharing-overview"
                }
            }
        ]
    }
}